That distinction matters for IT leaders evaluating governance tools, and particularly for Windows-centric organizations with growing investments in Microsoft Copilot Studio, Azure Foundry, Entra, and Purview. An early-access product can show a credible direction and give selected customers hands-on experience. It is not yet equivalent to a generally available product with established deployment patterns, published coverage detail, and a mature record in production.
What Dataiku is promising
Dataiku describes Agent Management as a standalone product for cross-platform agent governance and business-impact measurement. Its stated aim is to help organizations manage agents created outside Dataiku as well as agents built on its own platform.
The currently named platforms are Microsoft Copilot Studio, Azure Foundry, Salesforce Agentforce, AWS Bedrock, Google Vertex, Databricks, Snowflake Cortex, n8n, and Dataiku. That list matters because it spans the major cloud, data-platform, CRM, low-code, and workflow environments where companies may be experimenting with AI agents.
Dataiku publicly identifies three primary functions:
- Centralized inventory: Scanning connected agents into one inventory and associating each with an owner and business purpose.
- Measurement: Tracking usage, cost, and quality against the stated purpose, alongside claimed business value.
- Governance and assurance: Certifying agents, scheduling tests, and maintaining risk records designed to be audit-ready.
In principle, this is a response to agent sprawl. IBM has said that only 18% of organizations maintain a current and complete inventory of their AI agents. Separately, an OutSystems survey of 1,900 global IT leaders found that 96% of surveyed organizations use AI agents in some capacity, while only 12% said they had implemented a centralized platform to manage the resulting sprawl.
Those survey findings should not be treated as a universal census of enterprise deployments. They do, however, describe a familiar operational problem: experimentation is occurring faster than many organizations’ ability to identify every deployed agent, define its accountable owner, understand what systems it can touch, and determine whether it remains useful or safe.
The release-date correction is more than a technicality
Dataiku announced the Platform for AI Success and Agent Management on March 9, 2026, and said its early-access program was available that day. That announcement did not establish a September general-availability date.
Later Dataiku communications created a more confusing timeline. An earlier company post referred to a September 2026 launch, while a September 2 Dataiku post said general availability would arrive in October. The current Agent Management product page also says availability is October 2026.
The later and current statements are the clearest available guide: Agent Management was still pre-GA as of the dossier’s September 13 research date. The available material does not specify an exact October release day, rollout model, edition, region, price, or licensing structure.
For potential buyers, this changes the appropriate question. Rather than asking whether to replace a governance stack with a mature, generally available Dataiku service today, early-access prospects should ask what they can validate before GA:
- Which of their agent environments can actually be connected?
- What metadata is discovered automatically versus entered by administrators?
- Which policy, testing, evidence, and value-measurement functions work for each platform?
- What operational and contractual dependencies on Dataiku are required?
- How will exported records fit existing audit, security, and compliance processes?
Cross-platform is the bet — but integration depth is the test
Dataiku’s central competitive proposition is not merely an agent registry. It is a registry intended to cross platform boundaries without requiring customers to migrate their existing agent frameworks. Its early-access material says customers can connect existing frameworks through native APIs without migration.
That is potentially attractive to enterprises that already have agents spread among Microsoft, Salesforce, AWS, Google, data platforms, and departmental automation tools. A separate layer could reduce pressure to force every group into one development environment simply to achieve a basic inventory and governance process.
Yet the same public material imposes an important limit: Dataiku says third-party connections rely on native APIs and log streams, and that integration depth depends on what each connected platform exposes. It also says deeper integrations are still being developed.
This is not a minor qualification. “Supports nine platforms” does not necessarily mean the same level of discovery, runtime telemetry, testing, cost data, remediation options, or compliance evidence is available across all nine. The reviewed materials do not provide a public compatibility matrix that identifies feature-by-feature coverage for each platform.
A platform might expose enough information to identify an agent, its owner, and activity history, while another could provide less detail or make data available only after delay. Some environments may allow useful lifecycle and usage measurement but not the same visibility into permissions or connected data. The public evidence does not establish uniform capabilities across Dataiku’s listed integrations.
This limitation should shape procurement requirements. Enterprises should not accept a platform list as a substitute for a scenario-based proof of capability. They should test their own high-risk workflows: a Copilot Studio agent accessing Microsoft 365 information, an Azure Foundry agent using enterprise data, a Salesforce agent interacting with CRM records, or a workflow automation that can trigger downstream actions.
Native controls remain important, especially in Microsoft estates
The emergence of a cross-platform management layer does not make native controls obsolete. Native controls generally remain closest to the identity, data, application, and activity systems that agents use.
