Skip to main content Skip to footer

Governing AI agents across your martech stack: what needs to be in place

The age of agentic AI represents a significant shift in the way we work. While most of us are currently not working with AI agents on a scale, that situation seems likely to change sooner rather than later.

In terms of digital marketing, agents have the power to potentially publish content, edit pages, respond to customers and prospects, and more – all without human intervention. Agents can work across your entire marketing stack and with third-party systems through the Model Context Protocol (MCP).  

Content management systems and digital experience platforms have evolved quickly to incorporate agents with native and integrative capabilities: 

The need for governance

Agentic AI represents a significant potential loss of control for digital marketing teams, an uptick in what can be achieved through automation, and a required subsequent mind shift. Therefore, for agentic AI to work on a scale, governance controls and guardrails are needed to reduce risks, ensure content stays on brand, and allow marketers to trust the use of agents. 

Most organisations we work with are still at the early stage of using AI agents in digital marketing and therefore their governance is equally early stage. Previously we wrote about the importance of setting up the foundations for AI now to prepare for their wider use. In this post we’re going to specifically focus on governance for AI agents and the governance controls and policies that need to be in place.

 While the urgency of that need will differ across organisations and teams, we think these are all aspects that marketing teams need to consider as agentic AI ramps up in the products they use every day across the digital marketing stack.

Principles reflecting your appetite for risk

Upfront it is worth considering your appetite for risk in terms of using agentic AI for digital marketing and whether there are principles you want to stick to. To some extent this is working out what you would do and wouldn’t do. For example, would you allow publishing a piece without a review by humans? Would you allow authors outside the central digital team to use agents? Defining these will help derive the details of the other controls and guardrails and it is worth articulating these as principles.  Of course, as agents get more sophisticated or your use of them matures, these principles may change over time.

Alignment with other agentic AI controls and policies

Your organisation may already have wider governance in place relating to the use of AI agents and AI. Clearly the governance you introduce across the digital marketing stack will not only need to align with any enterprise-wide measures but also specifically incorporate any rules or processes into your approach. 

An agent inventory with named owners

It is easy to lose track of AI agents and what they do as they can occur across different technologies and interact with external tools via the MCP.  Teams can now also create their own agents. At the centre of any successful governance of agents has to be a register or inventory of agents to keep track of these.  This will need details such as what an agent does, the platforms it interacts with, the related permissions of who can use it, and importantly who owns the agent.

Maintaining an inventory then means it is easier to:

  • review agents when something changes, for example with the technology or with security policies
  • reassign ownership if somebody moves on
  • avoid duplication and optimise use
  • ensure humans are appropriately in the loop
  • review the introduction of new agents.

Agent permission policies

Agents all require permissions in terms of the systems they can access and what they can do in that system. There will also be permissions in terms of who can use and change an agent.

Permissions should follow wider permission policies that are in place across your organisation. This is likely to be a principle of least-privilege in terms of not granting permission to anyone who strictly does not need it, helping to reduce security and privacy issues.

5 Human approval where appropriate

Human-in-the-loop is a central AI principle for many organisations; human approval will almost certainly need to be woven into many agentic AI processes when used across the digital martech stack. For example, does every time a piece of content is published or deleted require human approval? We would strongly suggest yes. However, there also needs to be a sensible balance between what needs approval and what doesn’t in order not to devalue the use of the agent, or create workload or bottleneck issues for busy digital marketers.

In considering approval workflows, it is also important to consider whether a person has enough information and context to be able to make any approval decision; this needs to be factored into the agent design and workflow. 

Audit trails

You’ll want to be able to ensure there are the right audit trails in place which record when a page was changed or edited, potentially for compliance reasons. You may already have these in place for human edits, but they will also need to cover the actions of AI agents, including any external MCP agents.  

Brand and compliance checks

Agentic workflows that involve content generation and publishing should have steps built in to support brand and compliance checks covering everything from tone of voice to accessibility. This is a key selling point for using AI agents within your CMS; for example, native agents within Sitecore and Optimizely can provide checks on aspects of the brand you define within the CMS such as your visual identity, specific regulatory requirements, or positioning that needs to be avoided. We previously covered some of the core brand reference material that should be in place to support these checks. 

Model use and where the data goes

Different products have different approaches to using LLMs. For example, with Umbraco you can plug in your LLM-of-choice and even switch between different models for different use cases. Your legal and compliance team will want to know where data resides and whether there are any data privacy and compliance issues based on where data is being processed. As part of your governance, it will be useful to map out which LLMs and models are being used to process data; potentially this can be recorded in your inventory of agents. This approach can also help control costs and token use which is explored below. 

Cost and token controls

One practical issue that many teams are grappling with is keeping control over costs. It is all too easy to burn through AI tokens, and it will be necessary to ensure your agents have some controls put in to provide visibility on allowances being burnt. Some of the platforms have features built in – for example Optimizely displays the credits used for agents running.

Any policy on usage may also need to stipulate the right LLM model to use for which agent or use case which impact cost. You may also need to define any spending cap, as well as the instances or approval workflow required to buy additional credits.

Product, procurement and vendor review processes

Products are introducing agents at speed and new agents are launched all the time. The support for agentic AI may also be a key reason why a new product gets selected and added to your martech stack. There will need to be some defined processes concerning the use of agents in products, for example:

·       A review and approval process for new agents introduced into existing solutions.

·       Procurement guidelines and standards for support for agentic AI in new products.

·       Any standards that vendors need to meet, relating to the management of AI within their product.

Incident response processes

What happens when something goes wrong with an agent? Perhaps it has posted something it shouldn’t have done or posed a compliance or security risk. If something does go wrong, then it is worth mapping out the response to control the incident as well as any review and subsequent actions that need to take place as a result to stop it happening again through other agents. 

Periodic reviews of all the above

Agentic AI is moving at speed both in general and within the individual digital marketing products you use.  Your governance will need to keep up so you’ll need:

·       periodic reviews of all your governance to make sure it still works

·       specific reviews triggered by incidents or changes. 

Why AI agents need governance

Governance is critical for the success of agentic AI in the world of digital marketing. That’s not only because you need control over what gets published on your website or gets sent to a prospect, but also to take advantage of using agents to stay on brand and to establish confidence across the digital marketing team to use agents across daily workflows and tools.

If you’d like to discuss the use of AI agents the governance that needs to be in place, then get in touch.

Related Blog posts

About the author

3chillies

Unlimited possibilities

3chillies

Get in touch today