// governance checklist
Enterprise agent governance belongs in the execution path.
A policy document cannot explain a route after the fact or stop a model-driven action before it happens. Practical governance connects identity, tools, data, approvals, and evidence to the actual request path.
Product-fit boundaryPunk can apply policy to supported model requests and declared, instrumented tool actions. It supports evidence-aware routing and selected approval flows, but it is not a compliance certification or a substitute for your organization’s legal, security, and access-control program.