This series has taken AI governance apart one control at a time. This post puts it back together. Enterprises are putting five controls in place to de-risk AI, and you enforce every one of them in software. The case for that is its own post. This one is the map, a way to score where you are, and a plan for the first ninety days.
The five:
- MCP and agents. Every agent call to a tool goes through one gateway.
- Vibe-coded apps. A paved road from the AI assistant to production.
- Data handling. Policy enforced in the pipeline, for structured and unstructured data.
- Cost at runtime. Spend controlled while the work runs, before the bill arrives.
- Audit and proof. One record for agents, apps and workflows.
1. MCP and agents
Agents act with whatever access their tokens carry. The incidents of 2025 made that concrete: a poisoned issue in a public repository steered an agent using the official GitHub MCP server into leaking private repository data;1 a bug in Asana’s MCP server could expose one customer’s projects to users in other accounts;2 stolen OAuth tokens from one connected app were used to export data from many Salesforce instances;3 and a package impersonating Postmark’s MCP server copied every email to an attacker.4
The control is one front door. Whatever agent people use, it reaches your systems through a single gateway that allows only approved MCP servers, acts as the person asking, with that person’s permissions and no shared key, keeps scopes narrow, and logs every call. Gartner’s guidance on MCP makes the gateway the control plane for all agent-to-tool traffic.5 One fair caveat: other Gartner research prefers self-hosted MCP servers,6 and a CISO may raise it. The gateway pattern works either way. The control lives in identity and logging, wherever the server runs. The full argument is in one gateway for every agent.
2. A paved road for vibe-coded apps
People across the business now build working apps with Claude Code, Codex and Cursor, and many of those apps reach users with no owner, no log and a credential pasted into the code. GitGuardian found that public commits made with Claude Code’s help leaked secrets at roughly twice the baseline rate in 2025.7 Two caveats: public GitHub looks different from an enterprise repository, and GitGuardian sells secret scanning. Weigh it accordingly. Keep scanning in your build pipeline. The runtime side is what most programs lack.
I’ll make one concession plainly. Gartner has written that vibe-coded software should be kept out of customer-facing production.8 That caution is reasonable, and this post doesn’t argue against it. For the internal apps most of these builders are making, Gartner’s remedy is a governed platform with a promotion pipeline, so whatever moves to production moves through a controlled path.9
That path has to be faster than the workaround, or builders will route around it. Gartner’s guidance on scaling vibe coding puts it as making the safe path the easy one, with approved templates, secure integration patterns and deployment guardrails.10 The argument in depth is in why policy cannot govern vibe-coded apps.
3. Data handling in the pipeline
Start with people. In a University of Melbourne and KPMG study of more than 48,000 people in 47 countries, almost half admitted uploading sensitive company information into public AI tools, and only around two in five said their employer had a policy on AI at all.11 The fieldwork is now well over a year old; nothing since suggests the behaviour has declined.
The problem splits two ways. With structured data in CRM, ERP, HR systems and warehouses, the risk is scope: an agent querying with more access than the person who asked, and sensitive fields flowing into prompts and logs. With unstructured data in contracts, tickets, PDFs and email, there’s no schema, so there’s no column to mask. Sensitive fields hide in free text, and you have to classify and extract before you can protect anything.
Gartner’s data governance research makes the point that governance scales only when it operates where the data runs, with controls built into pipelines and platforms in place of manual escalation, and it ends with technical controls such as redaction and tokenization applied as policy in code.12 In practice that means four steps in the path: classify and extract, including from documents; mask or tokenize sensitive fields before anything reaches a model; check access at call time so the agent sees only what the person asking may see; and keep sensitive fields out of the logs. Teams forget the last one. The logging you added for audit can become the leak.
4. Cost at runtime
Most organizations see AI cost late, and agents make it less predictable: retry loops and growing context windows move spend in ways a monthly invoice cannot explain. The destination is a set of controls that act at runtime: tag every run, give users and teams budgets, route non-critical work to cheaper models, and limit what any single run can spend.
The step most programs skip is the one that makes those controls possible. You can’t set a budget for spend you can’t assign to an app, a team and an owner. That argument has its own post: before you cap AI spend, attribute it.
5. Audit and proof
Regulators, auditors and insurers increasingly ask to see evidence of control. Evidence is a record written as things happen: for every action by an agent, an app or a workflow, who asked, which identity it ran as, which system and data it touched, what it cost, and who owns the thing that did it. The hard part is having one record at all. If agents, apps and workflows each run somewhere different, you have 3 logs with 3 identity models, and the auditor’s question falls between them. The depth is in evidence regulators and insurers now ask for.
