{"id":2172,"date":"2026-09-18T12:13:31","date_gmt":"2026-09-18T15:13:31","guid":{"rendered":"https:\/\/4matt.com.br\/?p=2172"},"modified":"2026-09-18T12:13:34","modified_gmt":"2026-09-18T15:13:34","slug":"servicenow-ai-agent-governance","status":"publish","type":"post","link":"https:\/\/4matt.com.br\/en\/governanca-de-agentes-de-ia-servicenow\/","title":{"rendered":"AI agent governance in ServiceNow: inventory, data, and control."},"content":{"rendered":"<p>AI agent governance is the discipline that registers, authorizes, monitors, and audits each autonomous agent that operates on corporate data and processes. In ServiceNow, it relies on the AI Control Tower, which maintains a unified inventory of agents, models, and datasets linked to the CMDB. The limit of this governance is not the contracted language model: it is the quality of the configuration data that provides context to each action performed.<\/p>\n<h2>Why AI agent governance is a data problem<\/h2>\n<p>An autonomous agent differs from deterministic automation in one crucial aspect: it interprets context before acting. When the context stems from an incomplete configuration base, the agent doesn&#039;t visibly fail. It acts confidently on a flawed premise, and the error only becomes apparent later, in an incident escalated to the wrong team or a change approved without the necessary relationships to make it risky.<\/p>\n<p>This is the difference between governing a model and governing an agent. Governing a model means choosing a provider, controlling costs, and reviewing prompts. Governing an agent means answering who created it, what data it reads, what actions it can perform, under what identity, within what limits, and who is responsible when it makes a mistake. These are questions of asset management and configuration, not data science.<\/p>\n<p>The step prior to this, the platform readiness assessment, was discussed in the article about... <a href=\"https:\/\/4matt.com.br\/en\/go-to-servicenow-ti-leaders\/\">What IT leaders need to know before adopting AI in ServiceNow.<\/a>. This text begins where that one ends: with the agents already in operation.<\/p>\n<h2>What does ServiceNow AI Control Tower control?<\/h2>\n<p>The <a href=\"https:\/\/www.servicenow.com\/products\/ai-control-tower.html\" target=\"_blank\" rel=\"noopener\">AI Control Tower<\/a> It is the ServiceNow module for AI discovery, observability, governance, security, and measurement across the organization. According to the official product documentation, it automatically discovers agents, models, copilots, MCP servers, and datasets existing in the environment, and presents them in a unified inventory linked to the CMDB for business context.<\/p>\n<p>On May 5, 2026, during Knowledge 2026, ServiceNow announced the expansion of these capabilities to any AI system in use within the organization, not just those built on its own platform. The announcement describes five areas of focus, and each one is worth reading due to its data dependency.<\/p>\n<table>\n<thead>\n<tr>\n<th>Capability<\/th>\n<th>What solves it?<\/th>\n<th>Data dependency<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Discovery<\/td>\n<td>Find agents, models, copilots, MCP servers, and datasets in use, including those outside the platform.<\/td>\n<td>You need a CMDB to provide business context to the findings.<\/td>\n<\/tr>\n<tr>\n<td>Observability<\/td>\n<td>It exposes the agent&#039;s behavior at runtime, including where it makes decisions and when corrections are needed.<\/td>\n<td>It depends on the relationship with the service and application to translate decisions into impact.<\/td>\n<\/tr>\n<tr>\n<td>Governance<\/td>\n<td>Assesses risk from agents, models, datasets, prompts, and classical machine learning.<\/td>\n<td>It depends on the classification, criticality, and responsible party defined.<\/td>\n<\/tr>\n<tr>\n<td>Security<\/td>\n<td>Extends identity and access governance to AI environments from cloud providers, with scoped permissions and least privilege.<\/td>\n<td>It depends on non-human identities that are registered and associated with owners.<\/td>\n<\/tr>\n<tr>\n<td>Measurement<\/td>\n<td>Linking the use of AI to operational and financial results.<\/td>\n<td>It depends on consistent process indicators in ITSM and ITOM.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The column on the right is the part that is often overlooked when the module is evaluated as a standalone purchase, and it is precisely where AI agent governance ceases to be about configuration and becomes about data design. None of the five capabilities operates in a vacuum. They all consume the same substrate: a configuration base that knows what each record is, which service it belongs to, and who is responsible for it.<\/p>\n<h2>Agent inventory is only useful on a trusted CMDB.