the guides

20 questions, answered in full.

20 questions about running AI agents, each answered at the length the question actually takes rather than the length a product page has room for: AI agent governance, Prompt injection defence, The EU AI Act for agent deployers, LLM cost control, The agent permissions model, Audit evidence for agent actions, MCP tool server security, Shadow AI discovery, AI agent security, LLM gateway architecture, Observability and governance, Self-hosted or hosted governance, AI agent incident response, Agent-to-agent delegation, LLM data residency, The AI vendor questionnaire, Measuring AI agent risk, Policy as code for AI, Agent onboarding, Why agents need different controls. Every answer names mechanisms rather than adjectives and states its own limit beside its claim. They are written to be worth your time whether or not you ever buy anything.
Questions, each answered on its own merits
20
Sections of argument beneath them
114
Numbered steps you can act on today
142
Follow-on questions answered in full
100
start from the question

Which of these did you come here with?

  1. THE FIELD, DEFINED

    What is AI agent governance, and what does it actually require?

    AI agent governance
    What governance cannot reach

    Any agent that never routes through it — that is a discovery problem first

  2. INDIRECT INJECTION

    How do you defend an AI agent against prompt injection?

    Prompt injection defence
    The honest limit

    A phrasing nobody wrote a pattern for scores zero, and the rule never fires

  3. DEPLOYER OBLIGATIONS

    What does the EU AI Act require of an organisation deploying AI agents?

    The EU AI Act for agent deployers
    What no tool can do for you

    Classify your risk tier, run the assessment, or notify the authority

  4. HARD BUDGETS

    How do you stop AI agent spend running away?

    LLM cost control
    The cost of a hard ceiling

    One potentially billable egress: no retry, no failover on that call

  5. LEAST PRIVILEGE

    How should you model what an AI agent is allowed to do?

    The agent permissions model
    What this layer cannot see

    Argument values. Refunds over £200 is a policy, not a permission

  6. TAMPER EVIDENCE

    What counts as audit evidence for an AI agent’s actions?

    Audit evidence for agent actions
    The default, stated plainly

    Unkeyed, a rewrite that recomputes every hash verifies clean

  7. TOOL SURFACE

    How do you secure Model Context Protocol tool servers?

    MCP tool server security
    What is withheld rather than inspected

    Image, audio, blob and resource content, after the tool has already run

  8. COVERAGE FIRST

    How do you find AI use that is not going through your controls?

    Shadow AI discovery
    How current a finding is

    Exactly as current as the export it was computed from

  9. THE WHOLE SURFACE

    How do you secure an AI agent?

    AI agent security
    What none of it reaches

    An agent that calls a provider directly, and any media it sends

  10. THE REQUEST PATH

    How should an LLM gateway be architected?

    LLM gateway architecture
    The topology this assumes

    One process and one write path; no multi-replica or high-availability claim

  11. TWO DISCIPLINES

    Do I need agent observability or governance, or both?

    Observability and governance
    What neither reaches

    An agent that routes through neither, and the model’s hidden reasoning

  12. WHERE IT RUNS

    Should AI governance run in my own network?

    Self-hosted or hosted governance
    What self-hosting does not settle

    Support access, incident handling and evaluation terms are still a legal question

  13. WHEN IT GOES WRONG

    What do you do when an agent does something it should not have?

    AI agent incident response
    The limit of erasure

    It reaches the live database; snapshots and some tables are outside it

  14. INTERSECTION

    How should one agent be allowed to ask another for something?

    Agent-to-agent delegation
    What intersection does not bound

    Why the upstream agent asked — a legitimate grant, exercised for an injected reason

  15. RESIDENCY

    How do you keep agent traffic inside a jurisdiction?

    LLM data residency
    The assertion nobody can verify

    No control can prove where a vendor actually served a request

  16. PROCUREMENT

    What should you ask an AI vendor?

    The AI vendor questionnaire
    What this exercise is not

    A questionnaire is a filter; it does not replace testing the product yourself

  17. RISK, MEASURED

    How do you decide which agents are risky?

    Measuring AI agent risk
    What the tier does not do

    It is not a policy-scope dimension; rules bind on agent id, team and tag

  18. TESTABLE RULES

    How do you express an AI policy so it can be tested?

    Policy as code for AI
    What a compiled artefact is not

    A policy exported to another engine covers matching, not the enforcement around it

  19. PROTOTYPE TO PRODUCTION

    How do you take an agent from prototype to governed production?

    Agent onboarding
    What a readiness check cannot tell you

    Release provenance, independent testing, legal approval or your integration matrix

  20. THE GAP

    Why don’t existing API controls work for agents?

    Why agents need different controls
    What reusing the stack cannot fix

    An agent that never routes through any of it

the questions underneath

100 narrower questions, and where each is answered.

AI agent governance

Prompt injection defence

The EU AI Act for agent deployers

LLM cost control

The agent permissions model

Audit evidence for agent actions

MCP tool server security

Shadow AI discovery

AI agent security

LLM gateway architecture

Observability and governance

Self-hosted or hosted governance

AI agent incident response

Agent-to-agent delegation

LLM data residency

The AI vendor questionnaire

Measuring AI agent risk

Policy as code for AI

Agent onboarding

Why agents need different controls

If the question that would decide it for you is not on that list, that is the more interesting question and it is the one worth sending.

Ask it directly
get in touch

None of the 20 is your question?

Write to hello@tenhaw.com with what your agents do, which providers they call and what would have to be true for you to put something in front of them. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.

no form · no qualification step · no sales desk · the other three ways in