A working handbook for the Agentic Enterprise AI Architect. How to operationalize the seven AEGIS pillars on the four platforms where regulated enterprises actually deploy agents today: Adobe, Salesforce, ServiceNow, and Microsoft. Every native governance primitive mapped to its pillar, with the always-on horizontal dimensions and the latest feature sets and roadmap items called out by date.

Before any platform specifics, fix the mental model. The cost of governance is not constant across the lifecycle. Applying enterprise-scale controls to a lab experiment is waste; carrying lab-stage informality into production is debt that compounds. The architect's job is to know which phase each system is in, and to switch the model at the inflection point.
Most experiments fail and understanding is nascent. An ethics checklist and data hygiene are enough. Formal governance architecture here is disproportionate cost. Do not over-engineer.
The moment agents touch real users and real data, the model must update. AEGIS Pillars 1 to 4 active before GA. This is the design moment. Every shortcut taken here creates debt that grows 4 to 7×.
All seven pillars plus the Cost Layer become a procurement differentiator, a regulatory-resilience asset, and a market-access requirement. One ungoverned incident at scale can exceed the entire annual program cost by 30 to 40×.
The platforms in this handbook have all converged on the same realization in the last twelve months: the agent is not the product, the governed control plane around the agent is the product. Salesforce calls it Agent Fabric. Microsoft calls it Agent 365. ServiceNow calls it the AI Control Tower. Adobe calls it the AEP Agent Orchestrator. Four names for one architectural truth that AEGIS has held from the start.
This is good news for the architect. You are no longer bolting governance on from outside; you are configuring controls the platform already exposes as first-class primitives. The work shifts from building governance to mapping AEGIS pillars onto native capabilities and proving the mapping holds under audit. That is what the rest of this handbook does, platform by platform.
No platform chapter stands alone. These dimensions apply to every deployment regardless of which vendor's control plane you build on. Treat them as a checklist that runs orthogonally to the seven pillars: each platform section that follows assumes these are being governed in parallel.
Four primary verticals set the regulatory ceiling. Financial Services brings CFPB adverse-action, SR 11-7 model risk, and Reg BI. Healthcare brings HIPAA, ONC algorithm transparency, and FDA SaMD. Manufacturing brings GxP, ISO 9001, and on-premise data-sovereignty needs. Energy brings NERC CIP and NIS2 critical-infrastructure obligations. The same agent carries a different governance weight in each. The platform is constant; the pillar intensity is set by the vertical.
All four platforms are now multi-model. The governance requirement is model selection governance (Pillar 4): an allowed-list of providers per use case, least-cost model meeting the accuracy bar, and routing logged for audit. Anthropic Claude (Opus 4.8, Sonnet 4.6), OpenAI GPT-5.5, and Google Gemini 3.1 Pro are the production frontier set; coding agents add Cursor, Claude Code, Codex, and Windsurf via the platforms' MCP surfaces. Open models (NVIDIA Nemotron, Llama-derived) cover on-premise and data-residency cases.
Where the agent runs is a governance fact, not just an ops detail. NVIDIA AI Enterprise (NIM microservices, NeMo Guardrails with content-safety / topic-control / jailbreak NIMs, NeMo observability) is the dominant on-premise and edge guardrail layer. AMD Instinct MI400 series (MI430X for sovereign/HPC, MI440X for on-premise inference, UALink open interconnect) is the credible second source for enterprises wary of single-vendor lock-in. For GxP, NERC CIP, and ITAR cases, on-premise inference with zero cloud egress is the control, not a preference.
When agents drive actuators, the AEGIS action allow/blocklist (Pillar 4) becomes a physical-safety control and the audit trail (Pillar 6) becomes incident-reconstruction evidence. NVIDIA Isaac GR00T (humanoid VLA models, GR00T-H vision-language-action) and Cosmos world-foundation models anchor the manufacturing and logistics robotics stack. Governance additions over digital agents: emergency-stop authority, geofenced action boundaries, and simulation-validated behavior (Omniverse) before any physical deployment.
The hosting choice determines which data-residency and sovereignty obligations apply. Public cloud (Azure, AWS Bedrock, Google Cloud) is the default; sovereign and on-premise deployment is the control for regulated data that cannot leave a boundary. All four platforms now offer a sovereign or local path: Microsoft Foundry local deployment, Google Distributed Cloud, NVIDIA on-premise via AI Enterprise. The architect's job is to tag each system's data-residency requirement in the inventory (Pillar 2) and match the topology to it before GA.
