Govern the control, not only the product
The program needs named accountability, review cadences, and an exception path before the first agent is gated.
Use existing enterprise disciplines
Identity governance, infrastructure as code, change control, JIT elevation, and SIEM operations already provide the pattern.
Move by agent class
Different risk profiles reach enforcement on different schedules. The estate should never depend on one big-bang cutover.
Measure trustworthiness
Decision volume, refusal reasons, policy changes, exceptions, and audit verification show whether the control is healthy.