Agent Contracts: Set the boundaries for your entire AI agent fleet

AI agents create a new control challenge. They don’t just generate outputs: they can access enterprise data, use tools, interact with systems, and take actions autonomously. And every agent can have a different purpose, risk profile, set of permissions, and environment in which it operates. As organizations move from a handful of experimental agents to hundreds or thousands in production, defining controls agent by agent won’t scale. Enterprises need clear, reusable rules of engagement that can govern an entire agent fleet. That is the problem Agent Contracts are designed to solve.
What's new: Agent Contracts
Agent Contracts provide a scalable way to define what AI agents are expected, and permitted, to do. They translate governance requirements into machine-readable controls that can be consistently applied across an agent fleet.
Instead of creating and maintaining a separate set of rules for every agent, organizations can establish a hierarchy of reusable controls. Global contracts define baseline rules that apply to all agents, while specialized contracts add requirements for groups of agents based on factors such as function, specialty, risk classification, or operating context.
This layered model gives organizations a consistent enterprise foundation while adapting controls to the different roles and risks of their agents. As new agent types emerge, governance can expand seamlessly with them.
Built as an open standard, Agent Contracts are also designed to remain independent of a specific runtime environment, providing a consistent control framework across a heterogeneous agent fleet.
How Agent Contracts helps
Enterprise policies typically exist for humans to interpret — across governance policies, compliance documents, data classifications, and other sources. Agents, however, need explicit rules that reflect what they do, the tools and data they use, and the risks they introduce. Manually translating those requirements into bespoke controls for every agent quickly becomes unmanageable. Agent Contracts bridge that gap by turning enterprise requirements and relevant agent context into a reusable control framework. Global contracts establish common boundaries, while specialized contracts adapt those requirements to different agent categories, helping governance scale without treating every new agent as a separate policy project.
Agent Contracts turn your existing governance context into machine-readable rules that can be read and enforced at runtime.
Problems Agent Contracts solve
- Policies agents cannot act on: Translate human-readable governance requirements into machine-readable controls that can become actionable for guardian agents.
- Contracts that become outdated as governance context changes: Keep agent controls aligned as underlying policies, data classifications, and other governance requirements evolve.
- No consistent code of conduct across the agent fleet: Structure a minimum set of rules that applies to all agents, then extend it with specialized contracts based on function, risk, or operating context.
- Static rules don’t capture intent: Agent Contracts combine explicit controls with intent-level information, giving Guardian Agents the context to evaluate whether an agent’s behavior remains within its intended boundaries.
- Disconnected data and agent governance: Connect agent controls with the data they use, so changes such as a new PII classification can be reflected in how agents accessing that data are governed.
How Agent Contracts work
Agent Contracts translate governance requirements and relevant agent context into machine-readable instructions that define how agents are expected to operate. A contract can capture structured rules — such as which data or tools an agent can use — alongside intent-level information describing the agent’s purpose and expected operating boundaries. This creates a common source of truth that humans can review and runtime controls can read and enforce.
Contracts use a layered model to scale across an agent fleet. A global contract establishes the minimum set of rules — a common code of conduct — that applies to all agents. Specialized contracts extend that baseline for groups of agents based on their function, specialty, risk profile, or operating context. This allows organizations to apply consistent enterprise-wide controls without creating and maintaining a separate contract for every agent.
Agent Contracts can draw on the context surrounding an agent in Collibra, including its use case, models, tools, data, metadata, policies, ownership, and other governance information. Connecting these elements helps ensure that the rules governing an agent reflect what the agent is designed to do and the enterprise resources it interacts with, rather than applying controls in isolation.

A machine-readable Agent Contract brings together explicit rules, intent, and relevant agent context to define how an agent should operate.
Agent Contracts are designed as an open standard independent of a specific runtime environment, so organizations can establish a consistent control framework even when agents operate across different technologies. At runtime, Guardian Agents use the applicable contracts to supervise agent behavior. The separation is straightforward: Agent Contracts define the rules and intended boundaries; Guardian Agents ensure those rules and boundaries are followed at runtime.
Why you should be excited
Head of AI Governance
- Establish a common code of conduct across your agent fleet instead of defining governance independently for every agent.
- Extend global controls with specialized requirements appropriate to different functions and risks.
- Create an explicit source of truth for how different categories of agents are expected to operate.
- Connect agent controls to the broader AI, data, policy, and governance context already managed through Collibra.
CAIO / CIO / CTO
- Scale control as your agent fleet grows without scaling manual governance effort at the same rate.
- Apply consistent enterprise boundaries while allowing different teams to build agents for different purposes.
- Avoid locking your agent control framework to a single runtime, cloud, or AI technology.
- Establish clearer operating boundaries before agents move into production.
Risk and Compliance Leader
- Translate enterprise requirements into explicit controls that can be applied to agents.
- Apply additional requirements where an agent’s function, data access, or risk profile demands stronger controls.
- Make the intended boundaries of agent behavior visible and reviewable.
- Connect policies and compliance requirements with the agents expected to follow them.
ML Engineer / AI Producer
- Understand the rules and intended operating scope an agent Reuse established enterprise and specialized controls instead of interpreting governance requirements independently for each project.
- Build against clearer expectations for data access, tools, actions, and escalation.
- Understand why specific controls apply based on the context and purpose of the agent.
Use cases
- Defining boundaries beyond static rules: A clinical research agent at a pharmaceutical company works with trial outcomes, adverse-event data, and demographic information. Explicit rules can define which data the agent may access, but they cannot anticipate every possible combination of data or request. An Agent Contract can capture both those explicit controls and the intent behind them — such as protecting patient privacy and keeping the agent within its approved research purpose. This provides a richer definition of how the agent is expected to operate than static rules alone.
- Keeping agent controls connected to changing data governance: A data steward reclassifies a column as Restricted-PHI. An Agent Contract connects the rules governing an agent with the relevant data classifications and governance context, helping ensure that agents using that data remain subject to the appropriate requirements as the underlying data context evolves. This closes the gap between governing enterprise data and governing the agents that use it.
- Turning enterprise policies into rules agents can understand: A risk team establishes requirements for how AI systems should handle confidential information. Instead of requiring every AI team to interpret those requirements and manually translate them into agent-specific rules, Agent Contracts provide a machine-readable way to express the applicable controls. Global requirements can apply across the agent fleet, while specialized contracts add rules for agents operating in higher-risk functions or contexts.
Key takeaways about Agent Contracts
Agent Contracts give organizations a scalable way to define what their AI agents should be allowed to do. By combining global and specialized machine-readable controls with the context surrounding agents, organizations can establish consistent rules of engagement without governing every agent from scratch. Agent Contracts provide value as a common source of truth for agent behavior while also creating the foundation that runtime capabilities such as Guardian Agents can use to supervise agents in production.
Three things to remember
- Establish a code of conduct for your agent fleet. Global contracts define common enterprise boundaries, while specialized contracts adapt them to different functions, risks, and operating contexts.
- Bring rules and context together. Agent Contracts can combine structured controls and intent-level information with relevant agent, use case, model, tool, data, and governance context.
- Define controls independently of the runtime. An open, machine-readable approach helps organizations maintain consistent rules as agents spread across different AI environments.
Agent Contracts will be available to Collibra customers through AI Command Center by the end of October 2026.
Keep up with the latest from Collibra
I would like to get updates about the latest Collibra content, events and more.
Thanks for signing up
You'll begin receiving educational materials and invitations to network with our community soon.

















