---
title: "Your Agents Are Code. Stop Governing Them Like Documents."
url: "https://atlan.com/context-and-chaos/issue/your-agents-are-code-not-documents/"
description: "You cannot inventory agents fast enough to govern them. You can govern the parts they are made of: the skills, tools, credentials and memory underneath every one."
keywords: "AI Agents, AI Governance, Enterprise AI, Data Governance, Context Engineering"
---

> Atlan is hosting Context Conference, bringing together the leaders and builders at the frontier of giving AI the context it needs to understand their business. It runs online on October 28, 2026, from 11:00 AM to 2:00 PM ET. Atlan co-founder Prukalpa Sankar opens and closes the day. Leaders from AstraZeneca, BNY and Verizon share why they invest in context and what they get from it. Registrants get early access to The AI Context Gap, a new study from MIT Technology Review Insights. Register: https://atlan.com/context-conference/

A Context & Chaos issue (Atlan's practitioner newsletter) by **Vivek Dubey, Data & AI Leader at Atlan** (product, growth and community). Published August 6, 2026, 10 min read. You cannot inventory agents fast enough to govern them; you can govern the parts they are made of.

Key points:

- An agent is not an atomic thing you list and approve like an application. It is a composition of skills, tools, MCP servers, credentials, knowledge and memory, and those parts are the only pieces stable enough to govern.
- Ownership attached to an agent expires when someone renames it. Ownership attached to a skill survives every agent built on it, so governing a level down also covers agents nobody registered.
- Source control is the wrong half of the toolchain. A repository holds file versions; it cannot say which agents depend on a skill, what breaks when it changes, or what it costs to run. Those are registry questions.

## The problem

An executive asks for a list of every AI agent in production. The number is larger than expected, mostly built by people who never filed a ticket, nobody maintains the list, and the deadline is weeks. A hand-kept registry cannot keep pace with agent creation.

## Why the demand arrived all at once

- Coding assistants made building an agent something a sales rep assembles on a Tuesday afternoon. Governance was designed for software that arrives through procurement; now it arrives through enthusiasm.
- [McKinsey's 2025 State of AI survey](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai) (1,993 respondents, 105 countries): 62% of organizations at least experimenting with AI agents, 23% scaling in at least one function; among organizations using AI, 51% saw at least one negative consequence in the previous year. Neither number captures who was answerable for any agent that went wrong.

## The current playbook governs the wrong unit

- Procurement-led control towers inventory purchases: they see the licensed assistant, not the agent assembled inside it last week.
- Privacy and compliance platforms inventory approvals: they assess a use case at approval and never see the tool connection swapped in three weeks later.
- Both assume the agent is the unit of governance. That assumption is where the playbook breaks.

## An agent is a composition; the parts hold still

- Behind the prose-like canvas, an agent is code composed of artifacts: skills, tools, MCP servers, credentials, knowledge folders, memory.
- [Prukalpa Sankar on Context & Chaos](https://contextandchaos.substack.com/p/how-to-make-satya-nadellas-vision) argued a skill is a primitive: a reusable, versionable, testable unit of how-to, managed like code.
- Agents are the least stable object: renamed, forked, cloned, abandoned when owners change teams. The same dozen skills and few tool connections keep reappearing underneath.
- **Skills bite first:** the most reused artifact, so the widest blast radius and the most people downstream of an unannounced edit. Governance attached to parts holds through churn, including unregistered agents, because every agent is made of something.
- [Joe Reis](https://joereis.substack.com/p/your-agents-are-stuck-in-your-org): agents pointed at a siloed company produce more silos, faster; they need access, shared semantics and a human who owns the result. That human has to own something durable, so attach the person to the skill.

(Diagram: the agent gets renamed, the skill keeps its owner.)

## The discipline is familiar; only the artifact list is new

- Data teams spent two decades cataloging tables, views and columns, tracing lineage, naming owners, and treating the description of an asset as an asset.
- [Juha Korpela](https://contextandchaos.substack.com/p/conceptual-modeling-is-the-context) argues conceptual modeling is what agents need and semantics should be governed as its own layer; [Jessica Talisman](https://contextandchaos.substack.com/p/ontologies-context-graphs-and-semantic) set out the vocabulary for that layer.
- What agent artifacts lack is tooling: skills that are code libraries get filed like documents in office suites, shared drives and weekend-built trackers.

## Where source control falls short

Source control holds file versions, not relationships. It does not hold the dependency graph between skills, know that a skill is used by five agents or which broke after this morning's edit, know who uses what, or know what anything costs to run. Skills also do not need branching; consumers need audit history, versions and a named owner. The closer analogy is a **package registry**: who depends on this, which version is safe, what breaks if it changes. The request looks like a version control problem; it is a registry problem.

## Artifacts live at several altitudes

Artifacts belong at company, department, team or person level. Governance must handle promotion upward, inheritance downward, layering and precedence. On the author's estate, a company-wide instruction file pushed to every machine overwrote individuals' local instructions; nobody was notified because nothing knew two artifacts at different altitudes competed for the same slot. A spreadsheet has no column for this.

(Diagram: context has altitude — company, department, team, person — and who overrides whom.)

## What good looks like

1. **Derive the inventory instead of collecting it.** Form-based registries never keep pace. Agents leave traces: every session carries attribution for which agent ran, which skills it invoked and which tools it touched. On the author's estate, inventory derived from what actually runs is the only kind that stayed accurate, and it survives a rename.
2. **Lifecycle over a list.** Versions, audit history, named owners, promotion across altitudes, and the ability to pull one artifact and know which agents just lost a dependency: the kill switch an incident asks for first.
3. **Attach cost to the artifact.** License costs are fixed; token costs follow usage and compound. Until spend traces to agents and their artifacts, nobody knows which agents return value and which are duplicates. [Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027](https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027), citing escalating costs, unclear business value or inadequate risk controls; two of the three are visibility problems.

## Start with one skill

Pick one skill used by more than one agent. Ask who owns it, which agents depend on it, and what breaks if you delete it tonight. If that takes more than five minutes, the skill is not governed, and neither is anything built on it. [Gartner predicts the average global Fortune 500 enterprise will run more than 150,000 AI agents by 2028](https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl), up from fewer than 15 in 2025. The answer that survives: what agents are made of, who owns those parts, and what happens when one changes.

Closing cartoon: two cats in a lab beside a stitched-together AI agent and a tray of labelled spare parts; caption: "Congratulations. Now who owns the arm?"

## About Context & Chaos

A community newsletter where practitioners, builders and thinkers share stories and lessons on context engineering, governance, architecture, discovery, and the human side of data and AI work. [Browse all issues](https://atlan.com/context-and-chaos/) or [contribute](https://atlan.com/context-and-chaos/contribute/).

Related reads:

- [Conceptual Modeling Is the Context Engineering Nobody Is Doing](https://atlan.com/context-and-chaos/issue/conceptual-modeling-is-the-context-engineering-nobody-is-doing/) (April 2026)
- [Ontologies, Context Graphs, and Semantic Layers: What AI Actually Needs in 2026](https://atlan.com/context-and-chaos/issue/ontologies-context-graphs-and-semantic-layers-what-ai-needs-in-2026/) (January 2026)
- [Data Governance vs AI Governance: Why It's the Wrong Battle](https://atlan.com/context-and-chaos/issue/data-governance-vs-ai-governance-why-its-the-wrong-battle/) (March 2026)