Enterprises Are Picking Orchestration Platforms on Whether They Can Constrain the Agent
A VentureBeat Pulse survey of 107 enterprises asked why they chose their agent orchestration platform. Security and permissions came second, ahead of reliability. Control over agent execution tied with it. The number I keep returning to is a different one: when these enterprises were asked what worries them about a control plane that lives inside their AI provider, the top answer was not lock in. It was the provider's own security and permissioning limits.
VentureBeat Pulse Research fielded a survey on enterprise agent orchestration whose results were filtered to organizations of 100 or more employees, n=107, drawn from a single July 2026 wave and published by VentureBeat in August 2026. On why enterprises chose their primary orchestration platform, flexibility across models and tools led at 29%, followed by security and permissions at 17%, production reliability at 15% and control over agent execution at 15%, with model gravity last at 10%. On planned investment over the next twelve months, agent monitoring and debugging led at 31% and security and permissions enforcement followed at 30%. On the control plane, 53% said their primary control plane will be hybrid by the end of 2026, combining provider native with provider independent orchestration, and 78% intend to keep control at least partly outside the provider. Asked what risk they most associate with a provider resident control plane, respondents named the provider's own security and permissioning limitations at 37%, ahead of vendor lock in at 23% and limited visibility at 22%. On real time control of what an agent spends, 30% rely on native platform controls such as built in budget caps or throttling, 25% have built custom gateway plumbing described as proxy middleware to intercept a runaway agent, roughly a quarter use dynamic routing to cheaper models, and 21% rely on reactive monitoring alone, such as logs read after the fact. Those last figures answer a question about cost control, not about permissions, and this record keeps them labelled that way. The survey does not establish that any enterprise is buying a standalone agent authority product, does not establish that the 37% concern causes the 53% hybrid expectation, and cannot be read as representative of enterprises generally: the sample is self selected, technology heavy at 53% Technology and Software respondents, and weighted toward very large organizations, with more than half at 10,000 employees or above.
VentureBeat's Pulse Research programme ran a survey on how enterprises actually run agent orchestration. The write up that has been circulating leads on cost: enterprises have settled how they want agents governed well before they have settled how to meter what those agents spend. That is a fair reading of the data and it is not the part I want to spend this record on.
The part worth writing down is what the same respondents said when they were asked why they picked the orchestration platform they run, and what they are afraid of in a control plane that lives inside their AI provider.
What the survey measured
On the reason for choosing a primary orchestration platform, the leading answer was flexibility across models and tools, at 29%. Security and permissions came second at 17%. Production reliability and control over agent execution followed at 15% each. Model gravity, the pull of the platform that ships with the model you already use, came last at 10%.
On planned investment over the next twelve months, agent monitoring and debugging led at 31%, with security and permissions enforcement immediately behind at 30%.
On the shape of the control plane, 53% said their primary control plane will be hybrid by the end of 2026, meaning provider native orchestration alongside provider independent orchestration, and 78% intend to keep control at least partly outside the provider.
Then the question that makes this survey worth a record. Asked which risk they most associate with a control plane that sits inside the provider, respondents named that provider's own security and permissioning limitations at 37%. Vendor lock in came second at 23%. Limited visibility came third at 22%.
Two numbers this record refuses to blur
The same research carries a widely quoted pair of figures about stopping a runaway agent: 25% of these enterprises have built custom gateway plumbing, described as proxy middleware that can intercept a runaway agent, 30% rely on whatever native budget caps or throttling their platform ships, roughly a quarter route heavy work to cheaper models, and 21% have nothing but reactive monitoring such as logs read after the fact.
Those answer a question about controlling what an agent costs. They are not permissions results, and they are not a measure of whether an enterprise can stop an agent from taking a consequential action. It is tempting to fold them into a security narrative because the mechanism looks identical, a gateway sitting in front of the agent deciding whether the next call proceeds. The survey does not license that move, so this record does not make it.
It is worth noticing the mechanism anyway. A quarter of these enterprises did not wait for a platform feature. They built an interception point in front of their agents, because there was something happening at the moment an agent acts that they needed to be able to stop. They built it for the bill. The same location is where an authority decision would have to sit.
Moona Intelligence interpretation
Everything above is what the research reports. What follows is Moona's reading and should be weighed as that.
Three things look genuinely new here, and one thing does not.
First, constraint properties are showing up as purchase reasons rather than as governance policy. Security and permissions at 17% plus control over agent execution at 15% is 32% of these respondents naming a constraint property as the single reason they picked their platform. That is a different posture from an enterprise that buys an orchestration platform for capability and then writes a policy about how it will be used. VentureBeat groups those two with production reliability to reach 47%; Moona's narrower read stops at 32%, because reliability is a property of the platform rather than of the boundary around the agent.
Second, the ranking inside the provider resident concern is the interesting part, not its size. The usual enterprise objection to putting a control plane inside a supplier is commercial: lock in, pricing, negotiating position. Here lock in came second by fourteen points to a control objection. These respondents are more worried that the provider's permissioning will not be good enough than that they will be stuck with it.
Third, and least surprising, planned spend follows: monitoring at 31%, permissions enforcement at 30%. Enterprises intending to invest in permissions enforcement at nearly the same rate as in observability is a market where enforcement is no longer assumed to arrive for free with the platform.
What does not follow is causation. The 37% concern and the 53% hybrid expectation are two answers from one sample, not a demonstrated chain. It would be easy and wrong to write that enterprises are moving to hybrid control planes because they distrust provider permissioning. The research does not test that, and a hybrid control plane has other well documented reasons behind it, including the model flexibility that led the purchase driver question at 29%.
What the research also does not establish, and this matters more for Moona than anything above: nothing here shows that any enterprise is buying an independent agent authority product. The survey asked about orchestration platforms and control planes. Naming permissions enforcement as an investment priority is not the same as purchasing a separate authority layer, and reading it that way would be inventing a market the data does not contain.
What would have to be true next
The honest position after reading this is that a demand signal exists and its shape is still ambiguous. Enterprises in this sample say they want the boundary around an agent to be something they control, and a meaningful minority say that is why they chose their platform. Whether that resolves into provider features that get better, into an independently controlled execution boundary, or into more of the custom gateway plumbing a quarter of them have already built, is not answered by 107 responses in one July wave.
The question I would want the next wave to ask is narrower than any of these: when one of these enterprises stops an agent, what is it stopping it from doing. If the answer is still mostly spending, the market is buying cost control and calling it governance. If it starts to include acting, the boundary has moved.
For the supply side of the same question, see where Fortinet put the control when it bought Virtue AI, and for why an interception point that can only observe is not a boundary at all, see watching the agent is not the same as stopping it.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
