The Agent Control Plane Map
The controls exist, just not in one place.
Compare 29 AI products, who operates their controls, and the evidence behind them.
- AI products
- 29
- Control surfaces
- 9
- Org-owned controls
- 30%
Read the map
Hover for a quick view. Select a grade for its evidence.
Small violet dot: a setup or availability condition applies.
Coding agents & IDEs
Enterprise chat & knowledge
Agent platforms
| Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| Coding agents & IDEs | |||||||||
Claude Code | |||||||||
OpenAI Codex CLI | |||||||||
GitHub Copilot | |||||||||
Lovable | |||||||||
Replit | |||||||||
Devin AI | |||||||||
Kiro | |||||||||
Cursor | |||||||||
Devin Desktopformerly Windsurf · Cognition | |||||||||
Gemini Code Assist | |||||||||
| Enterprise chat & knowledge | |||||||||
Claude Cowork | |||||||||
Claude (Team & Enterprise)Anthropic | |||||||||
ChatGPT Enterprise | |||||||||
Glean | |||||||||
Google Gemini (chat app) | |||||||||
Microsoft 365 Copilot | |||||||||
Microsoft 365 Copilot CoworkGA Jun 2026 | |||||||||
Notion AI | |||||||||
Slack AI | |||||||||
Atlassian Rovoexcludes Rovo Dev | |||||||||
Perplexity Enterprise | |||||||||
| Agent platforms | |||||||||
Salesforce Agentforce | |||||||||
Copilot Studio | |||||||||
Microsoft Foundry | |||||||||
Amazon Bedrock AgentCore | |||||||||
Gemini Enterprise Agent Platform | |||||||||
Databricks Unity AI Gateway | |||||||||
ServiceNow AI Agentsgraded at Prime tier | |||||||||
Snowflake Cortex Agents | |||||||||
How to read this
- You own it
- Enforcement runs on infrastructure you control: your identity provider, your gateway, your cloud account, your endpoint fleet, your network.
- The vendor owns it
- A real control exists, but it runs in their console and they enforce it for you.
- Nobody owns it
- No control on this surface, or none you can reach.
- Security gap
- No control surface exists at all. Different from the row below: this one is a finding.
- Does not apply
- The surface is not part of how this product is built, so there is nothing to govern. Not a gap.
Tap any grade for the reasoning and the vendor documentation behind it. Every receipt carries its tier, when we last checked the page, when the document was published, and the sentence the grade rests on.
A small dot on a grade means the control is not necessarily switched on. The grade answers “if you turn this on, whose infrastructure enforces it?” The dot answers “is it on?”, which is a property of your deployment and something this map cannot see.
The full rubric for each column, the evidence-tier policy and the absence protocol are in the methodology. Every grade that has ever moved is in the changelog.
One agent. 6 of 7 domains in its containment path.
1 of 29 products sit at this depth. 0 run deeper.
In every product
- Human identity (IdP)29 of 29
- Product admin plane29 of 29
The other 5. None in more than 13 of 29.
- Network13 of 29
- Gateway credential9 of 29
- Endpoint / EDR9 of 29
- Cloud control plane5 of 29
- Data platform2 of 29
Two domains are not optional: the identity provider, and the vendor’s own admin console. Every one of the 29 products runs through both. After that there is no pattern. The next most common domain appears in 13 of 29, so which other team you need is a property of the product, not of your programme. 20 of 29 products reach past those two.
Three findings
Three things the data says that an AI governance programme has to plan around.
The controls are real. They are spread.
A programme wired into one domain covers a fraction of the surface, however good that domain is.
In most products the agent is the employee
In 21 of 29 products the agent acts with the identity of the person who started it: their token, their permissions, their name in the audit log. The other 8 issue the agent a principal of its own, though only some of those are minted by your fabric rather than the vendor’s. Where the agent is the person, identity is the plane you cut it on, and the audit trail will not tell you which of the two acted.
A grade says what you can turn on, not what is on
60 cells carry a marker saying the control is opt-in, tier-gated, in preview, still to be built, gated on a deployment mode, or dependent on a gateway you have not deployed. The grade is what the product makes possible. It is not what is running in your tenant tonight, and only your own environment can answer that. Confirm a control is firing before you write a policy against it.
Changelog
Every grade that has ever changed, newest first, with corrections, rubric changes and scope changes labelled separately. We publish our own corrections first.
v1.2 · A ninth surface, seven new products, and half the board re-read. Amazon Q Developer is retired, three rows are renamed to the product a buyer can find, and six grades moved after fourteen contested cells were adjudicated. Three further moves were made and then reversed, on re-reading the pages rather than the quotes.
Full changelogGet notified when a grade changes
Zaun keeps this map up to date as the source of truth for AI vendor controls, powering Zaun Reagent and other Zaun products. Subscribe to hear when a grade changes.
