SYSTEM Cited by 1 source
Redpanda Agent Network View¶
Definition¶
Agent Network View is the See pillar of the Redpanda Agentic Data Plane: a live graph of an enterprise's entire agent estate, showing every agent, the models it calls, the MCP servers it's connected to, the policies applied to it, and the tools it actually invoked — with runtime overlays for guardrail violations and authorization denials, plus a KPI strip across the top (agents, conversations, tool calls, tokens, and spend).
Introduced 2026-08-03 (Source: sources/2026-08-03-redpanda-out-of-band-policy-engine-governance-ai-agents-cant-ignore).
The key property: topology derived from traffic, not a registry¶
The load-bearing design choice is that the inventory is not self-reported. Verbatim:
"Because the plane is in the path of every model call and every tool call, the topology isn't reconstructed from a survey or a registry somebody remembered to update. It's derived from traffic, so if an agent is running, it's on the graph."
"Nothing here requires the agents to cooperate, or to have been built by us, or to know they're being watched. That's the point."
This is what makes it the answer to agent sprawl
/ shadow AI — the problem that "an employee didn't file a ticket
because they didn't need to. The framework was a pip install… It took
them an afternoon to go from idea to production." A registry-based
inventory misses exactly the agents nobody registered; a traffic-derived
inventory can't, because the data
plane sits in the path of every model and tool call.
Why it is an out-of-band control¶
Agent Network View observes agents from outside their reach: it requires no cooperation, no shared framework, and no awareness by the agent. That makes it consistent with out-of-band enforcement — the observation surface is not something the agent can disable or hide from, because it is derived from the traffic the data plane already carries. It is the observability half of governed agent data access rendered as a live graph rather than an after-the-fact audit query.
Relationship to sibling systems¶
- OBPE — the Govern pillar. Agent Network View sees what every agent reaches; OBPE constrains what each may see/return at the MCP boundary. The guardrail-violation and authorization-denial overlays on the graph are OBPE's decisions rendered visually.
- Agent kill switch — the Stop pillar (coming soon). Agent Network View is where a misbehaving agent becomes legible before it is cut off.
- Agentic Data Plane — the governance layer Agent Network View is the visualization surface for.
Caveats¶
- Coupled to being in-path. The traffic-derived guarantee holds only for agents whose model/tool calls actually traverse the Agentic Data Plane; an agent that egresses entirely outside the plane is invisible to it (the whole-path coverage question the source raises — whole-path-governance).
- No scale numbers. The post gives no figures for how many agents / edges the graph renders or its refresh latency.
Seen in¶
- sources/2026-08-03-redpanda-out-of-band-policy-engine-governance-ai-agents-cant-ignore — introduction (2026-08-03) as the See pillar of the See/Govern/Stop release; traffic-derived agent-estate graph with runtime overlays + KPI strip.
Source¶
- Original: https://www.redpanda.com/blog/agentic-ai-needs-out-of-band-governance
- Raw markdown:
raw/redpanda/2026-08-03-out-of-band-policy-engine-governance-ai-agents-cant-ignore-1e570767.md
Related¶
- systems/redpanda-agentic-data-plane — the governance layer this is the See pillar of.
- systems/out-of-band-policy-engine — the Govern pillar sibling.
- coding-agent-sprawl — the problem a traffic-derived inventory solves.
- out-of-band-agent-enforcement — why observation-from-outside-the-agent matters.
- concepts/governed-agent-data-access — the observability axis this renders live.
- systems/model-context-protocol — the MCP servers whose connections appear on the graph.
- companies/redpanda — company page.