Intelligence

Drata Used to Help You Prove the Control Existed. Now It Wants to Enforce It Before the Agent Acts.

Drata built its business proving to an auditor that a control existed after the fact. On 4 August 2026 it opened Limited Availability of a product that claims to sit inline with an agent and decide, in real time, whether a proposed action is even allowed to happen. I am less interested in Drata specifically than in what a compliance vendor making that move tells you about where the rest of this market is heading.

Event analysed: . This analysis was published on 28 August 2026.

Drata built its business on proving to an auditor that a control existed. Does its new AI Agent Governance product, opened in Limited Availability on 4 August 2026, actually evaluate an agent's action before it executes and block the ones that violate policy, and does that change how Moona Intelligence reads the broader shift from monitoring agents to governing what they are authorized to do?

Drata opened Limited Availability of AI Agent Governance on 4 August 2026, extending a compliance automation platform used by more than 8,500 organizations into a claim about runtime enforcement rather than after the fact evidence. Drata's own material describes the product as three components. A Sensor registers each agent at inception and maps it to an owner, an identity, its permissions and its scope. Mission Control, which Drata also calls Inline Enforcement, evaluates every agent action against approved policy in real time and blocks violations inline, before they execute, using policies a team writes as plain English intent that Drata compiles into machine enforceable rules, shipped with a baseline set drawn from OWASP. Chain of Custody logs every decision into what Drata describes as a tamper evident record mapped to SOC 2, ISO 27001, ISO 42001, the NIST AI RMF and the EU AI Act. Drata calls the whole design an agentic control plane: one layer that discovers, enforces, monitors and proves. The release covers agents running on Anthropic today, described as already running end to end in production for early access customers, with native coverage for OpenAI, Google Vertex AI and AWS Bedrock stated as in active development rather than shipped. Three weeks before the Limited Availability launch, Drata published research conducted by Wakefield Research among 300 United States IT and security professionals at companies of 1,000 to 20,000 employees, finding that 13 percent were fully confident they had complete visibility into the AI tools running in their organization and that 71 percent said an AI tool used for governance, risk or compliance had contributed to a failed audit or a regulatory lapse at least once. That survey measures a visibility and audit gap in AI tooling generally. It is not evidence about approval processes for agents or about whether Mission Control's blocking claim holds up in practice, and this record does not treat it as either. Every claim about what Mission Control does is Drata's own account, verified through convergent independently phrased research rather than a fetched page, and none of it is independent confirmation that the block executes correctly under production load or adversarial pressure. What is genuinely new is the direction, not the proof: a vendor whose entire prior business was demonstrating that a control existed after an audit is now claiming to decide, before an agent's action runs, whether it is allowed to.

Drata's business, since it was founded, has been a specific and fairly narrow promise: point Drata at your systems, and when an auditor asks whether a control exists, Drata can show them evidence that it does. That evidence has always been retrospective by design. A screenshot, a log line, a signed off ticket, all pointing backward at something that already happened, collected continuously so nobody has to scramble for it the week before a SOC 2 audit.

On 4 August 2026, Drata opened Limited Availability of a product that does not fit that description. AI Agent Governance, and specifically the component Drata calls Mission Control, claims to sit between an agent and the action it is about to take, and decide, before that action executes, whether it is allowed to happen at all. I want to be precise about why that is the part of this announcement worth reading closely, because the headline version of this story, a compliance vendor adds an AI feature, tells you almost nothing.

What Drata says it built

Drata's own material describes AI Agent Governance as three components working together. A Sensor sits inline with the AI platforms an organization uses and registers each agent at the moment it is created, mapping it to an owner, an identity, its permissions and its scope. An MCP Proxy sits at the point every agent tool call actually passes through and evaluates each request against policy. Telemetry from that activity is reduced and masked on the device before it flows into what Drata calls a tamper evident evidence feed.

The component doing the enforcement work is Mission Control, which Drata's material also refers to as Inline Enforcement. The claim, in Drata's own language, is specific enough to be checked rather than merely admired: Mission Control evaluates every agent action against approved policy in real time and blocks violations inline, before they execute any action. Drata's own comparison for this is a fire suppression system that intervenes before damage happens, set against what it describes as the smoke detector model of most existing monitoring, which watches an agent, sounds an alarm once the action has already run, and depends on someone hearing it in time to matter.

What is verified. The 4 August 2026 Limited Availability announcement, the three component architecture, the description of Mission Control evaluating actions against policy in real time and blocking violations before execution, the plain English to compiled policy claim, the agentic control plane framing, the Chain of Custody evidence description, and the Anthropic only current scope all come from Drata's own published material, corroborated through repeated, independently phrased research passes that converged consistently on the same language across Drata's newsroom, product and learn pages. Drata's domain was not directly fetchable in this session's tooling environment, so nothing below is quoted from a page this record rendered itself; every source is marked accordingly. Everything after this section is interpretation, and it is labelled as such.

