Article

Five questions to ask before an AI agent gets the keys to your governance record

Thomas Thejn5 min read

Before an AI agent gets access to a programme record, a PMO should ask five things. Does the agent act as a named user with that user's roles? Does every write record which surface made it? Is every change a preview a person confirms? Can every claim be traced to the record? And where does the model run?

Letting an AI agent into your governance record is a bit like lending someone your car.

You want to know who is driving. You want to know where they are going. You would like it back in one piece. And if it comes back with a dent, you would like to know who put it there, rather than a shrug and "it was like that when I got in".

The vendor demo never covers any of this. The demo is the bit where the car looks lovely in the showroom. Someone types "summarise the risks on the ERP programme", a fluent paragraph appears, and twelve senior people nod. Nobody asks for the keys, the insurance, or the name of the driver.

So here are the five questions I would ask before an agent gets anywhere near a CIO's IT and digital transformation portfolio. Each comes with the answer TransformRadar gives, so you can hold us to it too.

1. Who is driving?

The wrong answer is "the agent has a service account". A service account is a driver with no name and, usually, a set of keys to every car in the building. Its actions all look the same in the log. If the agent can read every project in the organisation because that was easier to wire up, your programme record has just acquired a reader that nobody invited to the party.

The right answer is that the agent is you. Same name, same roles on each project, same limits. In TransformRadar that is structural rather than a promise: an agent connected over MCP and Blip inside the product both run every call through the same permission check as a click in the interface. A viewer's agent is a viewer. A lead's agent is a lead. There is no secret third kind of user with a better parking space.

2. Who put the dent there?

Six months from now someone will ask why a risk was closed on the third of March. The audit trail needs to answer with a person, a time, and the route the change took. If the answer is "the API", the trail has a hole in it exactly where the AI is standing, whistling.

Every mutation in TransformRadar records which surface made it: the interface, an external agent over MCP, or the in-app assistant. Every AI call is logged with who triggered it and which artefact it relates to. The prompt and completion are kept for thirty days for review and then removed; the metadata stays, so the dent always has a name next to it.

3. Can it change the record without you?

This is the question that separates a governance tool from a chatbot that has found the database. A model that flips a RAG to green because it judged the evidence sufficient has replaced the project lead's judgement with its own, quietly, at 2 a.m. The steering group can no longer assume a human stood behind the number. That is not a feature. That is a poltergeist.

TransformRadar's write tools never touch the record directly. Each one prepares the change and returns a preview: a readable summary, the state before, a signed token valid for ten minutes, and a fingerprint of the current state. A separate commit, driven by the person confirming, applies it. If the record moved in between, the commit is refused rather than applied to stale data. The model is not given the commit tool. The confirmation belongs to the product, not to the prompt.

4. Where did that sentence come from?

Ask the vendor to show you the source of one sentence in the AI's summary. If the answer is "the model's understanding of the project", you are looking at fluent guesswork, and the guess will be most confident exactly where your record is thinnest. That is how you end up presenting a risk about "integration testing capacity in Q3" that nobody has ever raised, to a sponsor who asks who owns it.

Every prompt TransformRadar sends carries the structured data that licenses every claim in the answer, and tells the model to mention nothing outside it. Output is validated against a schema before a person sees it. A health drop with no traceable cause in the record produces a draft that says "no traceable cause in the record", which is less exciting and far more useful. The next post is entirely about this.

5. Where does the car go at night?

An agent that reads a transformation programme is reading the most sensitive description of a business that exists: what it is trying to change, where it is failing, what that costs, and who is accountable. Where the inference runs, who operates it, and whether the provider trains on what it sees have stopped being procurement footnotes and become product questions.

TransformRadar's own AI runs on Mistral La Plateforme in Paris, on a chain of European providers none of which trains on customer data. The one exception is deliberate and visible: connect your own agent over MCP and that agent's provider handles the conversation, which is why an Org Admin has to acknowledge it before external access can be switched on. The EU hosting page has the full arrangement.

What a good answer sounds like

A vendor who can answer all five without a pause has built the boring parts first: one permission model, one audit trail, one route to a mutation, one grounding rule, and a straight answer about where the data goes. Those are the foundations that let a CIO hand an agent real keys to a real programme.

A vendor who answers with a roadmap is asking you to be the crash test.

The MCP access page shows what the five answers above look like once an agent is actually connected.

  • AI
  • agentic AI
  • governance
  • PMO
  • MCP