Every platform now sells agent governance. Guardrails to bound behaviour, identity so agents can be permissioned like employees, control planes to watch them work. Kinaxis frames its supply chain agents as "governed, not autonomous", and the phrase could stand for the industry's whole posture. All of it answers one question. What may the agent do?
None of it answers the question you will actually manage by. Of the million actions agents take on your behalf this week, nearly all of them correct and inside policy, which handful genuinely needs a person, and who decides?
A century of prior art
That question is not new. Management by exception is roughly a hundred years old; it is the discipline that lets a plant manager run a factory without watching every machine, because thresholds, materiality rules and escalation paths decide what surfaces. The manager's attention is treated as the scarcest resource in the building and spent accordingly.
Agents multiply the actions taken on your behalf by orders of magnitude, which multiplies the value of exactly that discipline. Attention does not scale with the fleet. The routing rules must.
Autonomy is safe where exceptions are routed well, and unsafe everywhere else.
Governance without routing is a promise
Read the governance messaging closely. It describes what agents are prevented from doing, and it never says which deviations are material, who gets interrupted at what severity, or what happens when an exception is ignored.
Picture the first month of a deployed fleet. A planner arrives on Tuesday to find four hundred purchase orders re-sequenced overnight, every one inside policy, and one of them quietly cancelling a delivery a key account had been promised. Which of the four hundred should have interrupted someone's evening? The guardrails have no opinion; nothing was breached. The person explaining the missed promise on Thursday's call will have one.
The routing spec
Treat agents as an exception problem and you get a specification instead of a posture. Every class of machine action gets a materiality threshold. Crossing it creates one exception with a severity, an owner and a deadline. Exceptions are deduplicated and ranked, because ten duplicate alerts bury the one that matters. Escalation fires when the clock runs out, and every routed exception records what the human did, so the thresholds get reviewed against evidence rather than folklore.
None of that is speculative. It is what management by exception at machine scale already looks like in production, applied to a new source of events. Agents do not change the discipline, but they make skipping it much more expensive.
Prophesee's answer to the agent question is Pulse, which routes millions of events into the handful of decisions that need a person, with thresholds, owners and clocks attached. It is one exception engine shared across every module, so an escalation rule proven in one corner of the business is inherited by the next. A bolted-on control plane cannot compound like that. To see your own exception stream, start here.