A gate nobody owns is a formality: promotion between zones requires a named approver with authority to say no, defined evidence per tier, and a recorded decision; the form is the least important part.
This page carries process and authority only. Why gates exist at zone boundaries is argued in three-zone architecture; the printable gate checklists live in templates and checklists.
The checklist
1. Fire the gate on blast radius, not on sophistication. The three independently sourced triggers all measure reach rather than cleverness. Microsoft’s is sharing breadth: an agent going beyond a small group belongs in a managed environment. BCG’s is contact with enterprise systems. BMW’s, predating agents entirely, was a user count greater than one. A trade-press synthesis adds popularity, sensitive data, workflow change, customer impact, criticality and business dependency; that list is the most usable and the weakest-sourced in this bundle, so it serves better as a starting draft to endorse locally than as a standard to cite. Whatever the trigger, it has to be checkable by someone who did not build the thing.
2. Name the rungs, then name what each one costs. Three sources converge on a ladder, which is the strongest structural finding here: WEF’s sandbox → controlled deployment → full deployment, BCG’s shadow → supervised → guided autonomy → full autonomy, and Anthropic’s observed usage trajectory. Four rungs is enough. A rung states what the agent may do unsupervised, and to what, rather than marking maturity.
3. Set the evidence bar per rung, and keep it to what a gate can honestly attest. ISO/IEC 42001’s A.6.2.5 is the citable form: a documented deployment plan, defined release criteria, verification and validation, performance metrics, user testing, and management sign-off before release. Chan et al. supply the honesty constraint: certify only what is feasibly knowable. A gate can attest which tools the agent reaches, its authorized autonomy level, and how it handles sensitive data. It cannot attest that it will never violate a safety constraint, so no criterion should pretend otherwise. Concretely: eval results against a fixed suite (evals), the tier score and its inputs (risk-tier assignment), a named owner, and a data-access map.
Add one compliance criterion at every rung above personal use, answered by someone who can answer it: does this agent produce a record in a required category, touch MNPI, or communicate with a client. A gate that never asks cannot say which agents sit inside the compliance program (see compliance as an approver).
4. Separate the author from the approver. AWS’s Cloud Adoption Framework prescribes an author/approver/publisher split for model release, and ISO 27001’s change-management control carries the same segregation independently. Cite AWS as lineage only: its own page now carries a historical-reference banner, it is pre-agentic, and elsewhere it recommends input validation to separate data from instructions, an approach prompt injection argues against.
5. Promote by rebuilding, not by widening a share link. Microsoft’s sharpest sentence is that an agent in demand should be rebuilt or promoted into a managed zone, never scaled in place from a personal environment. The pre-agent evidence agrees: in one MISQE case pair, the firm that re-architected its no-code build into the platform framework succeeded, and the one that replaced it without architecture fell short. Reliability, capacity and cost displace flexibility as the driving forces at exactly this moment, and that is a rebuild, not an approval.
6. Automate the checkable part; escalate the rest. One firm in the MISQE study pointed an RPA bot at each citizen-built app to check security-role configuration and drive approve or reject, with findings returned to the builder. Note the scope: it checked configuration rather than judgment. That supports automating the mechanical pre-screen ahead of human review, and stops short of automating the gate itself.
The $90 million version of skipping this: the SEC’s 2025 Two Sigma settlement turned in part on an employee making unauthorised changes to more than a dozen investment models, unsupervised. A gate that only fires at launch would not have caught it (see regulatory exposure).
Where external authority for the pre-deployment step is wanted instead of the architectural argument, FINRA supplies it for member firms: a firm “should evaluate Gen AI tools prior to deploying them” and confirm it can still comply with the rules that apply to the business use of those tools (Regulatory Notice 24-09, 2024-06-27). That is an expectation, not a prescribed procedure, and the notice creates no new requirement, but it is still a regulator saying the evaluation happens first.
7. Gate updates, not just launches. Microsoft’s own guidance requires review and sign-off before promoting any update to production, not only at first release. This is the step most firms skip, and it is where capability creep enters.
