Announcing the Watchlight AI Beacon Plugin Suite: Runtime Governance Across Agent Frameworks
Watchlight AI Beacon Plugin Suite
Runtime governance for LangGraph, Google ADK, AWS Bedrock Agents, MCP servers, Microsoft Agent Framework, and custom agents. Available now in early preview.
Bottom line for CISOs. Watchlight AI Beacon now enforces runtime governance across the agent frameworks your teams actually deploy: LangGraph, Google ADK, AWS Bedrock Agents, MCP servers, and Microsoft Agent Framework, plus a documented contract for custom in-house agents. One governance plane, the same policy set, the same audit trail, regardless of which framework runs underneath. Defense in depth spans multiple enforcement layers, so an unauthorized action has no single point to slip through.
The Reality of Multi-Framework Enterprises
Organizations adopting AI agents rarely standardize on a single framework. Research teams use one, product teams use another, platform teams evaluate a third. New frameworks emerge every quarter. The governance layer cannot be framework-specific without forcing the enterprise to either standardize early (slowing adoption) or accept inconsistent governance (accepting risk).
Watchlight AI Beacon's design answer is one plugin per framework, all reporting to the same governance plane. Whatever framework a team picks, the same policies are evaluated, the same audit trail is produced, and the same compliance posture is maintained.
Plugin Coverage Today
| Framework | Plan | Act | Observe |
|---|---|---|---|
| LangGraph | ✓ | ✓ | ✓ |
| Google ADK | ✓ | ✓ | ✓ |
| AWS Bedrock Agents | † | ✓ | ✓ |
| MCP servers | ✱ | ✓ | ✓ |
| Microsoft Agent Framework § | Planned | Planned | ✓ |
| Custom / in-house agents | ✓ | ✓ | ✓ |
| Additional frameworks | ‡ | ‡ | ‡ |
‡ Plugin coverage expands on a systematic and disciplined cadence. The next plugins on the public roadmap are expected to include other widely adopted agent frameworks; new plugins are prioritized by customer demand and verified production patterns, and each must meet the same trust-boundary requirements as the existing set before it ships. Watchlight AI reserves the right, in its sole discretion, to adjust plugin sequencing and the roadmap at any time.
† AWS Bedrock Agents do not expose a plan stage during execution. The Bedrock runtime makes its reasoning and tool-selection decisions internally and emits act-stage and observe-stage signals only. Plan-stage coverage for a Bedrock-based workflow requires a customer-designed agent orchestrator that declares intent and proposed actions before delegating to the Bedrock runtime.
§ The Microsoft Agent Framework plugin ships today as a canonical-event observe-stage integration: the same lineage and audit event schema as every other supported framework, ready for governance evidence, forensic reconstruction, and cross-framework compliance dashboards. Plan-stage and act-stage enforcement for Microsoft Agent Framework are on the roadmap and follow the same prioritization and trust-boundary requirements as new framework plugins.
✱ MCP servers are reached over the network and do not expose a plan stage to external observers. The decision to call an MCP tool happens upstream, in the calling framework. For full plan-stage coverage of an MCP-using agent, instrument the calling framework as well.
Related reading: Authorization Before Action: Plan, Act, Observe in AI Agent Runtime Governance, and AI Security Is Not Enough: The Case for Agent Runtime Governance.
Defense in Depth: Plugin and Proxy
Beacon governs at more than one layer. The plugin enforces in-process, with visibility into the agent's declared intent and lifecycle events. The network layer enforces on the agent's outbound activity. The two layers are complementary, and for high-assurance deployments they operate together. We work through the specific coverage model, and which layers a given workload needs, with each customer during onboarding.
What the Plugin Suite Delivers
Each plugin produces the same governance outcomes regardless of the framework underneath.
Deterministic authorization. Every action is evaluated against current policy before execution. The same input produces the same decision, every time. There is no language model in the trust path.
Per-action enforcement. Tool calls, model invocations, and agent lifecycle events all pass through policy evaluation. An action that violates policy is blocked before it commits resources or modifies state.
Forensic execution lineage. Every authorization decision, every tool invocation, and every delegation is recorded in a tamper-evident audit log. The record an auditor sees is the record the runtime emitted.
Cross-framework consistency. A research agent built on LangGraph and a production agent built on Google ADK enforce the same policies, produce the same event shape, and feed the same compliance dashboard.
Enterprise Readiness
When Agents Are Denied
When a policy denies an action, the agent receives a clear, non-retriable response. It does not loop or attempt workarounds. The agent informs the user that the action was denied by governance policy. Every denial is visible in the execution graph with the specific policy that blocked it. No silent failures.
Security for Production Environments
The plugin suite is designed for enterprise deployment from development through regulated production environments. Authentication scales from low-overhead local configuration during prototyping to machine-to-machine identity and mutual TLS for regulated environments. Service credentials are managed and rotated centrally. Designed for SOC 2, ISO 27001, and regulated enterprise environments.
The Plugin Trust Boundary
Plugins are trusted services in the governance plane. The enterprise installs them inside its agent frameworks, and Watchlight AI Beacon accepts the events they emit. That trust is structured and verified, not implicit: plugin identity, integrity, and failure modes are all accounted for in the trust model, so a compromised or misbehaving plugin is detectable rather than silently trusted. We review the trust-boundary design in detail with security teams during evaluation.
![]()
For Enterprise Teams Deploying AI Agents
If your organization is running AI agents in production, or evaluating agent frameworks for production deployment, the governance question is the same regardless of which framework you pick. Which agents are active? What can they access? Who authorized each action? Can you prove it across all the frameworks you run?
Watchlight AI Beacon provides the Agent Runtime Governance layer that compliance, security, and engineering teams need to deploy agents with confidence. The same policies across frameworks. Deterministic enforcement on every action. Compliance-grade execution lineage.
"The governance layer should not be framework-specific. With Watchlight AI Beacon, it is not."
The Watchlight AI Beacon Plugin Suite is available now in early preview. Request a demo to start governing your agents at runtime. The plugin set today covers LangGraph, Google ADK, AWS Bedrock Agents, MCP servers, Microsoft Agent Framework (observe-stage today, with plan and act-stage enforcement on the roadmap), and custom in-house agents via a documented event-emission contract.
Already deploying agents and need to design the governance architecture? Our Authorization and Runtime Control Architecture workshop helps enterprise teams design policy models, deployment patterns, and integration strategies for their agent stack. 1-2 days. Book a workshop.
Watchlight AI is an independent provider and is not affiliated with, endorsed by, or sponsored by any of the third parties referenced in this post. LangGraph, Google ADK, AWS Bedrock, Microsoft Agent Framework, the Model Context Protocol (MCP), and all other product names, logos, and brands are the property of their respective owners and are used for identification purposes only.
Put runtime governance in front of every agent action
Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.
Agent Governance Readiness Assessment
Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.
2-3 days · Download one-pager (PDF)
