The enterprise AI conversation has been dominated by model-level concerns. Yet the truly consequential risks emerge from what agents do: the credentials they use, the data they access, the tools they invoke, and the autonomous decisions they execute across organizational boundaries.
Model-level safety and execution-level governance are complementary layers. Most enterprise architectures address the first while leaving the second largely ungoverned. The result is a structural gap between an agent that produces acceptable outputs and an agent that operates safely in production.
This paper introduces the architectural principles behind AgentVisor, Manetu’s Controlled Autonomous Runtime Execution platform. The objective is straightforward: govern every agent action at the runtime boundary through policy authorization, credential separation, and durable observability without requiring changes to agent code.