
WSO2 has released the general availability version of WSO2 Agent Manager, an open-source platform aimed at helping enterprises rein in the fast-growing sprawl of AI agents. The company says the product centralizes governance, identity management, security controls, and operational oversight for agents running across different models, frameworks, and deployment environments.
Why WSO2 Agent Manager exists
WSO2’s pitch is that enterprises are moving quickly from experimenting with AI agents to deploying them in real workflows, but the systems used to control those agents have not kept up. Agents can now call tools, access APIs, delegate work, and interact with other agents, which creates new questions around authority, accountability, and lifecycle management.
The company says its approach separates agent governance from agent logic. In practice, that means organizations can apply common controls without tying them to a single model provider, framework, or runtime.
What the general availability release adds
Agent Manager first entered beta in June 2026. The newly announced general availability release adds deeper agent identity capabilities, governance controls for Model Context Protocol, or MCP, interactions, and a Kubernetes-native sandboxed runtime.
WSO2 says the platform is designed to operate across cloud, on-premises, and hybrid environments. That positioning is meant to give organizations a way to manage agents consistently even when those agents are built on different infrastructure stacks.
Identity and authorization for non-human actors
A major focus of the release is agent identity. WSO2 says Agent Manager provides a central inventory and management layer with support for verifiable agent identity, role-based access, delegation, token exchange, and access revocation.
The platform also includes lifecycle controls that let teams move agents through development, staging, and production, and suspend agents when necessary. For enterprises, that mirrors the kind of governance they already expect for human users and traditional applications, but applied to autonomous software.
Controls across the agent stack
WSO2 says the platform includes more than 40 built-in controls, covering areas such as personally identifiable information masking and rate limiting. These policies can be applied across different parts of an agent workflow, including the agent layer, MCP layer, and LLM layer.
The company’s argument is that policy should follow the workload regardless of what powers it underneath. That matters because enterprises are increasingly mixing models, frameworks, and providers across different use cases.
Sandboxing and observability are part of the pitch
The new release also introduces a sandboxed execution runtime, reflecting concerns about agents being granted access to files, tools, APIs, and enterprise systems. WSO2 says the Kubernetes-native runtime is intended to create a controlled environment for execution while still allowing activity to be monitored and managed.
Agent Manager also uses OpenTelemetry for tracing, along with evaluation capabilities intended to monitor agent behavior over time. Those evaluations can be rule-based or LLM-based, and WSO2 says they can help teams spot issues such as unexpected token consumption, changes in behavior, or declining response quality.
Framework independence is the core design idea
WSO2 emphasizes that Agent Manager is built to stay independent of any single AI stack. The platform supports technologies including LangChain, CrewAI, Amazon Bedrock, Azure, Ballerina, and custom-built agents, while using standards such as OpenTelemetry, MCP, and OAuth 2 extensions.
The company’s broader point is that models and frameworks will continue to change quickly, but governance requirements tend to stay the same. By keeping identity, policy, and monitoring in a separate layer, WSO2 argues that organizations can change the underlying AI technology without rebuilding their control plane each time.
Enterprise AI agent governance is becoming a platform issue
WSO2’s launch lands in the middle of a wider industry shift. Major cloud and platform providers are also adding pieces of non-human identity, tool authorization, policy enforcement, runtime isolation, observability, and evaluation to their agent offerings.
According to the source material, recent analysis from Qovery has argued that no single platform yet delivers a complete governance stack across every layer. That has led to a practical reality for enterprises: they may need to combine identity systems, policy engines, infrastructure control planes, and isolated runtimes rather than rely on one vendor to solve everything.
Seen that way, Agent Manager is part of a broader attempt to treat AI agent governance the way enterprises have long treated cloud operations: as a cross-cutting control problem rather than a feature of the application itself.
What enterprises will likely watch next
For organizations evaluating AI agents at scale, the main questions now extend beyond what an agent can do. Enterprises also need to know who or what the agent is, what it is allowed to access, how its behavior is monitored, and how quickly it can be paused if something goes wrong.
- Can the agent’s identity be verified and revoked?
- Can permissions be managed independently from the model or framework?
- Are tool and API calls visible through tracing and evaluation?
- Can the runtime be isolated in cloud, on-premises, or hybrid deployments?
- Can policies apply consistently across the full agent workflow?
Those are the kinds of controls WSO2 is trying to bundle into one platform. Whether enterprises adopt it will likely depend on how well it fits alongside the other identity, security, and infrastructure systems they already use.
Source: Original report
Was this helpful?
Explore more: AI Automation Services More AI & Automation Tech News
Last Modified: September 18, 2026 at 10:34 pm
0 views