Score your program
For each control, be honest about where you are. Written policy only means a rule exists and depends on people remembering it. Partly enforced means some of the traffic goes through a control and some goes around it. Enforced in software means it happens whether or not anyone remembers.
| Control | Written policy only | Partly enforced | Enforced in software |
|---|---|---|---|
| MCP and agents | An approved-tools list | A gateway some agents use | Every agent-to-tool call goes through one gateway, logged |
| Vibe-coded apps | An acceptable-use policy | A review board for apps that ask | One deploy path with identity, credentials and an owner attached |
| Data handling | Training on what not to paste | Masking on some systems | Classification, masking and access checks in the pipeline |
| Cost at runtime | A monthly invoice review | A dashboard by provider and model | Spend tagged to app, team and owner as it happens, with controls on top |
| Audit and proof | Logs gathered after an incident | Separate logs per tool | One record across agents, apps and workflows |
In most rooms, the weakest rows are cost and audit, because both need the other three in one place first. If AI governance has no owner in your organization yet, every row is in the first column. Gartner’s newest maturity tool treats progress as moving one program element at a time over a planned horizon,13 which in practice means picking the row you scored lowest and starting there.
The first ninety days
- 1
Inventory, weeks 1 and 2
Find every agent, every MCP server in every developer config, and every AI-built app someone is running. Offer an amnesty. You’ll find more than you expect.
- 2
One gateway, weeks 3 and 4
Route agent-to-tool calls through a single gateway. Start with an allow-list of approved servers.
- 3
Paved road, weeks 5 to 8
Give builders one command to a governed deploy, and make it faster than the workaround.
- 4
Data and spend, weeks 9 and 10
Mask sensitive fields in the pipeline. Attribute spend to apps, teams and owners, then set team budgets and alerts.
- 5
Evidence, weeks 11 to 13
Pull one audit report across agents, apps and workflows and hand it to your security lead. If that takes a day of stitching, you have found your next project.
Measure progress the way Gartner suggests in its guidance on scaling AI-built software:10 how much of the building happening across the business goes through governed paths; how long it takes an idea to reach production safely; how many prototypes make it to production; and how often teams reuse approved components. Watch time to safe delivery most closely: if the governed path is slower than the workaround, the other three won’t move.
Where Tray and Tray Helix fit
Tray builds for these controls on one foundation, so agents, apps and workflows share the same identity and SSO, credentials, access control and audit. Tray Helix is the paved road: one command takes an app built in Claude Code, Codex or Cursor to a managed runtime with SSO, scoped roles, managed credentials so no secret sits in the code, a named owner and registry entry, execution logs, an audit trail, and AI and compute spend visible for every app. Tray also has a full iPaaS, where the Agent Gateway exposes more than 700 Tray connectors as governed MCP servers with an audit of every call, and immutable logs with step replay record what every workflow did.
Footnotes
-
Invariant Labs, disclosure of the GitHub MCP prompt-injection issue, May 2025. Back
-
Asana’s disclosure of its MCP server bug, June 2025, as reported by UpGuard, June 2025. Back
-
Google Cloud and Mandiant, advisory on the Salesloft Drift OAuth token compromise, August 2025. Back
-
Koi Security, via The Hacker News, September 2025. Back
-
Gartner, G00851029, Pasricha, Guttridge, 22 May 2026. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. Back
-
Gartner, G00839394, November 2025. Back
-
GitGuardian, “State of Secrets Sprawl 2026,” 17 March 2026, analysis of roughly 1.94 billion public commits made in 2025: commits made with Claude Code’s help leaked secrets at 3.2%, against a 1.5% baseline. Public GitHub is not representative of enterprise repositories, and GitGuardian sells secret-scanning products. Back
-
Gartner, G00843895, 15 June 2026. Back
-
Gartner, G00860022, 20 July 2026. Back
-
Gartner, “How to Scale Vibe Coding Using Low-Code Engineering Principles,” G00857758, Mukul Saha, 11 August 2026. Back Back
-
University of Melbourne and KPMG, “Trust, attitudes and use of artificial intelligence: A global study 2025,” survey of 48,340 people in 47 countries, fielded late 2024 to early 2025. Academic co-author; no vendor sponsor. The data predates the agent tools that have spread since. Back
-
Gartner, “Building Blocks for Effective Data Governance in the Age of AI,” G00853417, Amy Bickel, 13 July 2026. Back
-
Gartner, “Tool: AI Governance Program Maturity Assessment,” G00862675, 24 September 2026. Back