This is the board-level horizontal most programs miss. Every platform now meters agents differently: Salesforce per-conversation, Microsoft per Copilot credit, ServiceNow per ACV, Adobe per workflow. AEGIS Cost Governance threads through Pillars 1, 2, 4, and 6: per-agent budget caps as a hard stop, cost-as-circuit-breaker on runaway loops, token and API spend in the same dashboard as bias and performance, and a monthly spend report to the CAIO and CFO. Gartner projects 40% of agents will be decommissioned by 2027 for governance and cost reasons; the cost layer is how you avoid being in that 40%.
This is the table to keep open while you architect. Each AEGIS pillar already has a home in each platform's native governance tooling. The architect's value is knowing the mapping, configuring it deliberately, and producing the evidence that proves it. Read down a column to govern one platform; read across a row to see how the same obligation is met four different ways.
| AEGIS Pillar | Salesforce Agentforce 360 | Microsoft Agent 365 | ServiceNow AI Control Tower | Adobe Experience Platform |
|---|---|---|---|---|
| P1Governance Architecture | Agent Fabric governed control plane; per-agent ownership in Agent Builder | Agent 365 control plane; agent approval & publication flow; policy templates | AI Control Tower lifecycle orchestration: intake, review, retire; AI CoE workspaces | AEP Agent Orchestrator; agency system of record preserves accountability |
| P2AI System Inventory | Agentforce agent registry; Data 360 lineage; AgentExchange catalog | Agent 365 registry; cross-platform sync with Bedrock & Google Cloud | Discover across 30+ integrations (Azure, AWS, GCP, SAP, Workday); CMDB | AEP data and content inventory; Content Credentials provenance |
| P3Risk & Impact Assessment | Agentforce Testing Center; simulation in Agent Builder before deploy | Defender Agent SPM: posture, excessive-permission & misconfig detection | Govern: 5 risk frameworks aligned to NIST AI RMF & EU AI Act; pre-deploy review | Brand Intelligence validation; output checks vs brand & compliance rules |
| P4Controls & Human Oversight | Agent Script deterministic control; Agentforce Guardrails; HITL escalation | Entra Conditional Access for agents; network controls; least-privilege | Now Assist Guardian: prompt-injection & output guardrails; Veza least-privilege | AEP approval workflows; deterministic Firefly Creative Production; HITL review/approve |
| P5Transparency & Rights | Einstein Trust Layer; zero data retention; full action auditability via Data 360 | Purview sensitivity-label propagation to agent output; DSPM for AI | AI Risk & Compliance Workspace; explainable decision records | Content Credentials (C2PA) on every asset; AI-content labeling built in |
| P6Monitoring & Response | Agentforce transcript logs; Agentic Work Unit metering; Data 360 observability | Defender runtime detection; Purview AI Observability; audit logs in Entra | Observe (Traceloop): runtime agent-reasoning observability; financial dashboards | Content Analytics; AEP real-time monitoring of agent-driven experiences |
| P7Regulatory Intelligence | Spring/Summer release cadence; Trust Layer policy updates | Agent 365 policy-template updates; Compliance Manager | Built-in EU AI Act & NIST RMF frameworks, updated each release (Zurich → Australia) | Continuous Brand Intelligence learning; evolving compliance rule sets |
| $Cost Governance | Per-conversation metering; Agentic Work Unit tracking; Data 360 cost view | Agent usage estimator (Copilot credits); cost-management eBook; E7 bundling | Measure: financial dashboards for runaway-spend control; ROI analysis | Per-workflow cost in GenStudio; Firefly Services consumption metering |
Agentforce 360 reached general availability on February 23, 2026 (Spring '26) and is the most production-proven customer-facing agent platform: 22,000+ deals closed in Q4 FY2026 and 85% autonomous resolution on Salesforce's own help portal. For the architect, the governance story is unusually strong because Salesforce shipped Agent Script, a deterministic control language, and Agent Fabric, a multi-vendor governed control plane, in the same cycle. The platform's hard prerequisite is Data 360 (formerly Data Cloud); without it agents have no governed context to reason over.
Human-readable expression language for deterministic agent control: conditional logic, precise tool use, guided steps. This is how a consequential decision becomes repeatable and auditable rather than probabilistic.
Governed control plane for multi-vendor agents: deterministic orchestration plus centralized agent, tool, and LLM governance across the whole AI landscape, not just Salesforce-built agents.
Zero data retention with third-party LLMs, dynamic grounding, toxicity and bias filtering, configurable guardrails for regulated use cases. The data-protection spine under every agent.
ReAct-loop reasoning with configurable model choice (Claude, GPT-5.5, Gemini via Bedrock). Reliability is a product of architecture and clean process definitions, not the model alone.
