01
Policy drift
Each agent carries its own copy of the rules. Approvals become advisory, and no two teams enforce the same boundary the same way.
EmpowerID Agent Governance & Execution · Agent Teams
Deploy scheduled, heartbeat-driven teams with governed charters, deterministic run stages, human confirmation for consequential steps, fleet controls, and linked evidence—on the Identity Fabric that governs people and machine identities.
Governed operations within Agent Governance & Execution
The model contributes intelligence. The platform owns the operating lifecycle.
Not another chatbot. Not “an agent with policy.” A standing ops crew—charter, cadence, confirmations, fleet desk.
The problem
Most agent pilots are reactive: a human opens a chat, asks a question, and hopes context persists next time. Security teams see API keys, broad tool access, and no kill switch. Operations teams see queues, overnight failures, and escalations that arrive too late. EmpowerID Agent Teams inverts the model—proactive, scheduled, governed autonomy with heartbeats, team charters, structured handoffs, and confirmation gates before high-risk mutations.
01
Each agent carries its own copy of the rules. Approvals become advisory, and no two teams enforce the same boundary the same way.
02
Operators cannot see whether work is active, waiting, failed, or silently stuck—the only record is a chat transcript.
03
Stopping an agent means finding the right deployment, secret, or queue—not an authorization-protected pause or kill-switch.
Proactive intelligence with enterprise guardrails—the model proposes, the platform decides, humans confirm, auditors verify.
The model
Governed agents live across the platform—registration in AI Agent Discovery, reactive chat elsewhere, every model and tool call through the LLM Gateway and MCP Gateway. Agent Teams turns those identities into standing operational crews.
AI Agent Discovery gives an agent a badge. Agent Teams gives it a shift, a crew, and a supervisor sign-off.
Team
Durable charter, role bindings, authority model, capacity, and lifecycle—standing teams return to ready after each sweep.
Run
One brief or operational cycle—started by heartbeat, event, or intake. Concurrent runs are capacity-managed.
Stage
One attempt within a run—input, model contribution, artifact, and recorded handoff where policy and approval attach.
Reactive vs governed
Three moments on one fabric
AI Agent Discovery gives agents an identity. Agent Teams gives them a job description.
Register
OAuth identity, delegation, discovery, import, and lifecycle governance
Deploy
Template → team charter → agent bindings → heartbeat cadence
Operate
Heartbeats, project runs, approvals, collaboration, and covered-path receipts
Governed agent operations
How it works
Agent Teams worker-tier agents follow platform governance by construction. Models contribute drafts, classifications, and summaries. The runtime owns stage advancement, validation, and evidence—not unchecked prompt-driven control flow.
Scheduler mechanics, side-effect controls, and failure semantics are covered in From Agent Pilots to Governed Operations.
A heartbeat or submitted brief starts a team run under charter.
The runtime binds team, agents, active delegation, and permitted scope.
Models generate bounded content; the platform retains lifecycle control.
Policy routes each step to execute, request input, wait for confirmation, or fail.
Governed model and tool paths produce linked evidence in the operator timeline.
Proportional autonomy
Human in the loop is meaningful only when the runtime can stop before the action—not when it is buried in a system prompt.
Contract-Driven Autonomy makes autonomy a workflow property rather than a promise buried in a system prompt. High-risk mutations pause with a structured preview—not stochastic “please ask first” instructions. Organizations can apply different operating models to observation, advice, approved action, and bounded autonomous action.
Execute
Policy permits the step to proceed
Need input
Required information is missing or ambiguous
Wait for confirmation
A human must review the proposed consequential step
Fail
Policy or runtime conditions block the step
Identity Fabric
Agent Teams does not replace the agent registry, gateways, or orchestration services. It coordinates them around durable team operations.
AI Agent Discovery registers. The gateways govern calls. Agent Teams governs how delegated agents operate together over time.
Execution stack
| Capability | Component | Role |
|---|---|---|
| Register and inventory agent identities | AI Agent Discovery | Supplies registered agents and delegation context |
| Authenticate and delegate | Identity & Federation | Establishes who or what is acting and for whom |
| Decide access | Authorization Service / PDP | Evaluates team, subject, model, tool, and execution policy |
| Govern model calls | LLM Gateway | Applies model, intent, delegation, and spend policy |
| Govern tool calls | MCP Gateway | Applies tool discovery, schema, parameter, and delegation controls |
| Execute governed workflows | Orchestration + CDA | Brokers access, runs approved work, and enforces confirmation |
| Operate teams over time | Agent Teams | Owns heartbeats, charters, runs, stages, handoffs, and fleet operations |
| Preserve operational evidence | Receipts, events, and analytics | Supplies the governance timeline and investigation context |
Agent Teams Studio
Command Center
What needs attention now—fleet health, standing teams, and conditions requiring action
Projects and teams
Brief intake, run progress, stage completion, artifacts, and handoffs
Fleet
Individual agent configuration, heartbeat status, bindings, and lifecycle controls
Gallery
Reusable templates—standing reliability, ops digest, and governed team patterns
Approvals
Structured tasks waiting for human confirmation before mutation
Governance timeline
Events and evidence from covered execution paths—not log archaeology days later
Designed for operators supervising outcomes—not developers inspecting an agent trace one prompt at a time.