Why the execution boundary is the part that caught my attention

Moona Intelligence has read this same architectural distinction before, from companies that do not compete with each other and do not appear to be coordinating. Fortinet's acquisition of Virtue AI bought a product built around blocking a malicious tool call before it fires, sold into security teams. Rubrik's Agent Identity mints a scoped credential only after a specific tool call has already cleared policy, sold into data protection teams. Guidelight's independent assessment of frontier AI developers draws a hard line between monitoring that happens after an action has already run and monitoring that evaluates a proposed action before it executes and can stop it, aimed at AI safety practice.

Drata is none of those things. It is a GRC platform, sold to compliance and security teams whose job has historically been proving what already happened, not deciding what happens next. When a vendor from that specific corner of the market describes its new product with the same architecture, evaluate before execution, block if it fails, that is a different kind of evidence than one more security company doing what security companies do. It suggests the execution boundary is not a feature one product category invented. It is a shape the problem itself is imposing on whoever tries to govern agents seriously, regardless of which market they walked in from.

Monitoring is not enough once the agent can act

Guidelight's Control standard names the distinction precisely: asynchronous monitoring scans activity after it happens and can flag a problem but cannot undo it, while what Guidelight calls semi synchronous monitoring evaluates a proposed action before it runs and can block it. Drata's own framing lands on the same side of that line, in its own words: a monitoring tool that watches and alarms after the fact is a smoke detector. A system that intervenes before the action completes is something else.

That distinction matters more for a compliance platform than it might for a security product, because compliance tooling has spent decades built almost entirely on the after the fact side of that line. An access review runs quarterly. An audit sample checks a period that already closed. A control test confirms a policy was followed, once the period is over. None of that architecture assumes it can stop the thing it is checking. It assumes the thing already happened and its job is to document it accurately. An agent that can act in seconds does not leave room for a quarterly review to matter before the consequence exists. If Drata's own read of its market is correct, and enough of the surrounding evidence in this ledger points the same direction that I take the read seriously, compliance tooling built entirely on the retrospective model has a real problem with autonomous agents, independent of anything Drata specifically ships to answer it.

Governance moving into the execution path is the actual story

Set Drata's specific product aside for a moment and look at what the move itself represents. A company whose entire prior product surface was evidence collection, the Trust Graph, the audit workflows, the framework mappings, has now built a component that sits inline with an agent's own tool calls and makes an allow or deny decision on each one, using policy the customer wrote. That is a categorically different kind of software than anything in Drata's product history before this. Evidence collection can be wrong and nothing breaks except a future audit finding. A policy engine that blocks a tool call sits directly between the agent and whatever it was trying to do, and a mistake in either direction, blocking something legitimate or missing something dangerous, has an immediate operational consequence.

Drata is not choosing to carry that risk for no reason. Compliance vendors do not usually volunteer for operational blast radius. The more plausible reading is that Drata's customers were already telling it that evidence of what an agent did, produced after the fact, was no longer the thing they needed most. They needed to know, before an agent with real system access did something, whether it was allowed to.

Why identity and authority are becoming the same question

The part of Drata's architecture that connects most directly to evidence already in this ledger is the Sensor's registration step: mapping every agent, at the moment it is created, to an owner, an identity, its permissions and its scope. That is the same move Rubrik documents with Agent Identity, minting scoped access tied to a specific call rather than a standing grant, and the same question DataHub's approval gate raises about who controls the setting that decides whether an approval requirement applies at all. None of these companies compete with each other, and none of their architectures are identical. What they share is a premise: an authorization decision cannot be made sensibly without first answering who, or what, is asking. Mission Control's policy evaluation is only as meaningful as the identity, permissions and scope the Sensor attached to that agent in the first place, which is presumably why Drata built the two together rather than shipping enforcement on top of an unidentified actor.

What Drata's own market data actually shows, and does not

Three weeks before the Limited Availability launch, Drata published research it commissioned from Wakefield Research, surveying 300 United States IT and security professionals at companies of 1,000 to 20,000 employees, fielded in March 2026. The headline figures: 13 percent said they were fully confident they had complete visibility into the AI tools running inside their organization, leaving 87 percent without that confidence. 71 percent said an AI tool used for governance, risk or compliance work had contributed to a failed audit or a lapsed regulatory standard at least once.

I want to be exact about what that survey does and does not support, because it would be easy to read it as evidence for the Mission Control launch and it is not that. It measures visibility into AI tooling broadly and its history of contributing to audit failures. It says nothing about whether organizations want inline blocking specifically, whether they trust a policy engine to make that call correctly, or whether an approval workflow versus an automated block is the preferred design. It is also research Drata commissioned and published about the problem its own new product is positioned to solve, which is a normal thing for a vendor to do ahead of a launch and a real reason to read the numbers as evidence of a category Drata wants to exist rather than as neutral proof the market has already decided how to solve it. The genuinely useful fact underneath the marketing is narrower and still worth having: a meaningful share of the compliance professionals Wakefield surveyed say they cannot see what AI is doing inside their own organization, and that gap has already cost some of them an audit finding. That is evidence the visibility problem is real. It is not evidence that Drata's specific answer to it is the one the market will choose.

What changed for me, and what did not

Here is where I want to separate three different things rather than let them blur into one conclusion, because that blurring is exactly the failure mode this kind of announcement invites.