Microsoft's governance story crystallized with Agent 365 (GA May 1, 2026), the centralized control plane that treats every agent as a first-class governed identity. The defining primitive is Entra Agent ID: every agent built in Copilot Studio or Foundry gets a real directory identity, so it is subject to the same Conditional Access, Identity Protection, and audit machinery as a human employee. This is the cleanest expression of AEGIS Pillar 4 least-privilege in the market: an agent calling a tool is governed exactly like an employee accessing a system. Build agents in Copilot Studio (low-code) or Microsoft Foundry (pro-code, multi-agent, sovereign deployment).
Every agent is a governed Entra identity under a Copilot Studio identity blueprint. Conditional Access, Identity Governance, sign-in audit logs, and lifecycle management apply to agents exactly as to users.
Security Posture Management: continuous discovery and risk scoring of every agent, detecting excessive permissions, misconfigurations, shadow agents, and attack paths with prioritized remediation.
Unified visibility into how agents access and expose sensitive data; sensitivity-label propagation to agent-generated content; data-lifecycle retention for human-to-agent interactions.
Registry, approval-and-publication flow, policy templates grouping Entra / Purview / Defender controls, and rules-based lifecycle automation. Syncs with AWS Bedrock and Google Cloud for cross-platform governance.
ServiceNow has positioned the AI Control Tower as the governance layer for the whole enterprise, not just ServiceNow-built agents. Following the Zurich release (March 2026) and the Knowledge 2026 expansion (May 2026), it now discovers, observes, governs, secures, and measures AI across 30+ enterprise systems including Azure, AWS, Google Cloud, SAP, and Workday. For the architect whose estate spans multiple vendors, this is the strongest candidate for the single pane of glass that AEGIS Pillar 1 and 2 demand. Crucially, Anthropic is a design partner: Claude Cowork connects to ServiceNow's governed execution layer via Action Fabric, so agents built elsewhere trigger enterprise workflows under ServiceNow governance.
Discover, Observe, Govern, Secure, Measure across any system. Discovery spans 30+ integrations; full lifecycle orchestration from intake to retirement through connected workflows.
Real-time guardrails for first- and second-order prompt injection, harmful outputs, sensitive-data exposure, and adversarial behavior. The runtime control point for Pillar 4.
Opens ServiceNow's full system of action (flows, playbooks, approvals, catalogs) to any agent, Claude, Copilot, or homegrown, via the GA MCP Server. Every action is identity-verified, permission-controlled, and audited.
Veza's access-graph brings scoped permissions and least-privilege to every AI identity; Armis feeds IT/OT/IoT asset intelligence into the CMDB, turning static inventory into a live attack-surface picture.
Adobe's agentic story runs through the AEP Agent Orchestrator and the GenStudio content supply chain, reframed at Summit 2026 (April) as an agentic operating layer. Its distinctive governance contribution is provenance: Content Credentials (C2PA) embed verifiable, tamper-evident attribution into every generated asset, which directly satisfies the AI-content-labeling obligations of AEGIS Pillar 5 in a way no other platform does natively. Adobe's models are commercially safe by design (Firefly is trained on licensed data), and Brand Intelligence turns static brand guidelines into a continuously learning compliance engine. For regulated marketing and customer-experience workloads, this is the brand-and-rights control plane.
Builds, manages, and orchestrates Adobe and third-party agents grounded in customer data and content, with data governance and regulatory compliance built into the platform foundation.
Verifiable digital provenance embedded in every asset; the Content Authority API (beta) extends this programmatically. Direct, native satisfaction of AI-content disclosure and labeling law.
A continuously learning engine that moves beyond static brand-guideline PDFs, learning from approvals, rejections, and annotations, then making that understanding available to every content agent.
Trained on licensed data for IP-safe generation; Custom Models and Firefly Foundry let enterprises train on proprietary brand assets with governance and brand-validation rules enforced.
A handbook is only useful if it tells you what to do next. This is the sequenced readiness path that applies regardless of which platform or platforms you run. Work it in order; each stage assumes the previous one is done.
Notice what Stages 1 to 4 are not: a rip-and-replace. The readiness path is configuration and evidence, not construction, because the platforms have already built the primitives. The enterprises that win the next eighteen months are the ones that treat governance as the design input, not the post-incident cleanup. Gartner's projection that 40% of agents will be decommissioned by 2027 is a forecast about which enterprises did Stage 3 before GA and which ones skipped it.
AEGIS is the constant; the four control planes are how it gets expressed in the tools you already own. Map deliberately, gate before GA, and the same governance that regulators demand becomes the moat that wins enterprise procurement.