The permission layer got built, and built well. Over the last two years, every serious team shipped AI governance: what the agent may access, when it escalates, what gets logged. Real work, worth doing. All of it governs the actor.
Then the agent opens its mouth. And what comes out isn’t drawn from the permission matrix — it’s assembled from whatever the agent retrieves. Which is your estate: every public page you’ve ever shipped, current or not, owned or not, true or not.
This is the gap. Not a model problem, not a prompt problem — a knowledge problem. The agent is a well-supervised employee reading from an unsupervised library.
The estate ages on its own. Nobody deleted anything. Nobody made a mistake. The company renamed the plan, retired the product, moved the positioning — and the pages kept saying what they said the day they shipped. Watch a page drift through the bands:
An agent with clean permissions and a stale estate is a well-supervised liar.
And staleness is the gentle failure. The sharp one is contradiction— two pages that can’t both be true, both retrievable, with probability deciding which one your customer hears today.
So what does governing the knowledge layer actually mean? Not a content audit — audits are photographs of a moving thing. It means the estate holds five properties, continuously:
Hold those five and the mechanics flip. Every correct citation compounds the last; every retired page sharpens every answer that remains. The estate below is doing it right now — assembling, holding, and letting go of what no longer belongs:
The agent era doesn’t reward the loudest estate. It rewards the one that’s true. Govern what your agents say — not just what they’re allowed to do.