Identification: you cannot govern what you have not listed
Agents accumulate quietly. One team pilots an Agentforce agent for case deflection. A vendor ships a tool with an agent inside it that writes to the CRM. Someone connects an external assistant to the org through an integration user. Within a year, the honest answer to "how many agents act on our data" is usually "we are not sure". An agent nobody listed is an agent nobody owns, and an agent nobody owns has no approval, no reviewer, and no one to call when it misbehaves. The fix is unglamorous and essential: a register, one row per agent, each row with a named business owner and a named platform owner. In Huscribe's register, an agent with no owner is not a gap in the spreadsheet. It is the first finding.
Monitoring: approval is a snapshot, production is a movie
The day an agent goes live, its behaviour matches what was reviewed. Every day after that, the match decays, because the things the agent depends on keep moving:
- Permissions drift as other projects widen the access of the user the agent runs as
- Knowledge drifts as articles the agent quotes are edited and archived
- Logic drifts as flows and Apex the agent calls are changed upstream
- Instructions drift as prompts are tweaked during incidents and never re-reviewed
- Models drift as the vendor upgrades or swaps what sits behind the agent
None of this is anyone's negligence. It is the normal metabolism of a shared platform. Which is exactly why compliance cannot be a launch-day property. It has to be re-established, on a schedule and on every material change, against what was signed.
What good monitoring looks like
Watching a dashboard is not monitoring, and neither is reading a sample of transcripts when someone complains. Monitoring that stands up to an auditor has a specific shape:
- Checks are compiled from the signed approval, so "passing" means "doing what we agreed", not "looking fine".
- Checks run against what the agent actually did, not only against its configuration.
- Runs are triggered by the calendar and by change events: a permission widened, a knowledge article edited, a flow changed, a model swapped.
- Every run issues a report, and the reports live in your Git, readable without the vendor.
- Nothing is green by default. An uninspected agent shows as uninspected, not as fine.
When a check fails, evidence beats opinion
The payoff for all this structure arrives on the bad day. An agent quoted a retired policy, or wrote to records it should not touch. Without a register and reports, that day is spent reconstructing history from memory and logs. With them, the conversation is short: here is what was approved and by whom, here is the report showing the deviation, here is what changed last and where the change came from, and here is the smallest change that would make the check pass. The agent's owner decides, the team ships it, the next report confirms the fix. That is the difference between an incident and an unbounded investigation.
Start with one agent
You do not need a programme to begin. Pick the one agent whose failure would hurt most. Write down what it may and may not do, and have its owner sign that. Check it against the document. Expect that first inspection to teach you something, because the org has been moving since the agent launched. That one row is the seed of the register, and the register is how you scale from one watched agent to a governed fleet. This approval-first sequence is exactly how Huscribe builds and inspects Salesforce agents, and the case for the product as a whole is in why Huscribe.