WSO2 Agent Manager Brings Sovereign AI Governance to Enterprise Agent Sprawl
General availability adds sandboxed runtime, verifiable identity, and MCP-level governance, giving enterprises control of every agent without being tied to one model or framework
Austin, TX – September 15, 2026 – WSO2 today announced the general availability of WSO2 Agent Manager, an open control plane that governs AI agents across any framework, model, or deployment, helping enterprises put agents in production with confidence and regain control of agent sprawl. Fully open source and deployable anywhere, Agent Manager gives enterprises complete sovereignty over how they manage their own agents, regardless of framework.
WSO2 Agent Manager launched in beta in June 2026. Agent Manager lets enterprises secure, operate, and manage their entire agent estate, whether controlling what agents access (LLM, MCP and agent level guardrails, agent identity) or how they run (sandboxed runtime, observability, evaluation). Companies can now manage the full agent lifecycle in one place, cleanly separating agent governance infrastructure from agent logic. Implementing agent controls in a centralized and open platform gives teams consistent compliance enforcement and more flexibility: swapping models, frameworks, or deployments without rebuilding agent governance. General availability adds per-agent, per-environment agent identity controls, MCP-level governance and a sandboxed runtime within the platform.
"Speed and control get treated like a tradeoff. They shouldn't be," said Dr. Rania Khalaf, chief AI officer at WSO2. "Teams want the freedom to use the best model or framework for the job at hand and control has to respect that heterogeneity. When governance is separated from agent logic, it can scale across frameworks instead of being locked into one ecosystem. Speed comes because of control that never needs to be rebuilt, and that’s exactly what WSO2 Agent Manager delivers."
Why every enterprise needs an open agent control plane
Enterprise agent deployment continues to outpace the infrastructure meant to govern it. Most organizations have stitched together tools bought for separate jobs: a gateway for traffic, an identity system for credentials, an observability platform for monitoring. Yet none of them cover the full agent lifecycle. Gartner predicts the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, while only 13% of organizations think they have the right AI agent governance in place. Left unmanaged, that scale becomes agent sprawl: agents nobody can fully see, govern, or shut down.
Agent identity is where that gap has been slowest to close. Agents are still squeezed into identity categories built for people, and the moment one calls a tool or an MCP server, there's often no policy layer at all. Identity has to be central to any control plane, not an afterthought bolted on later.
The control plane must also stay flexible enough to meet changing AI needs. Providers change terms, throttle capacity, or deprecate models with little notice, and enterprises increasingly require the flexibility to keep critical agents running without depending on a single vendor's infrastructure. That flexibility is what delivers sovereignty from vendor lock-in.
A single solution for full agent control
WSO2 Agent Manager replaces stitched-together tooling with one system, giving enterprises full control over the agent lifecycle no matter which model or framework they use today or switch to tomorrow.
The full capability list includes:
- Federated agent management: One inventory for every agent on any model, framework or runtime across cloud, on-premise, or hybrid deployments
- Agent identity and security: Verifiable identity, role-based access, delegation, and token exchange for every agent, with instant revocation
- Governance and trust at the organization and agent levels: 40+ built-in guardrails — PII masking, rate limiting, and more — enforced at the agent, MCP, and LLM levels
- Full lifecycle management: A versioned path from development to staging to production, including the ability to suspend an agent in a single click
- Observability and Evaluation: End-to-end OpenTelemetry tracing with continuous evals at the trace or agent level, with rule based or LLM-as-a-judge monitors to catch runaway token spend or accuracy drift early.
- Scalable agent execution runtime: Secure, Kubernetes-native and sandboxed runtime, with real-time agent suspension
- Open, framework-agnostic foundation: Built in open source with open standards, including OpenTelemetry, MCP, and OAuth2, Agent Manager can manage agents in any Python or Ballerina framework that supports OpenTelemetry, such as LangChain, CrewAI, Amazon Bedrock Strands, or Microsoft Agent Framework.
WSO2 is both defining the standards needed to effectively govern agents and delivering these controls within their products, included among notable vendors in Forrester's Agent Control Plane Landscape, Q2 2026 report and winning Best Innovation in Open Source AI at the AI Dev Summit's 2026 AI Tech Awards. WSO2 co-authored the whitepaper Identity Management for Agentic AI with the OpenID Foundation and an OAuth 2 extension for MCP, standards that formed the foundation of identity and MCP governance in Agent Manager. The company recently joined the Agentic AI Foundation (AAIF), continuing to support the agentic community in defining foundational AI infrastructure.
Availability
WSO2 Agent Manager is generally available now, released under the Apache 2.0 license and deployable self-hosted, giving enterprises sovereignty over where agent data lives and runs, or as managed SaaS.
To learn more, visit wso2.com/agent-platform/agent-manager, or join the webinar on September 29, 2026.
Forrester Disclaimer
Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here.
About WSO2
For more than 20 years, WSO2 has provided the open source infrastructure powering technology used by millions around the world. Today, that foundation extends to AI-native tooling, giving enterprises the infrastructure to build, manage, and scale AI agents with sovereign, trusted governance. WSO2 delivers this through its Agentic Enterprise Fabric, a composable stack spanning agent, API, integration, identity, and engineering platforms. They provide agent control and lifecycle management; API and AI gateway capabilities that make data and AI models discoverable, governable, and safe for agents to consume; connectivity across legacy and modern systems; unified identity and access for humans, applications, and agents; as well as self-service platform engineering for developers and agents alike. These industry-recognized platforms help enterprises build with confidence at the speed the agentic enterprise demands. Founded in 2005, WSO2 has offices in Australia, Brazil, Germany, India, Spain, Sri Lanka, the UAE, the UK, and the US. Visit wso2.com to learn more.
Trademarks and registered trademarks are the properties of their respective owners.
###
PR Contact
Zaithoon Bin Ahamed
WSO2 Head of Corporate Communications
[email protected]