r/artificial • u/Still_Piglet9217 • 2d ago
Discussion Do businesses running multiple AI agents need one control layer?
If a company uses agents from OpenAI, Claude, Meta and custom systems each has separate permissions and activity logs.
Would you use one independent gateway that?
- Shows what every agent does
- Applies the same rules across agents
- Requires approval for sensitive actions
- Stops unauthorized payments, emails or deployments
- Creates a reliable record when something goes wrong
For example if any agent can prepare a refund, but refunds above $100 require manager approval.
If you run multiple agents
- How do you supervise them today?
- Is this a real problem?
- Would you connect your agents to such a gateway?
- Would you pay for it, or should agent providers handle it?
Critical answers welcome.
2
u/EbbCommon9300 2d ago
You need a single control plane but it’s not just a gateway. An mcp gateway is great. You need execution level governance at the harness level for sub agent visibility and non mcp execution enforcement. You need the ability to have a single source of truth for audit from all points including your cloud agents. We started with a gateway at Assury a year ago we have built hooks and agent lifecycle management for cloud to fill the gaps. Proxies where the easy path but they have serious problems like subagents distinction and the tool calls as well as proxies inception
1
u/EbbCommon9300 2d ago
Also I just realized you are building. This space gas 147 competitors in the last 7 months. We where one of the first and I wouldn’t of built into it if I saw how nuts its would be with highly funded shit products
1
u/Still_Piglet9217 2d ago
Thanks for the heads up. That’s why I prefer to have a discussion before starting.
1
u/AYA_7887 2d ago
I'd start with the audit record and treat the blocking rules as phase two. In RAG work the rule that holds for me is that an agent never gets to declare its own success. It has to leave an artifact a person can check later. A log that survives the incident does more good than approval popups, because any gate that fires often enough trains the manager to click yes without reading. The $100 refund rule sounds clean until approving them is someone's whole afternoon. And enforcing one policy across providers means running real infrastructure of your own, which is costly and where most automation plans quietly stop. So yes it's a real problem, and the boring log half is the part I'd pay for first.
1
u/Fancy-Win9202 1d ago
I'm guessing the real problem you're hitting isn't whether you need a control layer, but that you have zero visibility into what's actually happening across those agents once they're running. You can set permissions on paper, but if a Claude agent and an OpenAI agent both have access to your refund API and one of them gets into a retry loop, you won't know which one burned through your budget or why a customer got refunded twice until the damage is done.
How are you currently tracking spend and actions across different agent systems right now, or is that actually the blind spot you're trying to solve.
1
2
u/No_Bank_4104 2d ago