← News

WSO2 Agent Manager press graphic with Chief AI Officer Rania Khalaf quote on speed and control

15 Sep 2026

WSO2

WSO2 ships Agent Manager GA to govern enterprise AI agents without locking to one stack

WSO2 announced general availability of Agent Manager, an open-source control plane meant to secure, observe, and manage AI agents across models, frameworks, and deployments. The company says GA adds per-agent, per-environment identity controls, MCP-level governance, and a sandboxed runtime after a June 2026 beta.

Same-day SOFTWARE primary that an enterprise vendor put a framework-agnostic agent control plane into general availability, aiming at agent sprawl with identity, MCP guardrails, and a kill switch — the ops layer next to the agent boom.

WSO2 announced general availability of Agent Manager on 15 Sep 2026. General availability, or GA, means the product is out of beta and offered for production use. Agent Manager, as the company tells it, is an open control plane — the layer that sees and governs all agents — meant to secure, operate, and manage AI agents across frameworks, models, and deployments. Dual company primaries — the WSO2 newsroom and the same-day GlobeNewswire company wire — are both dated September 15, 2026, and datelined Austin, TX. Those company pages are the filing event. These are company claims. This desk did not run Agent Manager.

Product, still company: open source and deployable anywhere. WSO2 says the control plane governs agents across frameworks, models, and deployments, and separates governance from agent logic so a team is not locked to one stack. File that open / anywhere / separate-governance picture as WSO2’s. This desk did not deploy the software.

Timeline, as the same wire has it: Agent Manager launched in beta in June 2026. GA, the company says, adds per-agent, per-environment agent identity controls, MCP-level governance, and a sandboxed runtime. MCP is the Model Context Protocol — how agents talk to tools. A sandbox here is an isolated place to run an agent so a runaway job is contained. File the June beta and those three GA adds as WSO2’s. This desk did not sit in the beta.

Capabilities named on the company wire: a federated agent inventory — one list of agents across cloud, on-premise, or hybrid; verifiable agent identity with role-based access, delegation, token exchange, and instant revocation; 40-plus built-in guardrails, including PII masking and rate limiting, enforced at the agent, MCP, and LLM levels; full lifecycle management with a versioned path from development to staging to production and the ability to suspend an agent in a single click; end-to-end OpenTelemetry tracing with continuous evaluations; and a Kubernetes-native sandboxed runtime with real-time suspension. File that list as WSO2’s. This desk did not count the guardrails or time a suspend.

Frameworks, still company: Agent Manager can manage agents in any Python or Ballerina framework that supports OpenTelemetry, such as LangChain, CrewAI, Amazon Bedrock Strands, or Microsoft Agent Framework. OpenTelemetry is a common way to record traces — the step-by-step log of what software did. File those names as WSO2’s. This desk did not wire a LangChain agent into the product.

Problem framing, as WSO2 tells it: enterprises have stitched together a gateway for traffic, an identity system for credentials, and an observability platform for monitoring, and none of those cover the full agent lifecycle. Left unmanaged, the company says, that becomes agent sprawl — agents nobody can fully see, govern, or shut down. File that stitch-and-sprawl picture as WSO2’s. This desk did not survey enterprise stacks.

Gartner figures on the company wire — attribute as Gartner-via-WSO2, not as a count this desk ran: Gartner predicts the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, while only 13% of organizations think they have the right AI agent governance in place. File 150,000 and 13% as Gartner-via-company. This desk did not independently verify those figures.

Named voice on the release: Dr. Rania Khalaf, chief AI officer at WSO2. She argues speed and control should not be a tradeoff, and that when governance is separated from agent logic it can scale across frameworks instead of locking to one ecosystem. File the name and title as the company’s. Her quotes are color only and stay in Sources.

Plain English for the rest of the card: GA = generally available, out of beta. Control plane = the layer that sees and governs all agents. MCP = Model Context Protocol, how agents talk to tools. Sandbox = an isolated place to run an agent so a runaway job is contained. OpenTelemetry = a common way to record traces. RBAC = role-based access control, who is allowed to do what.

PRIMARY here: WSO2’s 15 Sep 2026 company newsroom plus the same-day GlobeNewswire company wire — dual Tier A PRIMARY company sources, the original record. The product page is product-home context, not a second originating newsroom. The Agent Manager GA, the open-source / deploy-anywhere / separate-governance pitch, the June 2026 beta, the per-agent identity / MCP-level governance / sandboxed-runtime GA adds, the federated inventory, the 40-plus guardrails, the one-click suspend, the OpenTelemetry tracing and evals, the Kubernetes-native runtime, the LangChain / CrewAI / Bedrock Strands / Microsoft Agent Framework list, the stitch-and-sprawl framing, the Gartner-via-company 150,000 / 13% lines, and the Khalaf title are company-attributed. Gartner figures stay Gartner-via-company. NOT claimed: named enterprise customers, pricing, ARR, independently verified Gartner counts, that this desk tested Agent Manager, a stock tip, or investment advice. Distinct from the already-filed salesforce-google-unify-agents, salesforce-koa-nemotron, zendesk-specialized-agents, and gensyn-open-1b-auditable.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

Sources