Enterprise guide

Enterprise Agent Plugin Governance

Enterprise AI governance should focus on the capability boundary. The plugin is that boundary: installable, owned, versioned, instrumented, and reviewable.

Publish the product

Use Telvine when the plugin is ready to be treated like software.

The first useful milestone is simple: one plugin directory, one owner, one release record, and one measurement model.

npm i -g @telvine/cli
telvine login
telvine publish ./my-plugin

The control point

Enterprises are moving from AI experiments to systems that take action. That creates a simple question: what exactly did we approve? If the answer is a folder of prompts and undocumented tool calls, the operating model will not hold.

A plugin gives the enterprise a control point. It can have an owner, purpose, component inventory, permissions, test evidence, telemetry contract, lifecycle state, and retirement path.

What governance should cover

A plugin governance model should be practical enough that teams use it. The aim is not to block every capability. The aim is to make the installable unit clear and the operating evidence visible.

Telvine is designed around this evidence record. It stores plugin versions, component inventory, metadata-only telemetry, eval results, feedback, outcomes, and promotion decisions.

  • Plugin owner and business purpose.
  • Approved harnesses and deployment surfaces.
  • Skills, connectors, tools, hooks, MCP config, commands, and assets.
  • Data handling, permission scopes, and operational limits.
  • Telemetry events, eval gates, version comparison, and rollback criteria.

From approval to improvement

The first approval is only the start. Agent behavior changes as models, tools, policies, and workflows change. Governance needs release evidence, not static paperwork.

That means every meaningful plugin version should be compared against the last stable release on errors, latency, outcome quality, feedback, and eval pass rate.

Where it applies

Use cases that deserve a maintained plugin

Platform teams

Standardise how agent capabilities are requested, packaged, evaluated, approved, and promoted.

Security teams

Review capability boundaries, data handling, component inventory, and connector scopes.

Business operations

Adopt useful agent workflows without losing sight of owners, versions, and measured outcomes.

FAQ

Common questions

What is agentic AI governance?
Agentic AI governance is the operating model for AI systems that can plan, call tools, access systems, and complete tasks. Plugin governance makes the approved capability package explicit.
Why govern plugins instead of prompts?
Prompts are not the full product. The plugin includes the instructions, tools, connectors, hooks, assets, permissions, telemetry, and release evidence that determine real behavior.
Does Telvine store sensitive prompts or outputs?
No. Telvine uses metadata-only events and does not emit prompts, file contents, connector payloads, tool arguments, or model outputs.