ClearTech Loop: In the Know, On the Move

AI Agent Governance Starts With Visibility | Alvaro Gonzalez 

August 18, 2026

Download Transcript (pdf)

You Can’t Govern What You Can’t See

Alvaro Gonzalez joins Jo Peterson to talk AI agents, least privilege, observability, governance committees, remediation, and why visibility has to come before control. 

AI governance gets complicated very quickly. 

Frameworks, policies, committees, identity, risk and controls all matter. But in this episode of ClearTech Loop, Alvaro Gonzalez, SVP of Product and Go-to-Market at Assured Data Protection, kept coming back to a much more basic question: 

Do you actually know what is in your environment? 

AI agents can hold delegated credentials, make authorization decisions in real time, interact with sensitive data and even create subagents with their own permissions. That makes identity much more dynamic than the environments traditional IAM and PAM systems were designed around. 

Alvaro’s point is not that least privilege no longer matters. It is that least privilege alone is not enough when identities, behaviors and access can change at machine speed.

Listen to the Full Episode

Listen to Jo Peterson and Alvaro Gonzalez discuss AI agent identity, governance, observability, remediation and what organizations should do first if they are starting from zero. 

Episode link: https://www.buzzsprout.com/2248577/episodes/19663499 

The Three Questions

What Does Least Privilege Look Like for AI Agents?

Least privilege was easier to manage when identity was relatively static. AI changes that. 

Agents can appear, disappear, proliferate and, in some cases, create additional identities. Alvaro described a realistic path forward in three layers: 

Inventory: Know what identities exist. 

Observability: Understand what those identities are doing in real time. 

Remediation: Have a way to recover when the first two layers do not stop something from going wrong. 

That third layer is especially important. Security programs have always had to account for the fact that controls can fail. AI increases the velocity of both useful actions and damaging ones, which means recovery has to be part of the design, not something organizations think about after the incident. 

Are AI Governance Committees Actually Working?

Alvaro’s answer: they can. 

But having a governance committee is not the same thing as having effective governance. 

He described the distinction as “librarians and warriors.” 

A governance team that writes policies, documents standards and sends enforcement somewhere else may be doing valuable work, but the organization also needs people close enough to execution to see what is deployed, understand how it is behaving and change course when something moves outside acceptable boundaries. 

As Alvaro put it: 

“Are they governing by writing, or are they governing by doing and interacting and iterating?” 

The question for organizations is not simply whether they have an AI governance structure. It is whether that structure can actually influence what happens inside the environment. 

If You’re Starting From Zero, What Do You Do First?

Alvaro did not hesitate on this one. 

Inventory first. 

Organizations need to know what agents are already running, what non-human identities exist and what people are doing with them. 

That sounds basic, but it is the prerequisite for everything else. 

The same lesson showed up during the rise of cloud and shadow IT. Governance could not catch up until organizations understood what was actually being used. AI creates a similar visibility problem, except the technology can now make decisions and take actions on its own. 

Alvaro also challenged the usual sequencing around risk. Before trying to predict every possible failure, he would prioritize the ability to remediate one. 

Know the actor. Know what it can do. Know how to reverse the damage. 

Then expand the risk model from there.

The Three Layers of AI Agent Control  

Inventory

What exists?

  • AI agents 
  • Non-human identities
  • Delegate credentials 

Observability

What are they doing? 

  • Behavior 
  • Access 
  • Real-time activit

Remediation

What happens when something goes wrong?  

  • Reverse the action 
  • Recover quickly 
  • Limit the impact 

When everything is in motion, resilience has to be part of least privilege.

Controlled Aggression 

Toward the end of the conversation, Alvaro talked about experimenting with MCP servers himself. 

His goal is not to recreate an enterprise environment in a personal lab. It is to understand how the technology behaves, where it surprises him and what questions customers are likely to face as they begin connecting agents to more applications and data. 

That led to one of the most memorable phrases from the episode: 

“Controlled aggression. Structurally controlled aggression.” 

The idea is simple: organizations should not stop experimenting with AI until every possible risk is understood. That is not realistic. 

But experimentation should happen in environments where mistakes can be observed, contained and remediated. Organizations can then expand from there with a better understanding of what the technology touches and how it behaves. 

The goal is not to eliminate movement. It is to make sure speed does not remove the ability to recover.

What Jo Is Seeing 

Visibility continues to show up as one of the biggest themes across ClearTech Loop conversations about AI security. 

Organizations are discussing increasingly sophisticated governance models while many are still working to answer basic operational questions: What agents are running? What identities do they use? What applications can they reach? Where does sensitive data live? 

That is not entirely new. Cloud, SaaS and shadow IT created similar visibility gaps. 

What is different now is that AI systems can act. They can make decisions, invoke tools, access connected systems and move through workflows at speeds that make static controls increasingly difficult to rely on by themselves. 

As Jo puts it: 

“Before we build another AI governance framework, we should probably make sure we know what we’re governing.” 

That may be the most practical place to start. 

Alvaro Gonzalez

SVP of Product and Go-to-Market, Assured Data Protection 

Alvaro leads product, alliance, marketing and go-to-market functions at Assured Data Protection, with a focus on cyber resilience, data protection and building the systems that support field and channel execution. 

Additional Resources

Additional Resources 

Stay in the Loop 

Subscribe to the ClearTech Loop newsletter for new conversations on AI security, governance, cloud strategy and cyber risk. 

https://www.linkedin.com/newsletters/7346174860760416256

Watch full episodes and subscribe to ClearTech Research on YouTube. 

https://www.youtube.com/@ClearTechResearch