Share with your CTO
WSO2 is betting that agent sprawl, already an operational headache, becomes a governance crisis as Gartner projects Fortune 500 firms will run more than 150,000 agents each by 2028. The company’s answer is WSO2 Agent Manager, now generally available under Apache 2.0, which acts as an open control plane giving enterprises verifiable per-agent identity, sandboxed execution, MCP-level guardrails, and OpenTelemetry-based observability across LangChain, CrewAI, Bedrock Strands, and other frameworks, without committing to any single one.
What this means for your business
The company you’re in right now almost certainly has agent governance that looks like archaeology: a gateway bought for API traffic, an identity system designed for human employees, an observability tool that was never meant to watch autonomous processes. That patchwork was defensible when agents were experiments. At 150,000 agents it becomes a liability. Where you sit on this story depends on how far ahead of your deployment curve your governance actually is, and most teams are behind.
The sharper claim WSO2 is making is that governance and agent logic should be architecturally separate. That’s not just a product pitch, it’s a structural argument worth taking seriously. The recurring failure mode in enterprise software is that compliance controls get baked into the thing they’re supposed to control, which means every model swap, framework migration, or vendor change requires rebuilding those controls from scratch. Separating them into a dedicated control plane, the way network teams long ago stopped embedding firewall logic in individual applications, is the right architectural instinct. Whether WSO2 executes on it is a different question, but the pattern they’re following is sound.
WSO2 co-authored the OpenID Foundation whitepaper on agentic identity and an OAuth 2 extension for MCP, which gives Agent Manager a standards pedigree that proprietary control planes from model vendors can’t credibly claim. That matters for a purchasing decision you may already be deferring: the vendor whose agent governance you adopt is also the vendor whose identity standards and policy schema your whole estate gets shaped around. An open-source, standards-grounded option changes the calculus on that lock-in risk. I’d revise this read if a hyperscaler ships a comparable open control plane before enterprises need to decide, because at that point the distribution advantage swamps the standards argument.
Concept deep-dive: Agent control plane
An agent control plane is a centralized layer that governs what AI agents are allowed to do, how they authenticate, and whether they’re behaving correctly, without being part of the agents themselves. Think of it the way a power grid’s management system relates to the appliances plugged into it: the appliances change, the grid standards don’t. In enterprise terms, it’s the difference between writing access and safety policies once and enforcing them everywhere, versus rebuilding those policies every time a team ships a new agent on a new framework.
Based on reporting from WSO2 Agent Manager Brings Sovereign AI Governance to Enterprise Agent Sprawl, originally published 2026-09-18 05:36:00.
