In one fortnight the market sketched an "agent governance stack": Okta Agent SSO (GA), IBM watsonx Orchestrate AgentOps, Broadcom AgentMinder, and Dataiku Agent Management (GA planned October). Okta's 2026 AI Agents at Work data says only 34% of organizations apply the same security controls to agents that they apply to humans.

Separately, Cybersecurity Insiders' 2026 research (vendor-adjacent — label it) claims 91% of orgs discover agent actions only after execution and only 23% report inline real-time AI security. Whether you buy their gateway or not, the direction is clear: inventory and allow/block at the point of action, not in next quarter's postmortem.

For a small Bay Area shop the checklist is still human-scale: what agents exist (Cursor, Claude, MCP, Copilot, RMM scripts), what they can reach (Drive, email, tickets), who approved them, and whether a compromised laptop can stand one up overnight. Procurement will start asking; better to have the list before the RFP does.