ZaunZaun
Zaun Research

The Agent Control Plane Map
The controls exist, just not in one place.

We track how much of the control over an AI product you can own and run in your own stack, and how much of it only the vendor can operate. That is the whole question: when this agent acts, whose infrastructure decides whether it can?

29 products, 9 control surfaces, every cell carrying the vendor’s own documentation, quoted to the sentence and re-checked by machine against the live page.

30%of the controls on this board run on infrastructure you own. The vendor operates most of the rest, and on 36 cells nobody operates anything at all.

Tap any grade for its evidence.

Coding agents & IDEs

Claude Code

OpenAI Codex CLI

GitHub Copilot

Lovable

Replit

Devin AI

Kiro

Cursor

Devin Desktopformerly Windsurf · Cognition

Gemini Code Assist

Enterprise chat & knowledge

Claude Cowork

Claude (Team & Enterprise)Anthropic

ChatGPT Enterprise

Glean

Google Gemini (chat app)

Microsoft 365 Copilot

Microsoft 365 Copilot CoworkGA Jun 2026

Notion AI

Slack AI

Atlassian Rovoexcludes Rovo Dev

Perplexity Enterprise

Agent platforms

Salesforce Agentforce

Copilot Studio

Microsoft Foundry

Amazon Bedrock AgentCore

Gemini Enterprise Agent Platform

Databricks Unity AI Gateway

ServiceNow AI Agentsgraded at Prime tier

Snowflake Cortex Agents

ProductModel routingTools & connectorsGuardrailsAgent-to-agentLive logsLog contentsContainmentData boundaryAgent identity
Coding agents & IDEs
Claude Code
OpenAI Codex CLI
GitHub Copilot
Lovable
Replit
Devin AI
Kiro
Cursor
Devin Desktopformerly Windsurf · Cognition
Gemini Code Assist
Enterprise chat & knowledge
Claude Cowork
Claude (Team & Enterprise)Anthropic
ChatGPT Enterprise
Glean
Google Gemini (chat app)
Microsoft 365 Copilot
Microsoft 365 Copilot CoworkGA Jun 2026
Notion AI
Slack AI
Atlassian Rovoexcludes Rovo Dev
Perplexity Enterprise
Agent platforms
Salesforce Agentforce
Copilot Studio
Microsoft Foundry
Amazon Bedrock AgentCore
Gemini Enterprise Agent Platform
Databricks Unity AI Gateway
ServiceNow AI Agentsgraded at Prime tier
Snowflake Cortex Agents
ZAUN·RESEARCHyou own itvendor owns itno controlsecurity gapnot applicablezaun.ai/agent-control-plane-mapv1.2 · validated 2026-09
How to read this
You own it
Enforcement runs on infrastructure you control: your identity provider, your gateway, your cloud account, your endpoint fleet, your network.
The vendor owns it
A real control exists, but it runs in their console and they enforce it for you.
Nobody owns it
No control on this surface, or none you can reach.
Security gap
No control surface exists at all. Different from the row below: this one is a finding.
Does not apply
The surface is not part of how this product is built, so there is nothing to govern. Not a gap.

Tap any grade for the reasoning and the vendor documentation behind it. Every receipt carries its tier, when we last checked the page, when the document was published, and the sentence the grade rests on.

A small dot on a grade means the control is not necessarily switched on. The grade answers “if you turn this on, whose infrastructure enforces it?” The dot answers “is it on?”, which is a property of your deployment and something this map cannot see.

The full rubric for each column, the evidence-tier policy and the absence protocol are in the methodology. Every grade that has ever moved is in the changelog.

Everything you must reach to stop one agent

One agent. 3 of 7 domains in its containment path.

The agentGleanChat & knowledge
3domains in its containment path

9 of 29 products sit at this depth. 11 run deeper.

In every product

  • Human identity (IdP)29 of 29
  • Product admin plane29 of 29

The other 5. None in more than 13 of 29.

  • Network13 of 29
  • Gateway credential9 of 29
  • Endpoint / EDR9 of 29
  • Cloud control plane5 of 29
  • Data platform2 of 29

Check another product. Fewest domains to most.

2 domains6 domains

Two domains are not optional: the identity provider, and the vendor’s own admin console. Every one of the 29 products runs through both. After that there is no pattern. The next most common domain appears in 13 of 29, so which other team you need is a property of the product, not of your programme. 20 of 29 products reach past those two.

Three findings

Three things the data says that an AI governance programme has to plan around.

FINDING 01

The controls are real. They are spread.

A programme wired into one domain covers a fraction of the surface, however good that domain is.

FINDING 02

In most products the agent is the employee

In 21 of 29 products the agent acts with the identity of the person who started it: their token, their permissions, their name in the audit log. The other 8 issue the agent a principal of its own, though only some of those are minted by your fabric rather than the vendor’s. Where the agent is the person, identity is the plane you cut it on, and the audit trail will not tell you which of the two acted.

FINDING 03

A grade says what you can turn on, not what is on

60 cells carry a marker saying the control is opt-in, tier-gated, in preview, still to be built, gated on a deployment mode, or dependent on a gateway you have not deployed. The grade is what the product makes possible. It is not what is running in your tenant tonight, and only your own environment can answer that. Confirm a control is firing before you write a policy against it.

Changelog

Every grade that has ever changed, newest first, with corrections, rubric changes and scope changes labelled separately. We publish our own corrections first.

2026-09

v1.2 · A ninth surface, seven new products, and half the board re-read. Amazon Q Developer is retired, three rows are renamed to the product a buyer can find, and six grades moved after fourteen contested cells were adjudicated. Three further moves were made and then reversed, on re-reading the pages rather than the quotes.

Full changelog

Get notified when a grade changes

Every quote on this board is re-checked against the live vendor page each week, so a grade moves when the documentation does. Subscribe and the changes come to you.

The harder question this research raises is the one we cannot answer for you: this board covers 29 products, your estate is running more than that, and the controls for them sit in 7 different domains. Reagent builds this same board for your environment by connecting to the systems already doing the enforcing: EDR, MDM, identity provider, firewall and secure web gateway, AI gateways, cloud IAM, the data platforms holding the data, and the vendor consoles themselves. No new agent, no new sensor, and no gateway you have to route your traffic through. See what this looks like for your own estate.