Moona Intelligence's own flagship reading of this market has argued that you cannot prompt your way out of agent authority, that instructions given to a model are not the same thing as authority checked at the moment an action runs. The fact in front of me is narrow: Drata says Mission Control evaluates an agent's action against policy and blocks it before execution if it violates that policy, and describes early access customers running this against Anthropic agents in production. That is Drata's own account, not something an auditor, a customer or Moona Intelligence has independently confirmed by watching it stop a real violation. Vendor demonstrations of access control mechanisms elsewhere in this ledger, including Rubrik's own worked example, have consistently turned out to be exactly that: illustrations of an intended design, not proof of behavior under adversarial pressure at scale.

The inference is broader and, I think, defensible: a compliance vendor building this specific architecture, evaluate before execution, block on failure, independently of the security vendors already doing the same thing, is evidence that the execution boundary is not one market's idea. It is where the problem is pushing anyone who tries to govern an agent seriously, regardless of which door they walked in through.

The thesis question is the one I want to be most careful about. One vendor's claim that it moved a control inline does not establish that inline enforcement is the winning architecture for this market, and I am not asserting that it does. What it does is add one more independent data point, from an adjacent market, to a pattern this ledger has already been tracking from security vendors and infrastructure providers. A pattern with a new, unrelated contributor is a stronger pattern than the same pattern with one more example from the same corner of the market. It is still not proof of an outcome.

My read by control surface

Moona Intelligence tracks a small set of control surfaces across every record in this ledger. Here is how I read this specific piece of evidence against each of the ones it touches, and I want to be equally clear about the one it does not.

Execution Authority. Strengthened, modestly. This is the surface Mission Control's own claim is most directly about, and an independent vendor from outside the security market making the same architectural move as Fortinet, Virtue AI and Rubrik adds real weight to the pattern that control is relocating to the moment of action. The qualifier matters: this is Drata's own account of its own product, not independently verified behavior in production.

Agent Identity. Strengthened, modestly. The Sensor's owner, identity, permissions and scope mapping at agent creation is consistent with what Rubrik, GitLab and AWS already document, and a compliance vendor building the same premise from a different angle, that authorization requires a resolved identity first, is corroborating evidence rather than a new claim.

Audit and Evidence. Strengthened. This is the surface closest to Drata's actual history, and Chain of Custody's mapping to SOC 2, ISO 27001, ISO 42001, the NIST AI RMF and the EU AI Act is a credible, in character extension of a compliance evidence business into agent activity specifically. Of everything in this announcement, this is the claim I find easiest to believe Drata can actually deliver, because it is the closest to what the company has always done.

Approval Controls. Unchanged. Drata describes a configurable choice between a human staying in the loop for consequential actions and a human staying on the loop for lower risk ones, which is a real design decision but not a new one. DataHub, GitHub's Agentic Workflows and TrueFoundry's gateway have already established that approval gates for agent actions exist and that who controls the gate is the harder question. Nothing in Drata's material adds new evidence to that specific question.

Sequence Integrity. Insufficient evidence, and I want to be direct about why rather than let this pass quietly. Mission Control, on every account available, evaluates each agent action against policy individually, in real time, at the point of that specific tool call. Nothing in Drata's published material describes evaluating several individually permitted actions together for the authority they accumulate as a set, or checking whether actions that each look fine taken alone add up to something the policy would have refused taken together. That gap is not a criticism unique to Drata. Almost nothing in this ledger yet addresses authorization that depends on what an agent already did, and this record is not going to manufacture a change on this surface that the evidence does not support.

What I would watch next

Whether coverage actually reaches OpenAI, Google Vertex AI and AWS Bedrock on the timeline Drata implies, since a control plane that only governs one model provider is a narrower claim than the framing around it suggests. Whether any customer, auditor or third party publishes an account of Mission Control blocking a real policy violation in production, rather than a vendor demonstration. Whether Drata or anyone else extends this kind of policy evaluation from a single action to several actions considered together. And whether other compliance and GRC vendors, the market Drata actually competes in, make the same move toward inline enforcement, which would be the independent convergence this ledger looks for before calling anything a market consensus rather than one company's roadmap.

What would change my mind

A documented case, from a customer or an independent party rather than from Drata, of Mission Control correctly blocking a genuine policy violation under real conditions would move the execution authority read from a vendor claim toward verified behavior. Evidence that the block can be bypassed by an agent retrying with a slightly different action, a limitation Guidelight's own standard names honestly as a real weakness of blocking architectures generally, would narrow the claim in the other direction. And if Drata's own coverage stalls at Anthropic only for an extended period, that would be worth reading as evidence that inline enforcement across multiple model providers is harder to generalize than the announcement implies.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[2]
AI Agent Governance Software
Drata · Technical documentation
[3]
The Agentic Control Plane: A Complete Guide
Drata · Technical documentation
[5]
Drata Opens Limited Availability for AI Agent Governance Product
Security Boulevard · 5 August 2026 · Journalism
[8]
AI visibility gap hits compliance teams, Drata finds
SecurityBrief UK · 16 July 2026 · Journalism

Related Intelligence

All Intelligence Records →