Governing Agentic AI in Enterprise Operations: Architectural “Rails” for Safe, Deterministic, and Compliant Autonomous Systems
Abstract
As enterprises accelerate the adoption of autonomous and agentic AI, the need for robust governance has become a critical architectural priority. Large organizations operate under strict regulatory, operational, and financial constraints, where even a single incorrect payment, billing error, or missed reconciliation can lead to significant compliance violations, audit failures, and material financial losses. These environments depend on deterministic, traceable, and verifiable execution; therefore, AI-driven automation cannot operate freely but must be deployed on well‑defined “rails” that enforce consistency, accountability, and operational safety. This paper argues that the introduction of agentic AI requires a substantial expansion of traditional enterprise architecture principles to address new behavioral, security, and governance risks emerging from non-deterministic AI systems interacting with heterogeneous operational platforms-ERP, HCM, CLM, asset management, workflow engines, and domain-specific applications. We propose a governance-centered framework for safe agentic AI in enterprise settings, emphasizing lifecycle oversight (model management, testing, deployment, rollback), cross-system policy enforcement, and auditable decision lineage. Central to this framework is a security model grounded in Just‑In‑Time (JIT) and Just‑Enough‑Access (JEA) permissions, ensuring that AI agents receive only the minimal privileges required, only when needed, and never with long‑standing or system‑wide access. Additional safeguards include least‑privilege design, segmentation boundaries, continuous audit trails, agent identity isolation, controlled inter-agent communication, and human‑in‑the‑loop escalation for high-risk or sensitive tasks. These controls prevent unauthorized lateral movement, protect sensitive financial and HR data, and ensure agent actions remain aligned with organizational risk and compliance boundaries. By integrating these governance mechanisms with orchestration and policy engines, enterprises can achieve predictable execution, transparent reasoning, and resilient automation at scale. This work highlights why governance is not peripheral but foundational to the safe deployment of agentic AI
Keywords: AI Agents, Governance, Agentic Framework, Human-in-the-loop
DOI: 10.54941/ahfe1008136
Cite this paper
More from this volume
- Explainability in Automated Driving: From Spatial Attention to Human-Centred Reasoning
- Design and Evaluation of an AI Academic Advisor: Insights from Student Interactions
- To boldly go where AI must not go alone: Designing for non-delegable human authority in AI-assisted expert work
- Integrating Three Modalities into One Experience: A Case Study of 2024 DigiWave—DdDd
- Improving Usability in a Smart Building Ecosystem through Heuristic Evaluation and Usability Testing
- Anchored in the Learner: A Critical Review of AI Discourse in Design Education
- Narrative as a Cognitive Scaffold for Human-Centered Design Education:A Case Study of Schema Change in Interaction Design Students
- Assessment-Before-Intervention: A WHO iSupport-Grounded Conversational AI System for Dementia Family Caregiver Support
- Analyzing Stress and Perceived Safety in Human-Cobot Collaboration: The Impact of Task Proximity, Interface Cues, and System Errors
- Metascience of content-based cognitive ergonomics
- Developing an Assistive Mobile Application for Elderly Nepali Migrants in the UK
- Integrated Home Service Robots for Ageing in Place: A Multi-Stakeholder Perspective on Acceptance and Care Needs in Taiwan


AHFE Open Access