A Guide to Agent Control
Geordie’s Field Guide shows the control points Anthropic, OpenAI, AWS, and Microsoft have built in natively – and where each falls short. Reviewed quarterly.
Every major agent platform ships real controls. The question CISOs and AI governance teams actually need answered is: at which point in an agent’s lifecycle – from system prompt to tool call to network egress – can your team actually see what’s happening and act on it, versus just review it after the fact?
The Agent Control Field Guide plots Anthropic, OpenAI, AWS Bedrock, and Microsoft against exactly that question, sourced entirely from public documentation and independent security research. The placement above is the summary. The guide is the reasoning behind it: what each platform actually exposes, stage by stage, and the documented failure modes — CVEs, red-team findings, independent research — behind every gap on the chart.
Included:
- A shared, eight-stage lifecycle for reasoning about agent control across any platform or harness
- A side-by-side map of what Anthropic, OpenAI, AWS Bedrock, and Microsoft each expose natively — and what they leave to you
- The documented failure modes (CVEs, red-team findings, independent research) behind each platform’s control gaps
- A structural gap common to all four platforms, and where to focus governance effort regardless of which one you’re on