Pipeline request
Your GitHub Actions or GitLab step asks for production authority.
Governance for agentic pipelines
When agentic workflows change Terraform or CDK through GitHub Actions and GitLab, Control9 applies policy, approvals, and an audit trail so speed does not mean flying blind.
Platform leads start a Control9 team with a work email or Google (Google Workspace). Teammates your admin invites can sign in with any email address on that invite, including personal addresses when that is the invited email. GitHub is for installing the Control9 Action in CI, not for signing into the admin app.
Your GitHub Actions or GitLab step asks for production authority.
Control9 classifies what the Terraform or CDK change actually does.
Policy allows, observes, or requires approval before deploy continues.
Approvals, deploy proof, and off-path signals stay on one timeline.
An agent or developer expands an IAM role in Terraform. The pipeline sends Control9 the plan summary and fingerprint before apply can use production authority.
Agentic pipelines keep moving. High-impact changes still get policy and approval.
Approvals and deploy outcomes live outside ephemeral CI logs.
Keep GitHub Actions, GitLab, Terraform, and CDK where they already run.
Agentic pipelines, governed delivery
Control9 is not an AI agent and does not write your Terraform or CDK. It sits on the pipelines those agents already use so every high-impact change gets policy, approval when required, and tracking you can show later.
Let agents ship faster with governance and tracking still on.
Approve the plan that actually reaches production apply.
Review template risk without moving deploy off your pipeline.
Confirm the approved artifact is the one that deployed.
Keep who approved what after job logs are gone.
See production mutations that skipped the governed path.
Start with a two to four week shadow-mode assessment. Production deploys continue while you review ranked findings before enabling enforce mode.