Agent Sprawl Meets Its Control Plane: WSO2 Agent Manager Goes GA
On September 15, 2026, WSO2 announced the general availability of WSO2 Agent Manager, an open control plane that governs AI agents across any framework, model, or deployment. It launched in beta in June 2026 and reaches 1.0 under the Apache 2.0 licence, deployable self-hosted or as managed SaaS. The pitch is deliberately unglamorous: rather than selling you another agent, it sells you the place where you can see, identify, constrain, and switch off the agents you already have. Given how fast agent estates are multiplying, that unglamorous layer is the thing most enterprises are missing.
1. The number that explains the product
WSO2 anchors the announcement to a Gartner projection: the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, while only 13 percent of organisations believe they have the right AI agent governance in place. Call that spread agent sprawl. Most teams today have stitched together a gateway for traffic, an identity system for credentials, and an observability platform for monitoring, and none of those covers the full agent lifecycle. The result is agents nobody can fully see, govern, or shut down, which is a strange thing to accept in production software.
# One inventory for every agent, whatever the framework. The manifest is
# what the control plane federates into a single agent estate.
apiVersion: agents.wso2.com/v1
kind: AgentRegistration
metadata:
name: support-triage
environment: production
spec:
framework: langchain # langchain | crewai | strands | ms-agent-framework
runtime: kubernetes
telemetry:
otel: true # required: control is built on OpenTelemetry
identity:
mode: verifiable # per-agent, per-environment identity
scopes: ["agreements:read", "tickets:write"]
delegation: true
lifecycle:
promoteFrom: staging
suspendable: trueOne inventory across cloud, on-prem and hybrid agents
2. What general availability actually adds
Three things separate the GA release from the beta. First, per-agent, per-environment identity controls: verifiable identity, role-based access, delegation, and token exchange for every agent, with instant revocation. Second, MCP-level governance, so policy is enforced when an agent calls a tool or an MCP server rather than only at the network edge. Third, a sandboxed, Kubernetes-native execution runtime with real-time suspension. Around those sit federated inventory, versioned promotion from development to staging to production, and forty-plus built-in guardrails including PII masking and rate limiting, enforced at the agent, MCP, and LLM levels.
# Policy lives outside agent logic. Guardrails are enforced at three levels
# -- agent, MCP, and LLM -- so a tool call cannot slip past the edge.
policy:
name: prod-baseline
guardrails: # 40+ built-ins ship with the platform
- pii-masking: { fields: [email, phone, national_id] }
- rate-limit: { rpm: 60, per: agent }
- token-budget:{ per_run: 120000, action: warn }
- deny-tools: ["delete_account", "export_bulk_pii"]
mcp:
servers:
- name: agreements
transport: http
allow: ["list", "get", "summarise"]
requireApproval: ["send_for_signature"]
egress:
default: deny # agents speak only to approved servers
allow: ["agreements.internal", "llm-gateway.internal"]3. Identity is the hardest part, and the announcement says so
Agent identity is where that gap has been slowest to close, the release notes, adding that agents are still squeezed into identity categories built for people. That is the correct diagnosis. An agent is not a user, not a service account, and not quite a workload identity: it has a user's intent, a service account's reach, and a workload's churn. The reference points here are worth noting. WSO2 co-authored an OpenID Foundation whitepaper on identity management for agentic AI and an OAuth 2 extension for MCP, and both standards shaped the identity and MCP governance in the product. If you are designing agent identity today, that is the paperwork to read.
# Verifiable identity is the part most stacks get wrong: an agent needs a
# revocable identity of its own, not a borrowed human or service account.
import httpx
TOKEN_ENDPOINT = "https://auth.internal/oauth2/token"
def agent_token(agent_id: str, tool_audience: str) -> str:
# RFC 8693-style token exchange: the agent presents its own credential
# and receives a narrowly scoped token for the tool it is calling.
resp = httpx.post(TOKEN_ENDPOINT, data={
"grant_type": "urn:ietf:params:oauth:grant-type:token-exchange",
"subject_token": agent_id,
"subject_token_type": "urn:wso2:agent-identity",
"audience": tool_audience,
"scope": "agreements:read",
}, timeout=10)
resp.raise_for_status()
return resp.json()["access_token"]
# Revocation is instant: a suspended agent fails the next exchange, even
# mid-run. That is the difference between a policy and a password.A Kubernetes-native runtime with real-time suspension
4. Framework-agnostic is the differentiator
The most consequential design decision is separation: governance lives outside agent logic. WSO2's chief AI officer, Dr. Rania Khalaf, frames it as refusing a tradeoff. Control has to respect that heterogeneity, she says, and governance separated from agent logic can scale across frameworks instead of being locked into one ecosystem. Practically, Agent Manager manages any Python or Ballerina agent that emits OpenTelemetry, which covers LangChain, CrewAI, Amazon Bedrock Strands, and Microsoft Agent Framework, over open standards including OpenTelemetry, MCP, and OAuth2. For a team standardising its agent stack, that means swapping models or frameworks does not force you to rebuild your controls.
