<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Governance on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/governance/</link><description>Recent content in Governance on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:20:27 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/governance/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS Agent Registry for AI agent discovery and governance is now GA</title><link>https://curadevops.metacog.co.kr/insights/2026-09-01-aws-agent-registry-for-centralized-agent-discovery-and-gover/</link><pubDate>Tue, 01 Sep 2026 15:20:27 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-01-aws-agent-registry-for-centralized-agent-discovery-and-gover/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> New GA AWS service adds cross-account agent catalog support via CloudFormation, Terraform, CDK, and AWS RAM — worth evaluating this quarter if your org is building shared AI agent infrastructure, as it may change how you architect agent discovery and access control across accounts.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> AWS Agent Registry offers a governed, org-wide catalog for AI agents and tools with audit trails and cross-account sharing; worth tracking as a pattern for AI governance strategy, but no immediate decision or vendor-risk event is present.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>GitHub Copilot model access update for multi-org Team plan seats</title><link>https://curadevops.metacog.co.kr/insights/2026-09-01-copilot-model-access-update-for-github-team-plans/</link><pubDate>Tue, 01 Sep 2026 15:20:27 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-01-copilot-model-access-update-for-github-team-plans/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> If your org has Copilot Team seats spanning multiple GitHub organizations, review how the new multi-org model-access rules affect your billing and governance setup — no deadline, but worth confirming entitlements are as expected.&lt;/li>
&lt;/ul></description></item><item><title>CNCF governance patterns across 72 projects by maturity level</title><link>https://curadevops.metacog.co.kr/insights/2026-08-27-governance-guidance-for-cncf-projects-choosing-the-right-str/</link><pubDate>Thu, 27 Aug 2026 20:52:16 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-27-governance-guidance-for-cncf-projects-choosing-the-right-str/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Distilled governance patterns from 72 CNCF projects offer a useful reference for leaders evaluating or maintaining open-source projects or assessing the health of tools their org depends on.&lt;/li>
&lt;/ul></description></item><item><title>AI Agent Security Requires Systems-Level Controls, Not Human Review</title><link>https://curadevops.metacog.co.kr/insights/2026-08-19-17-600-actions-agent-security-is-a-systems-problem/</link><pubDate>Wed, 19 Aug 2026 11:17:39 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-19-17-600-actions-agent-security-is-a-systems-problem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> The incident data on 17,600 attacker actions is a useful framing for why platform-level controls (observation, constraint, blast-radius limiting) matter for agentic workloads, but there is no deployment action or deadline here — useful for teams beginning to run AI agents on shared infrastructure.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Relevant context for leaders setting AI adoption standards: the argument that agent governance requires systemic controls, not per-action review, shapes how to frame agentic AI policy, but no licensing, cost, or vendor decision is forced by this piece.&lt;/li>
&lt;/ul></description></item><item><title>GitHub Enterprise: team-scoped managed settings now GA</title><link>https://curadevops.metacog.co.kr/insights/2026-08-04-enterprise-team-specialization-for-managed-settings/</link><pubDate>Tue, 04 Aug 2026 12:54:10 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-04-enterprise-team-specialization-for-managed-settings/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> GitHub Enterprise admins can now delegate managed settings to specific teams via per-team config files, reducing governance bottlenecks at scale — worth noting for orgs standardizing on GitHub Enterprise with distributed platform teams.&lt;/li>
&lt;/ul></description></item><item><title>Docker CISO Panel: Governing Agentic AI in the Enterprise</title><link>https://curadevops.metacog.co.kr/insights/2026-07-23-agentic-ai-needs-guardrails-not-guesswork/</link><pubDate>Thu, 23 Jul 2026 12:19:57 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-23-agentic-ai-needs-guardrails-not-guesswork/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A panel of enterprise security leaders sharing governance frameworks for agentic AI is worth a read for leaders thinking through AI policy; no concrete product or standard to act on yet.&lt;/li>
&lt;/ul></description></item></channel></rss>