# Why you need an Agentic Control Plane

Your agents take real actions on real systems — refunds, writes, sends. Why hand-rolled checks don't hold in production, and what enforcing control at the call level buys you.

<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h1 class="acp-hero-h1">Why you need an Agentic Control Plane</h1>
      <p class="acp-subtitle" style="max-width:660px;margin:16px auto 0;">
        Your agents stopped chatting and started acting &mdash; refunds, database writes, emails to customers.
        The checks you hand-rolled hold only while you're watching. A control plane makes them hold when you're not:
        every call identified, checked against your rules, metered, and logged.
      </p>
    </div>
  </div>
</div>

<!-- One real incident -->
<div class="acp-section">
  <div class="acp-container">
    <h2 class="acp-section-title">What it looks like when this bites</h2>
    <p class="acp-muted" style="max-width:680px;">
      This one is ours. From <a href="/caught-in-the-wild">Caught in the Wild</a>, the running log of real interceptions on our own agents:
    </p>
    <div class="acp-card acp-card-pad" style="max-width:760px;margin-top:16px;">
      <div style="display:flex;align-items:center;gap:10px;margin-bottom:10px;">
        <span style="font-size:10.5px;font-weight:700;letter-spacing:0.08em;padding:3px 9px;border-radius:999px;border:1px solid rgba(6,182,212,0.40);color:#4cc9e0;background:rgba(6,182,212,0.10);">CAUGHT BY METERING</span>
        <span style="font-size:12px;color:var(--acp-text-faint,#71717a);">2026-07-21</span>
      </div>
      <h3 style="font-size:17.5px;line-height:1.3;margin:0 0 10px;">The surprise bill came from the one agent outside the plane</h3>
      <p class="acp-linkcard-desc" style="font-size:14.5px;line-height:1.65;">
        &ldquo;A ~$15/day model bill traced to a container running on a fresh API key &mdash; spend invisible because it never crossed the proxy. &hellip; The bill you get surprised by is always from the agent you didn't control.&rdquo;
      </p>
      <p class="acp-linkcard-desc" style="font-size:14.5px;line-height:1.65;margin-top:10px;">
        Nothing crashed. No alert fired. The agent did its job &mdash; on a key nobody was metering, at a run rate nobody chose. Every check we'd written held; the failure was the call path those checks never saw. That's the shape of the problem: agents don't fail loudly, they act quietly, and whatever isn't on the call path is invisible until the invoice, the deleted row, or the leaked record arrives.
      </p>
      <a href="/caught-in-the-wild" class="acp-btn" style="margin-top:14px;" data-track="Why: CITW">Read the full log &rarr;</a>
    </div>
  </div>
</div>

<!-- Before / After -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Before and after</h2>
      <div class="acp-table-wrap">
        <table class="acp-table">
          <thead>
            <tr>
              <th>Concern</th>
              <th>Without an ACP</th>
              <th>With an ACP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td>Identity</td>
              <td class="acp-faint">Shared API key — backend can't distinguish users</td>
              <td>Every request bound to verified user identity</td>
            </tr>
            <tr>
              <td>Authorization</td>
              <td class="acp-faint">All-or-nothing access, enforced in app code</td>
              <td>Per-user, per-tool policies enforced at the gateway</td>
            </tr>
            <tr>
              <td>Data protection</td>
              <td class="acp-faint">PII flows into prompts unchecked</td>
              <td>PII detected and redacted before reaching the model</td>
            </tr>
            <tr>
              <td>Cost control</td>
              <td class="acp-faint">No per-user limits — surprise bills, runaway loops</td>
              <td>Rate limits, budget caps, and agent guard per user</td>
            </tr>
            <tr>
              <td>Audit</td>
              <td class="acp-faint">Generic logs with no user attribution</td>
              <td>Every action logged with identity, policy, and cost</td>
            </tr>
            <tr>
              <td>Compliance</td>
              <td class="acp-faint">Manual controls, audit gaps, failed reviews</td>
              <td>Automated evidence for HIPAA, SOC2, GDPR, PCI</td>
            </tr>
          </tbody>
        </table>
      </div>
    </div>
  </div>
</div>

<!-- CTA -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h2 class="acp-section-title">Thirty seconds to the first audit row</h2>
      <p class="acp-muted" style="max-width:520px;margin:8px auto 0;">
        One command, no account, on your machine &mdash; or self-host the MIT-licensed modules. Same control engine, your choice of deployment.
      </p>
      <div class="acp-btn-row" style="justify-content:center;margin-top:24px;">
        <a href="/getting-started" class="acp-btn acp-btn-primary" data-track="Why CTA: Get Started">Get started</a>
        <a href="/reference-architecture" class="acp-btn" data-track="Why CTA: Architecture">See the architecture</a>
      </div>
    </div>
  </div>
</div>
