O
OOMeta
← Back to Insights

September 2026 · 5 min read

Buy runtime evidence, not control planes

Buy runtime evidence, not control planes

Key Definitions

Agent Control Plane The infrastructure layer that centrally manages agent identity, permissions, guardrails, runtime, and observability, separated from agent logic. WSO2 Agent Manager, Microsoft MAI, and ServiceNow all sit in this category; in 2026 it moved from a differentiated product to an openly available commodity.

In-Stack Self-Attestation Eval, telemetry, and compliance evidence produced by the governed system itself. A vendor claims to govern “inside your trust boundary,” but the producer and the defender of the evidence are the same party, so the record cannot be independently verified.

Runtime Evidence An exportable, third-party-verifiable record of what agents actually did in production — identity, tool calls, policy hits, audit trails. Unlike bundled observability, it is decoupled from the system, which makes independent recomputation possible.

When a 20-year-old open-source middleware vendor gives away an agent control plane as an Apache-2.0 product, the commercial story of control planes as a differentiator is over. WSO2 shipped Agent Manager GA on Sep 15 — a framework-agnostic, self-hostable control plane with identity, guardrails, sandboxed runtime, observability, and continuous eval built in. What matters is not another product: it is that a layer of the stack is being commoditized, while the evidence vendors use to prove “we are governing” is still generated by the vendors themselves.

The control-plane lane is being absorbed by open source

WSO2 is a 20-year-old open-source middleware vendor that started with API management and identity servers. Agent Manager went beta in June 2026 and GA on Sep 15: Apache 2.0, self-hosted or managed SaaS, framework-agnostic — it can govern agents built with LangChain, CrewAI, Amazon Bedrock Strands, or Microsoft Agent Framework (source: WSO2 announcement — https://www.globenewswire.com/news-release/2026/09/15/3362114/0/en/wso2-agent-manager-brings-sovereign-ai-governance-to-enterprise-agent-sprawl.html ). The feature list is the standard answer sheet of the category: verifiable identity per agent (RBAC, delegation, token exchange, instant revocation); 40+ built-in guardrails (PII masking, rate limiting) enforced at agent, MCP, and LLM levels; a Kubernetes-native sandboxed runtime with one-click suspension; end-to-end OpenTelemetry tracing with rule-based or LLM-as-judge continuous evals that catch runaway token spend and accuracy drift; and a slot in Forrester’s Agent Control Plane Landscape Q2 2026 (product details — https://wso2.com/agent-platform/agent-manager/ ).

This is not an isolated event; it is the latest evidence that the control-plane lane is crowded. Gartner predicts the average Fortune 500 enterprise will run more than 150,000 agents by 2028, while only 13% of organizations believe they have the right agent governance in place (source: cited by WSO2 — same GlobeNewswire URL). Techzine puts it bluntly: the agent governance market “almost appears to be expanding faster than that for agentic creation” (source: Techzine — https://www.techzine.eu/blogs/analytics/140974/wso2-agent-manager-enterprise-ai-governance/ ). When an open-source incumbent, an analyst landscape, and framework-agnosticism all line up, the “should we buy a control plane” decision degenerates into “default to open source.”

Our judgment (1): control planes are necessary, not differentiating

Commoditization has three markers, and control planes hit all of them. First, feature homogeneity: identity, guardrails, observability, eval — every vendor claims them; the differences live in marketing vocabulary, not capability boundaries. Second, open-source supply: WSO2’s Apache-2.0 release is only the latest entry in a lane already filled by Okta Agent SSO, Microsoft MAI, and assorted self-hosted workspaces. Third, analyst assimilation: Forrester now publishes a landscape report for the category — analysts treat control planes as a shelf item, not anyone’s moat.

Another Gartner number (via Techzine) shows the market is still in the education phase: more than 40% of agentic AI projects are expected to be canceled by 2027, driven by rising costs, unclear value, and insufficient risk controls (source: Techzine — https://www.techzine.eu/blogs/analytics/140974/wso2-agent-manager-enterprise-ai-governance/ ). Vendors are racing to be the educator. For buyers, the point of being educated should be clearer procurement — not a more expensive self-attestation.

