Watchlight AI
Back to Blog
Agent Runtime GovernanceWatchlight AI BeaconAI SecurityEnterprise AIAgentic AIObservability

Announcing the Agent Execution Graph: See Every AI Agent Action as It Happens

Aldo PietropaoloApril 8, 20267 min read
Share

When an AI agent calls an API, invokes a tool, delegates to another agent, or accesses a customer record, your security team should be able to see it. Not in a log file. Not in a search query. In a live graph that shows every action as it happens, with the full governance context: who authorized it, what intent was declared, which policy decided it, and how it connects to every other action in the same execution chain.

Today we are announcing a new capability in Watchlight AI Beacon: the Agent Execution Graph.

Why This Matters

AI agents do not behave like traditional software. They reason about what to do, choose tools at runtime, delegate to other agents, and chain actions across systems at machine speed. A single user request can trigger dozens of API calls, multiple policy evaluations, and several delegation hops, all happening in seconds.

Security teams need a way to see this. Not after the fact. Not by reconstructing timestamps across separate log systems. In real time, as it unfolds.

The questions security leaders are asking:

  • "What are our AI agents doing right now?"
  • "Which agents are most active, and what tools are they invoking?"
  • "When that agent accessed our CRM five minutes ago, what authorized it and where did the chain start?"
  • "Are any agents behaving in ways that should trigger investigation?"

Traditional observability tools were built for services that follow predictable code paths. They were not built for autonomous actors that select tools dynamically and delegate to each other at runtime. You can have full coverage of every API call your agents make and still not be able to answer these questions.

What the Agent Execution Graph Is

The Agent Execution Graph is a live, queryable graph of every governed agent action across your environment. It is built from the events that flow through the Watchlight AI Beacon control plane: policy decisions from the policy engine, API requests through the runtime enforcement proxy, tool invocations, agent spawns, and execution lifecycle events.

Every action becomes a node. Every relationship becomes an edge. Delegation, tool calls, resource access, and policy authorization are all captured as the action happens, then materialized into a graph that security teams can search, visualize, and query in real time.

See It in Action

The video walks through the Agent Execution Graph in Watchlight AI Beacon: viewing live agent activity, drilling into a specific execution chain, and reconstructing the full delegation path from the originating user through every policy decision to the downstream resource.

How It Works

The graph is built from an event-driven pipeline that subscribes to governance events as they happen.

1. Event emission. Every component in the Watchlight AI Beacon control plane emits structured events. The runtime enforcement proxy emits execution start, API request observed, and execution completed events. The policy engine emits policy decision events with full evaluation context. Agent frameworks emit spawn and lifecycle events.

2. Event transport. Events flow through a NATS JetStream backbone with durable consumers. This means events are reliably delivered, can be replayed for audit reconstruction, and survive transient outages without loss.

3. Graph materialization. A dedicated service consumes the event stream and reconstructs the execution graph in real time. Events are normalized, deduplicated, and assembled into nodes and edges. Each execution is connected to its parent, its children, the policies that evaluated it, the resources it accessed, and the agents that participated.

4. Anomaly detection. As the graph is built, automatic anomaly detection flags suspicious patterns: broken delegation chains, denied actions following allowed parents, deep delegation, unusual fan-out from a single orchestrator, and orphan executions.

5. Query and visualization. The graph is exposed through a query API and visualized in the governance dashboard. Security teams can search by execution ID, agent identity, policy decision, time range, or session, then drill into any node to see the full chain.

What You Can Do With It

Real-Time Visibility

See every agent action as it happens. Filter by agent, tool, policy decision, or time window. The dashboard updates as new events arrive. No more waiting for logs to ship or running batch reconstructions.

Forensic Reconstruction

When something goes wrong, or when an auditor asks for evidence, query the graph by any execution ID and get the full chain back: who started it, every delegation hop, every policy decision, every resource accessed. The reconstruction is built from immutable, append-only events.

Anomaly Alerting

The graph flags suspicious patterns automatically. A child execution denied after its parent was allowed. A delegation chain that exceeded depth thresholds. An orchestrator that spawned an unusual number of sub-agents. These are surfaced in real time so security teams can investigate before incidents escalate.

Compliance Evidence

Every node in the graph carries the governance context that auditors care about: agent identity, declared intent, authority grant, policy version, evaluation result, and timestamp. When a regulator asks "can you prove this action was authorized?", the graph is the answer.

Cross-Service Correlation

The graph correlates events across services that were never designed to be correlated: the proxy, the policy engine, the agent framework, and the resource being accessed. A single execution ID ties them all together.

Built on the 12 Principles

The Agent Execution Graph is the operational realization of several principles from our Agent Runtime Governance framework:

The graph is also the engine behind Execution Lineage, the capability that lets security teams reconstruct any delegation chain from a single execution ID.

Why This Matters for Security Leaders

For CISOs and CIOs, the Agent Execution Graph turns AI agent governance from an aspiration into an operational reality.

Before: Audit logs scattered across systems. Reconstruction takes hours. Anomalies are discovered after the fact, if at all. The answer to "who authorized that AI to do that?" requires forensic archaeology.

After: A live, queryable graph of every agent action with the full governance context attached. Anomalies surface in real time. Reconstruction is one query. Compliance evidence is built into the system, not assembled afterward.

This is what real-time agent governance looks like in production.

Available to Founding Design Partners

The Agent Execution Graph is available now in Watchlight AI Beacon for organizations participating in our Founding Design Partner Program. We are working with a small cohort of partners to refine the capability against real-world agent deployments.

If your organization is deploying AI agents in production and wants visibility into what those agents are actually doing, we would welcome the conversation.


The Agent Execution Graph is part of Watchlight AI Beacon, the enterprise control plane for Agent Runtime Governance. To learn more, read the 12 Non-Negotiable Principles or join the Founding Design Partner Program.

Found this useful? Share it with your network.
Watchlight AI Beacon

Put runtime governance in front of every agent action

Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.

Request a Demo
Recommended Workshop

Agent Governance Readiness Assessment

Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.

2-3 days · Download one-pager (PDF)

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more