For Microsoft environments, Agent 365 is documented as providing centralized visibility, lifecycle management, access control, and compliance through an Agent 365 registry, Microsoft Entra, and Microsoft Purview. Microsoft further describes Purview support for configured agent activity through sensitivity labels, data loss prevention, audit, eDiscovery, communication compliance, insider-risk management, and records-management capabilities.
For a Windows and Microsoft 365 organization, that makes Entra and Purview central to the actual control environment. A cross-platform product may supply broader inventory and common reporting, but it does not automatically replace the systems that govern identity and protect Microsoft-held data.
Salesforce similarly documents multiple protections through its Einstein Trust Layer, including CRM grounding, sensitive-data masking, toxicity detection, audit trail and feedback, and zero-data-retention agreements with third-party large-language-model partners. But Salesforce also documents a notable limitation: pattern-based and field-based LLM data masking is disabled for agents in specified Agentforce scenarios.
The practical lesson is broader than either vendor. Product-level governance claims need to be read alongside documented exceptions. A control described at a platform level may not apply identically to every agent configuration, every data path, or every runtime action.
Dataiku is not alone in cross-platform governance
Framing the market as Dataiku’s cross-platform approach versus vendors that govern only their own ecosystems would now be too simple.
IBM announced that watsonx Orchestrate’s AI Gateway can scan connected platforms, discover external agents, and manage them in a single control plane. IBM said Amazon Bedrock agent discovery and registration became generally available on August 31, 2026. It also said integrations for Azure AI Foundry and Google Vertex were planned for late September.
That does not prove IBM and Dataiku have equivalent capabilities. Their public descriptions, supported connections, deployment models, policy functions, and commercial terms may differ substantially. But it does show that cross-platform discovery and management is becoming a competitive category, rather than a unique Dataiku position.
The wider market moved quickly in late August and early September. Okta made Agent SSO generally available on August 24, while Broadcom introduced AgentMinder on August 31 as a control layer intended to verify agent identity and authorize actions against mission, context, and risk. IBM also announced generally available AgentOps-related capabilities in early September.
These releases target different parts of the problem. Identity-centric tooling focuses on who or what an agent is and what it may access. Runtime control focuses on whether a proposed action is authorized in context. A management layer emphasizes inventory, lifecycle, evaluation, measurement, and audit evidence. Mature enterprise governance will likely require several of these functions, not a single dashboard.
The risk case is real, but measurement needs care
Security and governance concerns are not theoretical. SailPoint reported in May 2025 that 80% of companies surveyed had experienced agents taking unintended actions, including unauthorized access to resources and inappropriate access, sharing, or downloading of sensitive data. McKinsey separately cited that research when discussing risky agent behavior.
The figure should be described accurately. It reflects reported unintended actions in the referenced survey; it is not a definitive measure that 80% of every organization has suffered a security breach caused by an agent. Nonetheless, it underscores why an agent inventory is only the starting point.
An accountable governance program needs to connect an agent’s business purpose to its identity, permissions, data access, connected tools, action boundaries, testing record, monitoring, and retirement process. If any one of those elements is missing, a central inventory can become an attractive but incomplete record of what the organization knows.
What Windows IT teams should demand before adopting a new layer
For Microsoft-heavy enterprises, Agent Management’s listed support for Copilot Studio and Azure Foundry makes it worth watching. But the product’s October target and stated variability in integration depth mean teams should approach it as an evaluation candidate, not a settled replacement for native controls.
A useful pilot should establish the following in writing and through technical testing:
- Discovery accuracy: Can the tool find the agents actually deployed across the selected environments, including those created by different teams?
- Ownership and accountability: Can each record reliably identify a business owner, technical owner, purpose, lifecycle state, and escalation route?
- Identity and permission visibility: Can governance staff connect inventory records to Entra identity, access policies, and the systems an agent can reach?
- Telemetry quality: Which usage, cost, quality, evaluation, and action data are available from each connector, and how current is that information?
- Evidence for auditors: Are certifications, scheduled tests, exceptions, and risk records exportable in a usable form?
- Native-control coexistence: Does the new layer complement rather than duplicate or obscure Purview, Entra, and other established controls?
- Failure behavior: What happens when an API, log stream, or connector becomes unavailable? Is the inventory marked stale, and who is alerted?
Dataiku’s approach addresses a genuine need: organizations building agents in multiple environments need a way to see and govern the portfolio as a portfolio. But the strongest promise — a unified control plane across disparate platforms — is also the one that will depend most on connector quality, exposed APIs, and demonstrated coverage in the customer’s own environment.
For now, the evidence supports treating Dataiku Agent Management as a significant forthcoming cross-platform governance offering, not as a completed October-ready product in mid-September. Its eventual value will be determined less by the length of its supported-platform list than by the depth, consistency, and auditability of what it can actually observe and govern across those platforms.