<\/h2>\n<p>Discovering agents is the mechanical part. The value appears when each discovered agent is linked to the service it touches, the application it queries, and the process it executes. Without this link, the inventory becomes a list of technical names with no operational consequence, exactly as happens with a CMDB fed by Discovery without modeling.<\/p>\n<p>An example illustrates the difference concretely. An agent that opens and closes access requests can be recorded as an isolated item, with a name, provider, and creation date. Recorded in this way, it doesn&#039;t answer the question that matters in an audit: which business services were affected by the 4,000 actions it performed in the quarter. The answer depends on the relationship between the agent, the applications it accessed, and the services those applications support, which is precisely what CSDM organizes.<\/p>\n<p>The health criteria for this database are detailed in the material about... <a href=\"https:\/\/4matt.com.br\/en\/quality-governance-data-cmdb-csdm-servicenow\/\">Data quality and governance in CMDB<\/a> and in the guide of <a href=\"https:\/\/4matt.com.br\/en\/cmdb-servicenow-csdm-implementation\/\">Implementing CMDB in ServiceNow with CSDM<\/a>.<\/p>\n<h2>Minimum attributes for treating an agent as a governed entity.<\/h2>\n<p>A governed agent must carry the same attributes as any critical asset. The table below compiles the minimum set that allows for responding to an audit without manually reconstructing history.<\/p>\n<table>\n<thead>\n<tr>\n<th>Attribute<\/th>\n<th>Question that answers<\/th>\n<th>Consequence of being empty<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Functional owner<\/td>\n<td>Who approves what this agent can do?<\/td>\n<td>No area assumes the decision to suspend or expand the scope.<\/td>\n<\/tr>\n<tr>\n<td>Technical owner<\/td>\n<td>Who maintains the configuration and is responsible for failures?<\/td>\n<td>Incidents caused by the agent are left without a responsible party for remediation.<\/td>\n<\/tr>\n<tr>\n<td>Scope of action<\/td>\n<td>Which tables, records, and operations are allowed?<\/td>\n<td>The agent inherits broader permissions than their role entails.<\/td>\n<\/tr>\n<tr>\n<td>Execution identity<\/td>\n<td>Under which account are the actions recorded?<\/td>\n<td>Actions appear to be attributed to a generic account, without traceability.<\/td>\n<\/tr>\n<tr>\n<td>Related services<\/td>\n<td>Which business services are affected when he acts?<\/td>\n<td>Impact analysis and communication to the business become impossible.<\/td>\n<\/tr>\n<tr>\n<td>Data source consumed<\/td>\n<td>Where does the context that supports the decision come from?<\/td>\n<td>It is not possible to explain why the agent decided as he did.<\/td>\n<\/tr>\n<tr>\n<td>life cycle state<\/td>\n<td>At what stage is he, from pilot to retirement?<\/td>\n<td>Test agents remain active in production indefinitely.<\/td>\n<\/tr>\n<tr>\n<td>Suspension criteria<\/td>\n<td>What condition triggers the shutdown?<\/td>\n<td>Containment depends on someone manually noticing the deviation.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Non-human identity and lesser privilege<\/h2>\n<p>Agents perform actions based on credentials. Each agent credential is a non-human identity, subject to the same risks of over-permission, dormancy, and lack of periodic review that affect traditional service accounts, with one aggravating factor: agents are created more easily and reviewed less frequently.<\/p>\n<p>The Knowledge 2026 announcement describes how ServiceNow addresses this issue. The AI Control Tower security layer extends identity and access governance to cloud provider AI environments and every connected device through integration with Veza, applying scoped permissions and least privilege to each AI system, agent, and identity. The same announcement notes that when an agent goes off-script or operates beyond permissions, AI Control Tower detects the situation and shuts it down in real time.<\/p>\n<p>This containment mechanism can only be activated when the deviation is recognizable, which requires the expected scope to be declared somewhere. An agent without a registered scope cannot be detected outside of it.<\/p>\n<h2>Observability at runtime and audit trail<\/h2>\n<p>ServiceNow reports that the acquisition of Traceloop now delivers deep observability of agent behavior at runtime, providing visibility into how agents reason, where they make decisions, and when they need to be corrected.<\/p>\n<p>From a governance perspective, the value of this layer lies not in the technical record itself, but in the ability to reconstruct a specific decision months later, in the presence of an auditor or regulator. This changes what the operation needs to retain. A log that only records the action performed answers what happened. A record that records the action, the context consulted, and the criteria applied answers why it happened, which is the question an audit asks.