Ready to scale your workflows?

Did you know about a string of AI-agent incidents this year? It turned agentic AI governance from a nice-to-have into a board-level question.
Reports of autonomous agents escaping sandboxes and pulling data from systems they were never meant to touch. These incidents pushed identity and security vendors to act together, not separately.
That response arrived at Okta's Oktane 2026 conference in Las Vegas. That's where Okta announced runtime enforcement and a kill switch for its own AI Agents platform. At the same event, Okta joined 11 other vendors, including Amazon Web Services, CrowdStrike, and Google Cloud, to form the Blueprint Alliance.
The group's goal? Reworking the agent security framework Okta first published in March into an open, multi-vendor reference architecture.
This matters well beyond identity and security teams. Does your organisation run agentic AI inside monday.com, HubSpot, or any other operational platforms? Then, the same governance gaps apply to you.
This post walks through what the Blueprint Alliance actually recommends. Turn it into a checklist to run against your own AI agent governance before you scale agentic AI further.
Let's have the short answer. Most organisations cannot say where their agents are, what they can do, or what they are doing right now.
That is not a hypothetical gap.
LastPass's research found that 92% of business admins say AI is already in use across their organisation. However, only 27% have an enforced AI governance program.
Okta's own research tells a similar story. More than 90% of executives are confident that their organisation can detect AI acting outside its intended scope. Yet barely 34% of executives reported they always apply the same security controls to the digital labour force as they do to the human labour force.
Gartner's numbers are blunter still. Only 13% of organisations believe they have the right agent governance in place. Even then, they predict that the agent population inside large enterprises will keep climbing through 2028.
We'll get a clearer picture by putting all these data points together. That is, 'adoption has outrun governance almost everywhere.' monday.com workflows are not exempt just because they sit outside the security team's usual line of sight.

The Blueprint Alliance's first published guidance centres on four questions every business should be able to answer for its own agents:
That fourth question is the one most teams fail first.
Agents operate at machine speed. Hence, a response process built for human-scale incidents (tickets, escalations, next-day reviews) is already too slow.
Picus Security's Umut Bayram put it plainly to ZDNet: organisations cannot fight minute-scale attacks with day-scale processes. That's because attackers, and misbehaving agents, are already operating faster than that.
It is worth noting that "respond" does not only mean stopping a malicious agent. A well-intentioned agent stuck in a loop can burn through an LLM budget in hours.
This kill-switch discipline the Alliance is pushing protects against runaway costs just as much as it protects against genuine security incidents.


monday.com is not immune to any of this. Just deployed AI agents through the AI Agent Factory? You literally created new non-human identities with access to boards, automations, and integrated data.
Will their tasks be affected by the new AI governance rules? No, they can still qualify leads, triage support tickets, or prioritise engineering bugs.
Ready-made agents can:
That is genuinely useful. However, this is the kind of standing access the Blueprint Alliance is warning about. Can you track what each agent can reach?
You need to understand the difference between a controlled rollout and a retrofit nobody enjoys. That'll be governance built into workflow logic, not bolted on after deployment.
Escalation rules, audit logs, and role-specific permissions need to exist before an agent goes live. Why? That's because retrofitting controls onto agents already running production workflows is far harder than designing them in from the start.

Before you turn on another autonomous agent inside monday.com or any connected system, run through this list:
Don't consider these as abstract best practices. They actually mirror what the Blueprint Alliance is pushing at the identity layer, applied to the operational layer where your teams actually work.
Agentic AI isn't going anywhere. The industry will grow at a 40.2% CAGR, reaching USD 205.88 billion by 2033 from USD 19.33 billion in 2026.
However, the risk that comes with autonomous AI isn't going away either. That'll only be an issue if you deploy it carelessly. The Blueprint Alliance's four questions give you a simple, honest way to check whether your monday.com workflows are actually governed or just running unsupervised.
Run the checklist above before you add the next agent to your stack, not after something forces the question. If you want a second set of eyes on your governance posture or your next monday.com rollout, contact Fruition for a free consultation.
AI agent governance is the set of controls that let a business see where its autonomous agents are, what they can access, what they are doing, and how to shut them down quickly. It covers permissions, audit trails, escalation rules, and incident response, applied to software agents the same way identity and access management applies to human employees.
You need a fast, tested way to pause or revoke an agent's access, whether that is a formal kill switch or a documented manual process. Given how quickly agent activity can escalate, from data exposure to runaway LLM costs, waiting on a slow approval chain is not a workable fallback.
The Blueprint Alliance is building an identity-and-access framework at the infrastructure layer, led by Okta alongside AWS, Google Cloud, and other major vendors. monday.com sits at the workflow layer above that, so the same governance principles apply, but they get implemented through board permissions, automation rules, and agent configuration rather than through an identity provider directly.