# Observability is expected, not optional: end-to-end OpenTelemetry traces
# with continuous evals, so runaway token spend or accuracy drift is caught
# early rather than in a quarterly review.
from opentelemetry import trace
tracer = trace.get_tracer("support-triage")
def handle(ticket):
with tracer.start_as_current_span("agent.run") as span:
span.set_attribute("agent.id", "support-triage")
span.set_attribute("gen_ai.request.model", "gpt-5.6")
answer = plan_and_act(ticket)
span.set_attribute("gen_ai.usage.input_tokens", answer.tokens_in)
span.set_attribute("gen_ai.usage.output_tokens", answer.tokens_out)
span.set_attribute("eval.score", score(answer)) # rule or LLM-as-judge
return answer5. Where it fits in the market
Agent control planes are forming as a category fast. WSO2 is listed among vendors in Forrester's Agent Control Plane Landscape, Q2 2026 report, and it recently joined the Agentic AI Foundation. But the more useful signal is the shape of the stack: within a roughly two-week window this quarter, several vendors shipped standalone agent governance products, from SAP's agent hub to runtime identity controls. The pattern is consistent: inventory first, identity second, runtime policy third, audit always. If you are evaluating any of them, ask the same four questions. Can it enumerate every agent, can it give each one a revocable identity, can it enforce policy at the tool and MCP layer, and can it produce evidence an auditor accepts. Agent Manager is one credible answer; the questions are the durable part.
# A control plane earns its name at the moment you need to stop something.
# Suspension is one call, not a project.
import httpx
def suspend(agent_id: str, reason: str):
r = httpx.post(f"https://agent-manager.internal/api/v1/agents/{agent_id}/suspend",
json={"reason": reason}, timeout=10)
r.raise_for_status()
# The agent keeps its identity, its history and its audit trail; what it
# loses is the ability to act. That is the whole point of a control plane.
return r.json()
print(suspend("support-triage", "token budget exceeded in prod"))End-to-end OpenTelemetry tracing with continuous evals
6. How to evaluate it in a week
A practical trial takes a week. Day one, point it at an existing agent and confirm the inventory sees it without code changes. Day two, give that agent a real identity and revoke it mid-run to prove instant revocation. Day three, attach a guardrail, and PII masking is the fastest to demo, then confirm it fires at the tool level rather than only at the edge. Day four, export a trace and hand it to whoever signs off on compliance. If those four steps work on your own agents, the remaining work is process, not product. Sovereignty, in this case, means the control plane runs where your data does, and the licence lets you keep it there. One more check is worth the effort: ask the vendor to show you a revoked agent failing a tool call in the audit log rather than in a demo. Governance products are easy to believe and hard to verify, and the audit log is the line where the difference shows.
📌 Frequently Asked Questions
What is WSO2 Agent Manager?
An open control plane announced generally available by WSO2 on September 15, 2026. It governs AI agents across any framework, model or deployment, under the Apache 2.0 licence, deployable self-hosted or as managed SaaS.
What did general availability add?
Per-agent, per-environment identity controls (verifiable identity, role-based access, delegation, token exchange, instant revocation), MCP-level governance, and a sandboxed Kubernetes-native runtime with real-time suspension.
What is agent sprawl?
Large populations of agents that nobody can fully see, govern, or shut down. WSO2 cites Gartner's projection that the average Fortune 500 enterprise will run more than 150,000 agents by 2028, while only 13 percent of organisations believe their governance is in place.
Which frameworks are supported?
Any Python or Ballerina agent that emits OpenTelemetry, including LangChain, CrewAI, Amazon Bedrock Strands and Microsoft Agent Framework, over open standards such as OpenTelemetry, MCP and OAuth2.
How is it licensed and deployed?
Apache 2.0 open source, deployable self-hosted for data sovereignty or available as a managed SaaS.