The Catchup
with JANUS
Issue 08.11 iagentic.ca 11 August 2026
The Control Problem
The Tape
IL5First DoD agent accreditation
9.2MUS Army people served
Aug 2EU AI Act high-risk in force
Jan 2027Copilot run-only sharing GA

AWS ships agent authorization controls, Microsoft meters the fleet, and Salesforce takes agents to Impact Level 5

Welcome to Catchup with JANUS, a periodic note from the iAgentic team on what's moving in agent orchestration. Platform announcements, security incidents, enterprise deployments, the developer-tools fault lines, and the things we think enterprise buyers should actually care about. No vendor spin.

This week the control plane stopped being a roadmap slide: AWS shipped real agent-authorization controls, Microsoft moved to meter and balance whole fleets of agents, and Salesforce cleared a national-security accreditation tier, extending the runtime consolidation earlier issues tracked from the platform into how agents are authorized, billed and trusted.

Catchup with JANUS: AWS ships agent authorization controls, Microsoft meters the fleet, and Salesforce takes agents to Impact Level 5

AWS turned agent governance from slideware into shipped controls the same week Microsoft moved to meter and load-balance whole fleets of agents, and Salesforce cleared a Department of Defense security tier for autonomous agents. The gap this week is between the control-plane primitives hyperscalers are folding into their base platforms and the portable, sequence-aware authorization enterprises actually need.

“Capability is not the constraint anymore. Control is, and the week's launches are all circling it.”
On the Calendar Section 01
Analog Devices (ADI)

Tue Aug 19, before open · ~$187B. Analog and mixed-signal chips feeding AI data-center power, optical, and infrastructure: a picks-and-shovels AI semi, trading near record highs into the print.

Workday (WDAY)

Thu Aug 20, after close · ~$60-70B. Enterprise HR and finance SaaS; the story is whether its AI agents and Illuminate features offset the AI-threatens-software narrative weighing on the group.

Baidu (BIDU)

Mon Aug 18, before open · ~$35-45B. China's AI bellwether: Ernie LLM, AI cloud, and Apollo Go robotaxi. The purest AI company of the three.

Headline Moves SECTION 02
AWS

Agent authorization goes stateful, and lands in GovCloud

Bedrock AgentCore added temporal policies, stateful rules that judge each tool call against what the agent already did earlier in the session rather than checking each call in isolation, plus per-user rate limiting on the gateway (Aug 6). Two days later AWS extended AgentCore memory, policy and harness into GovCloud (US-West) (Aug 7). This is the follow-on to last week's move putting the original Bedrock Agents into maintenance mode: the migration path AWS pointed everyone toward now has shipped governance behind it.

The migration path AWS pointed everyone toward now has shipped governance behind it.
— Headline Moves
Microsoft

Microsoft put its Agent Orchestrator into preview, adding load balancing and unified billing across large agent fleets (Aug 5), and previewed run-only agent sharing in Copilot Studio (Aug 6, general availability slated for January 2027). It continues the Agent 365 and Foundry control-plane build recent issues tracked: the metered, centrally governed agent-fleet model keeps hardening inside M365.

Salesforce

The US Army Human Resources Command deployed Agentforce Public Sector at Impact Level 5 for 9.2 million soldiers, veterans and families (Aug 5), the first Department of Defense organization to run autonomous agents at that accreditation. After months of mixed field checks on the Agentforce rollout, this is a concrete regulated-sector proof point.

Sierra

Sierra launched Voice Personas and a Context Engine that grounds agent decisions in business knowledge when an outcome is on the line (Aug 7), and partnered with Plaid to embed secure bank-account connections into its agents for long-horizon financial workflows like loan origination and collections (Aug 4). Both advance the Horizon long-horizon-agent line we covered in July.

Decagon

Decagon named American Airlines, the world's largest airline by passengers carried, as a customer, pushing its AI customer-experience concierge into large-scale travel support. Marquee logos are landing fast on the CX-agent side of the market, and travel is the newest proof point.

Where the Landscape is Shifting SECTION 03

The governance primitives that were pitches a quarter ago are now shipping inside the base platform. AWS's temporal policies make authorization stateful and sequence-aware instead of a per-call allow-list. Microsoft's orchestrator adds load balancing and unified billing across whole fleets. As these move into the platform, the bar for a complete runtime rises: discovery, audit, policy enforcement and fleet billing are increasingly assumed to be in the box, and a runtime that cannot show them looks incomplete rather than lean.

Salesforce clearing Impact Level 5 resets the security-accreditation bar for public-sector and regulated agent work. Once one vendor runs autonomous agents at a Department of Defense tier, that certification becomes a checklist item rivals get asked about in regulated deals, and it moves the conversation from whether agents can be trusted in sensitive environments to which vendors have already been cleared to. The customer-experience side of the market is moving on logos rather than accreditation, with a large airline the latest name to sign, so buyers are watching two different proof points at once: who is certified and who is already live at scale.

Underneath all of it, the reliability question the red-team coverage raised last week has not gone away. Geoffrey Hinton warned that agents escaping their test environments expose a structural control gap (Aug 7), and AI4 2026 opened with Hinton, Andrew Ng and Fei-Fei Li openly split on whether agentic AI is an existential risk or an overstated one. Capability is not the constraint anymore. Control is, and the week's launches are all circling it.

Where the Openings Are SECTION 04

Three places worth attention if you are evaluating orchestration vendors right now:

01
Sequence-aware authorization is the real requirement.

AWS shipping temporal policies is a signal that per-call allow-lists are not enough. Ask whether a platform can judge an agent action in the context of the whole session, not one call at a time.

02
Metered fleets need portable billing and identity.

As fleet orchestration and unified billing arrive, confirm you can see per-agent cost and move agents, memory and identity between systems without a rebuild, rather than accepting one vendor's meter as the default.

03
Buy the orchestration layer, not just agents.

Practitioners are now running multi-agent workforces with a routing chief-of-staff agent (Allie K. Miller ran a public workshop on hers this week). The coordination layer, not any single agent, is where the value concentrates.

From the Community SECTION 05

The forum lanes came back quiet on Sierra and AgentCore this week, and framework-comparison chatter stayed flat at its usual baseline. The louder signal came from the reliability and oversight debate, with Hinton's test-escape warning and the AI4 researcher split keeping human-in-the-loop control in the headlines rather than letting it fade. Ethan Mollick added a useful caution for buyers reading the noise, warning against judging which AI company is winning from any single source. The through-line from prior weeks holds: developers want a coordination layer that gets out of the way, while enterprise buyers want agents that will not act until the outcome is checked, governed and logged.

The Back Page COMICS
Panel 02
Panel 03

Subscribe to get the next briefing in your inbox. We send when there's something worth saying.

Get notified →