<\/p>\n<h2>Risk frameworks applied to agents<\/h2>\n<p>The <a href=\"https:\/\/newsroom.servicenow.com\/press-releases\/details\/2026\/ServiceNow-expands-AI-Control-Tower-to-discover-observe-govern-secure-and-measure-AI-deployed-across-any-system-in-the-enterprise\/default.aspx\" target=\"_blank\" rel=\"noopener\">official statement from ServiceNow<\/a> The governance layer now offers five new risk frameworks aligned with NIST standards and the EU AI Act, with ready-to-use compliance controls. Risk assessment covers not only agents, but also models, datasets, prompts, and classical machine learning.<\/p>\n<p>For Brazilian organizations, these frameworks serve as an international benchmark for best practices, not as a local regulatory obligation. Companies with operations or clients in the European Union need to assess the applicability of the EU AI Act with their own legal support, and this assessment should not be derived from the configuration of a tool.<\/p>\n<h2>Agents outside the platform and the problem of scattering.<\/h2>\n<p>Most organizations don&#039;t concentrate their agents on a single vendor. Agents are born in productivity tools, cloud platforms, and isolated area initiatives, without going through a formal onboarding process.<\/p>\n<p>ServiceNow acknowledged this scenario when it announced, at Knowledge 2026, the <a href=\"https:\/\/newsroom.servicenow.com\/press-releases\/details\/2026\/ServiceNow-expands-AI-agent-governance-through-deeper-integration-with-Microsoft\/default.aspx\" target=\"_blank\" rel=\"noopener\">expansion of the partnership with Microsoft<\/a>. The integration between AI Control Tower and Microsoft Agent 365 extends the governance that the module already exercised over Microsoft Foundry and Copilot Studio to the Microsoft agent ecosystem. The announcement describes the integration as available in preview, which is relevant information for those currently building target architectures.<\/p>\n<p>The practical consequence for the operation is that the agent inventory needs to be treated like an asset inventory, with the same disciplines of continuous discovery, source reconciliation, and identification of unauthorized records that apply to... <a href=\"https:\/\/4matt.com.br\/en\/services\/itam\/\">ITAM<\/a>.<\/p>\n<h2>What needs to be ready before enabling AI agent governance?<\/h2>\n<p>Order matters. Activating the module on a weak foundation produces an inventory that no one can interpret and reports that no one can defend. The table below organizes the prerequisites by layer.<\/p>\n<table>\n<thead>\n<tr>\n<th>Layer<\/th>\n<th>Prerequisite<\/th>\n<th>How to check<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Data<\/td>\n<td>Critical applications with a defined owner and relationship to the service.<\/td>\n<td>View the CMDB health dashboard by class, not the total number of configuration items.<\/td>\n<\/tr>\n<tr>\n<td>Model<\/td>\n<td>CSDM taxonomy applied to the services that the agents will handle.<\/td>\n<td>Verify that business service, application service, and technical component are separated.<\/td>\n<\/tr>\n<tr>\n<td>Identity<\/td>\n<td>Service accounts and non-human identities inventoried and associated with owners.<\/td>\n<td>List identities that have not been used in the last 90 days and have no assigned owner.<\/td>\n<\/tr>\n<tr>\n<td>Process<\/td>\n<td>Entry rite for new agents, with approval and declared scope.<\/td>\n<td>Confirm that a formal record exists before the first production run.<\/td>\n<\/tr>\n<tr>\n<td>Risk<\/td>\n<td>Internal policy on what can and cannot be processed by AI.<\/td>\n<td>Confirm sensitive data classification applied to the sources that agents read.<\/td>\n<\/tr>\n<tr>\n<td>Measurement<\/td>\n<td>Consistent process indicators prior to activation.<\/td>\n<td>Having a baseline of volume, time, and recurrence for later comparison.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>As a ServiceNow Elite Partner in Brazil, recognized with the Technology Excellence Partner Award 2024\u20132025 and with more than 110 certified specialists, 4MATT operates in this sequence based on the following database: maturity diagnosis of <a href=\"https:\/\/4matt.com.br\/en\/services\/cmdb\/\">CMDB<\/a>, Design the target CSDM model and define ownership before any discussion about activating the AI module.<\/p>\n<h2>Common mistakes in agent governance<\/h2>\n<ul>\n<li><strong>Treat the agent as a functionality, not as an entity:<\/strong> Activating without registration, without an owner, and without a declared scope prevents any subsequent audit.<\/li>\n<li><strong>Measuring adoption instead of effect:<\/strong> Counting agent executions without comparing them to the baseline of the process it replaced.