AI Governance 3: aderit.ai's Readiness Stack
Sorting the Cluster in the AI Clusterf***
At the heart of aderit.ai’s approach is what they call the ‘readiness stack’. It is an 18 point list of all of the criteria that have to be specified and monitored to enable the machine side of AI governance.
If you’re following the series, this is where things start to get dense. Integrating AI into an organization as a trusted component of policy execution, risk managment, compliance auditing, and decision making is a complex overly on existing practices.
Most enterprises arrive at agentic AI by one of two well-traveled routes.
In the first, a pilot works. In the second, an incumbent vendor bolts AI onto a platform the company already owns and describes the result as transformation. Both routes produce something real. Neither produces something you would particularly enjoy explaining to the board after it has behaved creatively.
The problem is straightforward: pilots and product demonstrations are optimized to prove capability. Governance is designed to survive consequence. These are not the same engineering problem, although PowerPoint has done admirable work concealing the distinction.
Closing that gap requires an Agentic Readiness Stack. It has two halves, and they behave quite differently.
The first eight layers are Foundational Infrastructure. Enterprise architects generally recognize them. Most organizations have some portion of them. There are familiar names, established practices, budget categories, and people who can explain the architecture using diagrams of reassuring complexity.
The remaining ten layers form the Agentic Control Plane.
Here, the market has not yet developed a shared vocabulary. Consequently, these layers rarely appear in RFPs, analyst scorecards, or vendor positioning. Markets are excellent at naming things they already know how to sell.
The missing layers become visible only after agents begin operating—and failing—in ways that are subtle, gradual, and expensive.
The distinction matters because much of what is currently sold as “enterprise AI governance” reaches identity and authorization, pauses for applause, and declares the work complete. Identity and authorization are necessary. They are also approximately the beginning.
The foundational layers determine whether an agent can operate. The control plane determines whether the enterprise can survive the agent operating badly.
Can the agent recognize when the work is actually finished? Does an irreversible action receive more scrutiny than a recoverable one? Can someone stop the agent while it is confidently heading in the wrong direction? Afterward, can the organization reconstruct what it knew, what it inferred, what it did, and why?
These questions rarely surface during a pilot. Pilots take place in controlled environments with attentive sponsors and unusually cooperative data. This is also why houseplants flourish in hotel lobbies.
Nor does a vendor’s AI overlay solve the problem. It generally inherits the governance of the underlying platform. That governance was designed to manage software used by people, not software authorized to interpret conditions, choose actions, and pursue outcomes.
The missing controls become obvious the first time an agent is confidently wrong in front of someone who matters.
Most organizations possess fragments of perhaps four layers. Almost none have all eighteen working together.
The components themselves are not especially novel. Much of the stack maps to infrastructure, controls, and operating disciplines enterprises already own. What is new is the urgency—and the realization that agentic readiness is not a product category.
It is a checklist of organizational capabilities that must be assembled, assigned, tested, and governed.
In other words, it is something the enterprise has to build, even if the procurement process would strongly prefer another answer.
The Agentic Readiness Stack — 18 Layers
Foundational Infrastructure (1–8)
Identity — Agent attribution that answers which agent, acting on whose behalf, using what credential.
Authorization & Policy Enforcement — Fine-grained access control governing what an authenticated agent is actually permitted to do.
API Management & Mediation — Gates between agents and systems: rate limiting, throttling, and contract enforcement at machine speed.
Observability & Audit Logging — Traceability of what an agent did, why, and what data it touched.
Data Quality & Canonical Models — The canonical substrate agents reason against, without which they produce confidently wrong outputs derived from real data.
Data Privacy & Compliance — Coverage from two directions: gateway-side enforcement and data lineage tracking across PII, jurisdictional, and consent boundaries.
Secrets Management — How agent credentials are scoped, rotated, and revoked, including at agent retirement or compromise.
Integration Architecture — The connective tissue across ERP, HCM, CRM and other systems that constitutes the agent’s actual reach.
The Agentic Control Plane (9–18)
Agent Memory Governance — Write-tier policies and immutable write audit for what agents infer, learn, and persist back into the organization’s record.
Success & Failure Pattern Learning — An explicit outcome loop so patterns that work are reinforced at retrieval and patterns that fail decay out.
Staged Autonomy — Tiered privilege (observer → recommender → gated executor → autonomous) with graduation on measured metrics rather than confidence.
Closure Rules — Per-task-type criteria distinguishing “the agent completed the task correctly” from “the agent stopped.”
Reversibility Taxonomy — Classification of actions as reversible, compensable, or irreversible, so approval rigor scales with blast radius.
Kill Switches — Tested, executable stop and rollback mechanisms scoped per agent, per tenant, and per capability.
Structural Coherence & Drift Detection — Topology-level monitoring that catches reasoning drift before outputs degrade, rather than after.
Evidence Provenance — A deterministic record of which memories, at what confidence, supported a given recommendation.
Idempotency — Write-path guarantees ensuring retries don’t become duplicate actions in systems of record.
Communication Scope Enforcement — Architectural boundaries on which stakeholders an agent may reach, on which topics, at what data sensitivity.
Photo by Benoît Deschasaux



