---
title: "Google Managed Agents Control Matrix"
canonical_url: "https://move78int.com/google-managed-agents-control-matrix.html"
source_html: "https://move78int.com/google-managed-agents-control-matrix.html"
page_type: "tool_page"
primary_keyword: "Google Managed Agents control matrix"
secondary_keywords:
  - "Gemini Enterprise Agent Platform governance"
  - "AI agent control matrix"
  - "managed agent permissions"
  - "agentic AI governance evidence"
target_audience:
  - "CISO"
  - "CTO"
  - "engineering lead"
  - "AI governance owner"
  - "security reviewer"
product_ladder_destination: "ACT-2, Implementation Sprint"
primary_schema_type: "WebApplication"
schema_types:
  - "WebPage"
  - "WebApplication"
  - "BreadcrumbList"
  - "FAQPage"
date_published: "2026-05-23"
last_updated: "2026-05-23"
last_reviewed: "2026-05-23"
owner: "Move78 International Limited"
commercial_route: "ACT-2, Implementation Sprint"
claim_control: "Informational implementation-support content only; not legal, audit, certification, procurement, secure-code-review, or security assurance."
---
# Google Managed Agents Control Matrix

**URL:** https://move78int.com/google-managed-agents-control-matrix.html  
**Last reviewed:** 2026-05-23  
**Owner:** Move78 International Limited

## Direct answer

If an AI agent can call tools, read or write files, browse the web, execute code, or update systems, it needs a control matrix before wider rollout. The minimum evidence set is purpose, owner, data access, tool permissions, code boundary, external actions, approval gate, logs, incident route, and shutdown owner.

## Who should use this

Use this page if your team is evaluating Google Managed Agents, Gemini Enterprise Agent Platform agents, Antigravity workflows, or similar agentic AI systems.

## Control matrix scoring

Missing = 0. Documented = 1. Enforced with evidence = 2. Maximum score = 24.

| Score range | Readiness signal | Recommended route |
|---:|---|---|
| 0-7 | Not ready for agent rollout | Do not widen rollout until purpose, permissions, approval, logs, and shutdown evidence are documented. |
| 8-14 | Partial control coverage | Use ACT-2 if agents may touch files, code, tools, tickets, or customer data. |
| 15-20 | Managed, but not yet board-ready | Use ACT-2 or evaluate the Implementation Sprint. |
| 21-24 | Strong first-pass agent control | Use the Implementation Sprint for complex rollout, assurance review, or executive evidence packaging. |



## What the matrix is testing

The matrix reduces managed-agent review to five control questions.

| Area | Question | Evidence to keep |
|---|---|---|
| Permissions | Can the agent touch only approved tools and data? | Permission register, access decision, approved connector list. |
| Approval | Which actions need human review first? | Approval rule, reviewer role, retained approval record. |
| Execution | Can the agent execute or change anything important? | Sandbox rule, change log, code review record, deployment separation. |
| Observability | Can the team reconstruct what happened? | Prompt/tool-call logs, file change records, incident notes, retention location. |
| Shutdown | Who can stop the agent and preserve evidence? | Shutdown owner, revocation path, escalation contact, rollback note. |

## Control rows

| Control | Evidence question |
|---|---|
| Agent purpose and scope | You can describe what the agent is allowed to do and what outcome it supports. |
| Business owner | A named accountable owner approves the agent use case and accepts residual risk. |
| Data and file access | The team knows what files, repositories, tickets, documents, or datasets the agent can read or write. |
| Tool and skill permissions | The agent's tools, skills, APIs, and connectors are listed and reviewed before use. |
| Code execution boundary | Code execution is constrained, reviewed, and separated from production deployment authority. |
| Web browsing and external fetch | The team controls how the agent fetches, processes, and trusts external web content. |
| External system actions | Record updates, ticket changes, emails, commits, deployments, or workflow actions require clear approval rules. |
| Human approval gate | High-impact actions need a defined human approval point before execution or external release. |
| Agent identity and access | The agent has controlled identity, least-privilege access, and no shared human credentials. |
| Logging and observability | Prompts, tool calls, file changes, decisions, approvals, and errors have a known retention location. |
| Incident escalation and shutdown | Someone can stop the agent, revoke access, preserve evidence, and escalate if behavior is unsafe. |
| Versioning and change review | Agent instructions, skills, permissions, and configuration changes are versioned and reviewed. |

## ACT route

- Use ACT-2 when managed agents need inventory, control mapping, approval evidence, incident route, board reporting, and buyer assurance.
- Use the Implementation Sprint when agent permissions, ownership, logs, or system actions are unclear and leadership needs a defensible rollout path.

## Source basis

Public sources reviewed on 2026-05-23:

- Google I/O 2026 announcements: https://blog.google/innovation-and-ai/technology/ai/google-io-2026-all-our-announcements/
- Google Managed Agents announcement: https://blog.google/innovation-and-ai/technology/developers-tools/managed-agents-gemini-api/
- Managed Agents API documentation: https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents
- Gemini Enterprise Agent Platform overview: https://docs.cloud.google.com/gemini-enterprise-agent-platform/overview
- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework
- ISO/IEC 42001 public overview: https://www.iso.org/standard/42001

Move78 materials are informational and implementation-support resources only. They are not legal, tax, regulatory, audit, certification, conformity-assessment, procurement, or security advice.
