WSO2 Agent Manager Targets Governance for Multi-Platform AI Agents
WSO2 has made its open-source Agent Manager generally available, combining identity, policy, sandboxing and observability features for enterprises operating AI agents across varied technologies.

A separate control layer for enterprise AI agents
WSO2 has released the general-availability version of WSO2 Agent Manager, an open-source platform intended to centralize how enterprises govern AI agents. The product is aimed at organizations whose agents may be built with different models, frameworks and deployment patterns, while still requiring consistent oversight of access, policy, activity and lifecycle.
The release responds to a management gap that can emerge as agent deployments grow. Teams can select from a widening set of AI tooling, but the mechanisms for establishing an agent’s identity, defining its permissions and supervising its operations may remain distributed across environments. WSO2 positions Agent Manager as a layer distinct from agent implementation, so controls are not intrinsically tied to a particular model, framework or runtime.
Agent Manager entered beta in June 2026. Its general-availability release expands identity functions, adds governance for Model Context Protocol interactions, and introduces a sandboxed runtime built for Kubernetes. WSO2 says the platform can operate in cloud, on-premises and hybrid settings, supporting a governance approach that does not depend on one AI provider.
Identity and authorization are central to that approach. Agents differ from conventional applications because they can call tools, reach APIs, pass work to other agents and act in enterprise systems. The platform supplies an inventory and management layer with verifiable identities, role-based access, delegation, token exchange and revocation capabilities. It also provides lifecycle management spanning development, staging and production, including the ability to suspend an agent.
WSO2 includes more than 40 built-in controls, covering functions such as personally identifiable information masking and rate limiting. Policies can be placed at several points in an agent workflow: the agent itself, the MCP layer and the LLM layer. This arrangement is designed to make governance applicable across the workflow rather than limited to a single component.
The Kubernetes-native sandbox addresses the risk profile created when agents are allowed to use files, tools, APIs and internal systems. It is intended as a controlled execution environment in which activity can be monitored and managed. For operational visibility, Agent Manager uses OpenTelemetry tracing and offers evaluations that follow agent behaviour over time. Both rules-based and LLM-based evaluations can surface signals including unusual token use, behaviour shifts and reduced response quality.
The platform lists support for LangChain, CrewAI, Amazon Bedrock, Azure, Ballerina and custom agents, alongside standards and technologies such as OpenTelemetry, MCP and OAuth 2 extensions. Its design reflects a broader industry move to treat agent governance as a platform concern. As providers add identity, authorization, policy, isolation, observability and evaluation features, enterprises operating diverse agent estates may need to combine several control layers rather than rely on a single tool.
Key points
- WSO2 Agent Manager is now generally available as an open-source governance platform for AI agents.
- The platform separates common controls from the models, frameworks and runtimes used to build agents.
- Identity, authorization, lifecycle management and more than 40 policy controls form core capabilities.
- A Kubernetes-native sandbox, OpenTelemetry tracing and evaluations support controlled operations and monitoring.
