WSO2 has released WSO2 Agent Manager, an open-source platform built to deliver centralized oversight, identity controls, security measures, and operational management for AI agents operating across multiple models, frameworks, and deployment settings. The launch addresses a mounting enterprise problem: while companies can construct agents using a widening array of models and frameworks, the infrastructure managing their identity, permissions, conduct, and lifecycle is frequently scattered. WSO2's strategy decouples agent governance from agent logic, enabling shared controls to be enforced regardless of the underlying model, framework, or runtime environment.
Agent Manager entered beta in June 2026, with the general availability version adding enhanced agent identity features, governance controls for Model Context Protocol (MCP) interactions, and a Kubernetes-native sandboxed runtime. The platform is engineered to operate across cloud, on-premises, and hybrid environments, allowing companies to oversee agents without locking governance to a single AI vendor. A primary emphasis of the release is agent identity and authorization—unlike traditional applications, agents can trigger tools, reach APIs, assign work, and communicate with other agents, raising fresh questions about authority and accountability. The platform delivers a central inventory and management layer with capabilities including verifiable agent identity, role-based access, delegation, token exchange, and access revocation, along with lifecycle controls for transitioning agents through development, staging, and production stages and the ability to suspend agents when necessary. The platform offers more than 40 built-in controls spanning areas such as personally identifiable information masking and rate limiting, with these policies applicable across different segments of an agent workflow including the agent, MCP, and LLM layers.
The general availability release also introduces a sandboxed execution runtime, responding to rising worries about agents receiving access to files, tools, APIs, and enterprise systems. The Kubernetes-native runtime is designed to supply a controlled setting for running agents while permitting their activity to be tracked and managed. Agent Manager also employs OpenTelemetry for tracing and includes evaluation capabilities intended to monitor agent conduct over time, with rule-based and LLM-based evaluations usable to spot issues such as unexpected token consumption, behavioral shifts, or deteriorating response quality. According to the report, WSO2's approach centers on framework and model independence, with the platform supporting technologies including LangChain, CrewAI, Amazon Bedrock, Azure, Ballerina, and custom-built agents while using standards and technologies such as OpenTelemetry, MCP, and OAuth 2 extensions.
The report explains that the underlying premise is that governance should stay separate from the AI technologies being governed—models, frameworks, and providers can shift rapidly, and organizations may deploy different combinations for different workloads. A distinct governance layer could enable teams to swap those underlying technologies without reconstructing identity, policy, and monitoring controls each time. The wider industry discussion suggests that agent governance is increasingly becoming a platform challenge rather than simply an AI development challenge, with AWS, Microsoft, and other providers all incorporating combinations of non-human identity, tool authorization, policy enforcement, runtime isolation, observability, and evaluation into their agent platforms. Recent industry analysis from Qovery has also contended that no single platform yet delivers a complete governance stack across every layer, with enterprises likely to blend identity systems, policy engines, infrastructure control planes, and isolated runtimes—making the concept of a framework-independent control plane increasingly relevant, particularly for organizations that anticipate their agent estate will span multiple models and cloud platforms.
The emerging challenge resembles earlier transitions in cloud and platform engineering: workloads may employ different technologies, but organizations still need common controls around identity, security, policy, observability, and lifecycle management. The question is no longer merely how enterprises construct AI agents, but how they consistently identify, govern, and control them once they're operating at scale. The governance infrastructure that wins enterprise trust will likely be the one that survives model churn without forcing teams to rebuild their security posture every quarter. Organizations betting on a single vendor's agent stack may find themselves locked into governance choices that don't travel well when the next wave of models arrives.