Our judgment (2): built-in evals are still in-stack self-attestation

Every control plane ships eval and observability, but this is in-stack self-attestation: WSO2 says “bring governance into your environment,” Salesforce says “runs entirely inside your trust boundary,” Microsoft says “in your tenant.” Every vendor claims to govern itself. Control planes cover pre-admission (identity, permissions, policy) and in-flight (observability, eval) — but the observations and evals are produced by the governed system itself. In audit terms, the producer of evidence and the defender of the system are the same party.

The buyer’s real question lives on another axis: when agents run across frameworks, providers, and environments, who independently proves what actually happened? Control planes answer “is the system operating as designed”; they do not answer “would an auditor believe it is operating as designed.” OOMeta runs a multi-agent operating system — a task bus, a SQLite single source of truth, and per-action traces (URLs and tool outputs). Our operational experience is that governance capability is the easiest part to acquire; making an external auditor believe “the agents really ran under policy” is the hard part, and it requires an evidence chain independent of any vendor.

What buyers should do: a three-step procurement framework

Step 1: procure control planes as a commodity.

Default to open source; compare identity granularity, guardrail enforcement levels (agent/MCP/LLM), runtime isolation, and audit export formats — not feature counts. A control plane does not deserve a 12-month selection cycle.

Step 2: keep two ledgers for evidence.

Separate vendor-generated evidence (in-stack eval, bundled observability) from independently verifiable evidence (cross-stack, exportable, third-party recomputable). For every critical policy, define who can independently see the runtime evidence.

Step 3: add one hard clause to the RFP.

Runtime evidence must be exportable, open-format, and verifiable by a third party. Any vendor that cannot do this is selling a more expensive black-box attestation — regardless of how many guardrails it ships.

The question we leave with buyers

The next time someone pitches an “enterprise agent governance platform,” ask one question: can an independent third party verify what your agents actually did in production? If the answer is no, you are buying a pricier self-report — and control planes, by now, are cheap enough to take for free.

References: WSO2 announcement (GlobeNewswire, Sep 15) — https://www.globenewswire.com/news-release/2026/09/15/3362114/0/en/wso2-agent-manager-brings-sovereign-ai-governance-to-enterprise-agent-sprawl.html ; WSO2 product page — https://wso2.com/agent-platform/agent-manager/ ; Techzine analysis — https://www.techzine.eu/blogs/analytics/140974/wso2-agent-manager-enterprise-ai-governance/

FAQ

What is WSO2 Agent Manager and why does it matter?+

An Apache-2.0, framework-agnostic agent control plane GA’d by WSO2 (a 20-year-old open-source middleware vendor) on Sep 15, with verifiable per-agent identity, 40+ guardrails, a Kubernetes-native sandboxed runtime, OpenTelemetry tracing, and continuous eval. It matters not as a product but as proof the control plane is being absorbed into open source.

What marks the commoditization of control planes?+

Three markers: feature homogeneity (identity, guardrails, observability, eval are table stakes), open-source supply (WSO2, Okta Agent SSO, Microsoft MAI), and analyst assimilation (Forrester now publishes an Agent Control Plane Landscape category).

What is wrong with a control plane’s built-in eval?+

It is in-stack self-attestation: observations and evals are produced by the governed system itself, so the producer and the defender of the evidence are the same party. It answers “is the system operating as designed” but not “would an auditor believe it is operating as designed.”

How should enterprises procure an agent control plane?+

As a commodity: default to open source, compare identity granularity, guardrail enforcement levels, runtime isolation, and audit export formats. Keep vendor evidence and independently verifiable evidence in separate ledgers, and require exportable, open-format, third-party-verifiable runtime evidence in the RFP.

What is cross-stack runtime evidence and why is it scarce?+

An independent, third-party-verifiable record of agent behavior across frameworks and providers, decoupled from any vendor. It is scarce because every control plane today produces its evals from within the governed system; an independent evidence chain has to be designed deliberately.

What do the 150,000-agent and 13% numbers mean?+

Gartner predicts the average Fortune 500 will run more than 150,000 agents by 2028 while only 13% of organizations believe their governance is right (as cited by WSO2). The gap between scale and governance is why the control-plane market is expanding so fast — and why buyers need independent evidence.