8. Publish a turnaround time and delegate below it. A gate slower than the shadow path governs an empty set. Red Access puts the precondition plainly: the registration path has to be lower-friction than staying hidden, and the steps worth governing are connect, deploy and access, not ideation and building. Delegate low-risk approvals to federated approvers working to central standards, so the queue never becomes the argument against the gate.
9. Record the decision, because the record is the control. Kolt reads Restatement (Third) of Agency § 7.05(1) to attach principal liability to negligence in selecting, training, supervising or controlling an agent, liability not confined to the scope in which the agent was deployed. A documented gate decision is precisely the evidence that those choices weren’t made negligently. Boundary: § 7.05 governs human agents, Kolt argues the rule could extend, and no court has held that a gate discharges the duty, so build against the reasoning and don’t cite it as settled law.
One framing earns credit cheaply. A promotion gate is ISO 27001’s 8.31 and 8.32 read together: a change-management checkpoint at an environment boundary. That is our argument, not a claim either standard makes; neither mentions agents at all. But it lets an examiner recognize the gate as conformity with controls the firm already certifies against.
How you’d know it’s working
Rejection rate above zero. A gate that has approved everything it has ever seen is a form.
Turnaround measured against the shadow path, not against a locally invented service level. If registering takes three days and building unregistered takes an afternoon, the internal service level is the wrong yardstick.
Autonomy grants and interventions rising together. Anthropic’s telemetry over 998,481 sampled tool calls found full auto-approve used in roughly 20% of sessions by users with under 50 sessions, rising above 40% past 750 sessions, while interrupt rates also rose, from about 5% of turns to about 9%. Experienced users granted more autonomy and intervened more. That is calibrated trust, and it is the best empirical picture in this corpus of what a working progression looks like. Three caveats before quoting it: it is the share of sessions run in full auto-approve mode rather than an approval rate; it is developer usage of a coding tool, not the output of any governance gate; and it cannot separate production traffic from evals.
Promotions that go the other way. The healthiest gate outcome is sometimes demotion or conversion. A BCG worked example takes an invoice-matching agent, observes that the large majority of matches are exact, builds a deterministic layer for those, re-scopes the agent to genuine exceptions, and sets a retirement trigger for when the exception rate falls far enough. Those figures are BCG’s own modeling and could not be independently verified, so take the shape rather than the numbers.
What this doesn’t solve
A gate checks a moment. Post-promotion drift, capability creep, and an owner who has left the firm all escape it; those belong to registry review and offboarding. Worse, the artifacts a gate checks are themselves moving. Research on agent-assisted knowledge work finds agents expand the scope of work attempted, not only its speed, so declared scope decays after approval; gate on current scope and re-check it.
The friction objection stays unsettled, and the objection is real: the same MISQE study that credits governance with preventing shadow IT also records that over-strict rules cause it. Legibility and friction are the variables rather than strictness. The counter-evidence is narrower than it looks: McKinsey found 47% of C-suite leaders think their firms ship gen AI too slowly, but they blamed skill gaps (46%) and resourcing (38%), with only about 8% naming a complex approval process. That survey covers $1B+ firms, fielded January 2025, before the agentic wave. It rebuts “approvals are the bottleneck” as a reflex, not as a finding about any particular firm.
We have one asset-manager-specific example and it is thin. HBR Analytic Services reports Vanguard running staged governance toll gates whose standards differ for internal versus client-facing use. That research is AWS-sponsored, skews large-enterprise, and the passage could not be corroborated outside the report itself, so it stands as one example rather than a pattern.
Finally, a gate cannot manufacture the thing it checks. Roughly three-fifths of firms in a 2026 survey lacked a fully established AI development life cycle at all. That survey was sponsored by Databricks, with the underlying split not public, so weight it accordingly. If nothing upstream produces eval results and a tier score, the gate degenerates into a meeting.
See also
- Three-zone architecture — the architectural reason a gate exists at each zone boundary.
- Templates and checklists — the printable gate-review checklists.
- Risk-tier assignment — the tier score that sets each gate’s evidence bar.
- Evals — the acceptance evidence gates should demand, and what it can’t tell a gate.
- Human approval gates — approval as a runtime control, distinct from lifecycle promotion.
- Registry review cadence — the recurring check that catches what gates cannot.
- Shadow agents — what the gate governs if registering is harder than hiding.