# Discussion History

## 2026-09-16 — Report structure consolidation

- Removed the research-scope/method chapter and the phased-delivery chapter.
- Merged AGT technical assessment and broader industry positioning into one chapter.
- Merged CAF fit, build-versus-reuse decisions, and the bounded AGT evaluation into one chapter.
- Renumbered the report and updated the outline and cross-references.

## 2026-09-16 — Policy-language analysis

- Added a standalone chapter distinguishing serialization, structured policy models, expression languages, policy DSLs, relationship models, decision APIs, and authoring interfaces.
- Compared Rego/OPA, Cedar, CEL, OpenFGA/SpiceDB, XACML, Casbin/Polar, Kubernetes admission policy, and business-rule models.
- Added policy-authoring mechanisms to the Section 3.2 product comparison.
- Removed source hyperlinks from the On-prem cells while retaining the evidence-based classifications.
- Added an outline at the beginning of the report.

## Current understanding

- The active project is `agent-governance`.
- The requested research covered AI-agent governance tools, generic governance foundations, Microsoft Agent Governance Toolkit, and CAF v2 reuse versus custom development.
- The complete English report is `report.md`; detailed source memos are preserved under `raw-research/`.

## Research conclusions

- No single product provides complete portable agent governance. The market is compositional across identity, policy, enforcement, isolation, evidence, evaluation, compliance, approval, and incident response.
- Microsoft AGT is best positioned as agent runtime governance middleware: a broad, promising public-preview policy/enforcement SDK and reference architecture, not an enterprise IAM, sandbox, SIEM, GRC, or complete managed governance platform.
- AGT's value depends on complete mediation through trusted host/framework paths. Its identity and audit primitives require enterprise authority, durable storage, and hard host controls.
- CAF should remain an agent-runtime compatibility and evidence layer for managed HPC rather than becoming a general governance platform.
- CAF should build its runtime-neutral contracts, adapters, conformance suite, HPC facades, and application evidence semantics while reusing host mechanisms.
- AGT should be evaluated as an optional provider behind CAF-owned interfaces; it should not define CAF's identity authority, public schema, or hard security boundary.

## Recent changes

- Completed seven evidence workstreams, preserved as separate research memos.
- Preserved the raw research in the project workspace.
- Drafted and independently reviewed the full report.
- Corrected the market comparison to separate inventory from identity and restored risk, compliance, and incident-response dimensions.
- Added generic-tool licensing/deployment choices, commit-pinned AGT evidence, exact Pi MVP version, missing CAF execution-profile/OCI/MCP decisions, and correct ACS approval semantics.
- Completed structural and critical-link QA.
- Converted the final report to `agent-governance-report.docx` using the project-local repeatable converter `scripts/md_to_docx.py`.
- Verified the current DOCX package, heading outline, nine tables, opening title, and final conclusion. LibreOffice was unavailable, so no rendered PDF/layout preview was produced.
- User correctly identified that Microsoft AGT was missing from the Section 3.2 comparison table because it had been isolated into the Section 6 deep dive. Added AGT to the horizontal comparison as the focal open-source runtime-governance comparator and retained Section 6 for detailed evidence.
- User made on-premises self-deployment a first-class comparison criterion. Added an evidence-linked `On-prem self-deploy` column to Section 3.2 and preserved the detailed evidence in `raw-research/on-prem-self-deployment.md`.
- Verified the user's hypothesis: among 23 rows, 7 are fully self-deployable, 7 partial/hybrid, 8 hosted-only, and 1 mixed. Large cloud-native suites are mostly hosted-only; IBM is the clearest large-platform software exception, while open-source middleware/gateways have the strongest self-host posture.

## Open questions

- Should the next phase be the proposed bounded AGT/ACS versus minimal OPA/Cedar technical spike?
- Does the user want a shorter executive brief or presentation derived from the report?
