What governance looks like when agents act

A policy that is not in the path will be remembered only during the audit.

An agent that can open a pull request can also take an action nobody scheduled a meeting to approve. The control that matters is the one that fires before the action, and leaves a name on the exception.

That is a different artifact from a policy PDF. It is a gate: the run stops, a person decides, and the decision is stored with the run. Later, the question is not what the policy said. It is whether the gate held.

Command is more than approval. It is deciding how much each process may do on its own, where it must stop, what it may spend, and who may change those terms. Activity records and release traces are the same idea at two distances: one shows the session, the other the release it landed in.

See it on your own agents.

Start with one process, set the gates, and read the record.