Some workflows need browser interaction, local evidence capture, shell operations, or mobile approval. The paired Local Worker executes signed envelopes from the control plane—pairing-gated enrollment, supported desktop connectors, and results returned to the governed path.
Local execution does not bypass policy. It extends approved execution to a paired device while keeping the control plane and evidence path intact.
Agent Teams supports structured collaboration directives and branch runtime—multi-role crews under one charter, not two chatbots running in parallel. Operators see live execution and conversation filters through the operations stream.
Telegram, email, and other inbound channels follow a pairing lifecycle—pending, approved, rejected, or expired—before any tool runs. Inbound interaction gates stay separate from outbound contact policy.
Differentiation
Typical agent platforms optimize conversation and connectivity: prompt → plan → call tools → respond. Security is often API keys, coarse RBAC, optional guardrails, and logs. Operations are reactive—someone must open the chat.
Typical platforms ask: “Can this agent call this API?” Agent Teams asks: “May this delegated crew, on this cadence, under this charter, run this campaign—and which mutations pause for human sign-off before Orchestration executes?”
Durable heartbeat schedules with fleet lifecycle controls—not session-bound chat or cron hitting an API.
Durable teams, project runs, and staged handoffs—not ad-hoc multi-agent prompt chains in code.
Structured confirmation gates before mutation—not in-process guardrails or prompt engineering alone.
LLM Gateway and MCP Gateway govern cognition and action separately; Agent Teams consumes both as runtime.
Operational patterns
Some templates—including full customer escalation commander patterns—need scoping with EmpowerID first. Confirm wired connectors, delegation scope, and edition before production commitments.
Auto-provisioned team template monitors platform health—each sweep is a governed run with provenance, exceptions surfaced before the standup.
Identify ambiguous subjects or unresolved access conditions, request structured human input through WAITING tasks, and continue after confirmation—same IGA spine, not a separate agent stack.
Collect state from approved systems, divide research and drafting across defined roles, and publish or notify only under the team’s confirmation policy.
Detect an exception, assemble context, propose a plan, complete safe internal steps, and wait before a customer-facing or consequential change.
Enterprise trust
Authority narrows and revokes like human grants—graph-backed, PDP-evaluated.
Agents receive data and results, not OAuth secrets or vault keys.
Emergency stop without redeploying application code or rotating API keys.
Senders approved before inbound execution reaches tools.
Governance events and covered-path receipts—not vendor trace archaeology.
Outcomes
Scope boundaries
Feature availability—including heartbeat schedules, studio surfaces, Local Worker connectors, template gallery, inbound channel pairing, and evidence coverage—varies by edition, deployment, and connected systems. Contact EmpowerID to align scope with your environment.
FAQs
No. Agent Teams is a governed operations application and runtime built on the EmpowerID Identity Fabric. The IdP establishes authentication and delegation context; Agent Teams consumes that context while operating teams.
AI Agent Discovery registers, inventories, and governs the lifecycle of agent identities. Agent Teams binds registered agents into teams and operates their heartbeats, runs, stages, approvals, and fleet controls. Typical path: register in Discovery → bind to a team in Agent Teams Studio.
Reactive chat waits for a human to ask. Agent Teams runs proactive operations—scheduled heartbeats, multi-agent handoffs, and human approval at mutation gates, not in the chat loop. If you only need governed chat or registration, use those surfaces; if you need monitored operations without someone typing prompts, use Agent Teams.
Copilot Studio and similar tools build conversational apps in a vendor tenant. Agent Teams runs cross-system governed operations with heartbeats, team charters, CDA confirmations, and Identity Fabric PEPs—including connectors your enterprise already governs.
Governed agents are the platform—identity, delegation, and PEP enforcement on every model and tool call. Agent Teams is the operate application: standing crews with heartbeats, charters, staged runs, confirmation gates, and a fleet ops desk.
Digital Workforce was an earlier product name. The capability lives in EmpowerID Agent Teams and Agent Teams Studio.
No. Agent Teams consumes those controls. The LLM Gateway governs model invocations. The MCP Gateway governs tool invocations. Agent Teams governs the operational lifecycle above them.
Autonomy is configured and governed by workflow. Graded autonomy levels exist; enterprise defaults should use confirm-before-mutate for customer-facing actions rather than one mode for every agent.
Today, Agent Teams provides persistent workspace state, templates, artifacts, and durable run history. Adaptive learning from outcomes is on the product roadmap—ask EmpowerID about your use case.
Governed model, tool, and execution paths produce receipts and governance events. Cryptographic receipts are not guaranteed for every internal state transition or denied action—coverage depends on the path and configuration.
Yes—with Local Worker. Pairing-gated enrollment, signed envelopes from the control plane, and the same evidence trail as cloud execution. Local Worker does not bypass policy.
Yes. Agent lifecycle controls include pause, resume, suspend, and kill-switch operations for governed agent instances.
Online
Powered by EmpowerID AI