<\/li>\n<li><strong>Exclude agent identities from access review:<\/strong> subjecting human accounts to periodic recertification and ignoring non-human accounts, which are more numerous and less visible.<\/li>\n<li><strong>Keep pilot agents in production:<\/strong> Without a life cycle state, a two-week test remains active for two years.<\/li>\n<li><strong>Govern only what originated on the platform:<\/strong> Ignore agents created in productivity and cloud tools, which rarely go through a formal onboarding process.<\/li>\n<li><strong>Treating an international framework as a local obligation:<\/strong> Applying EU AI Act or NIST controls without a legal assessment of their actual applicability to the business.<\/li>\n<\/ul>\n<h2>Frequently asked questions about AI agent governance.<\/h2>\n<h3>What is AI agent governance?<\/h3>\n<p>It is the set of records, policies, permissions, indicators, and audit trails that ensures each autonomous agent has an owner, a declared scope, its own identity, a defined life cycle, and a reconstructible history of the actions performed.<\/p>\n<h3>What does ServiceNow AI Control Tower do?<\/h3>\n<p>According to the official documentation, it discovers agents, models, copilots, MCP servers, and datasets in the environment, displays this set in a unified inventory linked to the CMDB, and applies governance, security, and measurement to it.<\/p>\n<h3>Why does CMDB matter for governing agents?<\/h3>\n<p>Because the agent inventory only produces decisions when each agent is linked to the service, application, and process it affects. This link is what allows for impact analysis, communication with the business, and response to audits.<\/p>\n<h3>Should an AI agent be registered as a configuration item?<\/h3>\n<p>The decisive factor is not the table where it resides, but rather the set of attributes it carries: functional owner, technical owner, scope of action, execution identity, related services, data source consumed, lifecycle state, and suspension criteria.<\/p>\n<h3>Is it possible to disable an agent that goes out of scope?<\/h3>\n<p>The ServiceNow announcement from May 5, 2026, states that AI Control Tower detects when an agent operates beyond its permissions and shuts it down in real time. The mechanism assumes that the expected scope is declared; otherwise, the deviation is not recognizable.<\/p>\n<h3>Does AI Control Tower govern agents created outside of ServiceNow?<\/h3>\n<p>ServiceNow announced at Knowledge 2026 its integration with Microsoft Agent 365, extending the governance already exercised over Microsoft Foundry and Copilot Studio to the Microsoft agent ecosystem. The announcement describes the integration as available in preview.<\/p>\n<h3>Does the EU AI Act apply to Brazilian companies?<\/h3>\n<p>The frameworks offered by the module are an international benchmark for best practices. The applicability of the EU AI Act depends on each company&#039;s operations and customer base and requires its own legal assessment, which should not be derived from the configuration of a tool.<\/p>","protected":false},"excerpt":{"rendered":"<p>How to register, authorize, and audit AI agents in ServiceNow with AI Control Tower, and why CMDB and CSDM define the boundary of this governance.<\/p>","protected":false},"author":217054028,"featured_media":2175,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","inline_featured_image":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[1368,1391,1416],"tags":[1363,1399,1371,1385,1419,1367,1372,1420,1366],"class_list":["post-2172","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-servicenow","category-governanca-de-ti","category-inteligencia-artificial","tag-cmdb","tag-csdm","tag-elite-partner","tag-governanca-de-ti","tag-inteligencia-artificial","tag-itam","tag-itom","tag-llm","tag-servicenow"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/phhKzJ-z2","jetpack_featured_media_url":"https:\/\/i0.wp.com\/4matt.com.br\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-18-de-set.-de-2026-12_11_26.png?fit=1774%2C887&ssl=1","_links":{"self":[{"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/posts\/2172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/users\/217054028"}],"replies":[{"embeddable":true,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/comments?post=2172"}],"version-history":[{"count":1,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/posts\/2172\/revisions"}],"predecessor-version":[{"id":2173,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/posts\/2172\/revisions\/2173"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/media\/2175"}],"wp:attachment":[{"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/media?parent=2172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/categories?post=2172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/4matt.com.br\/en\/wp-json\/wp\/v2\/tags?post=2172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}