Why should IT approval be a hard gate before an AI agent goes live?

Because the team that builds an agent and the team that owns the systems it will write to are usually different, and a gate is the only handoff that lets the first move fast without the second inheriting the risk: nothing runs in production until IT has connected the systems, bound the fields and approved the agent.

What the gate checks

Before an agent can even be submitted it must pass its evaluation cases and have its required systems identified. IT then sees exactly what it will do: which operations on which systems, which fields it reads and writes, which rules it is bound by, and the evidence from evals and shadow runs. IT connects the credentials (the business user never handles them), binds the data contract, and approves. Approval locks the version; a change to the agent means a new version and a new approval.

Compliance tags and approval policies sit on top. A capability IT marks as risky is auto-gated for every agent that uses it, and the audit trail shows who approved what, when, and what changed since.

Why business-led and IT-governed is not a contradiction

The people who know the work are not the people who administer Salesforce. Platforms that require IT to build the agent get few agents; platforms that let the business deploy without IT get incidents. Separating "describe, build and prove" from "connect, approve and govern" gives each side the part it is qualified for, and the gate between them is the contract.

The terms, as the product defines them

IT approval / Governance

The control layer: who can approve what a domain agent does.

Compliance tags (e.g. SOX, GDPR), approval policies, and an audit trail. IT/security review and approve domain agents before production, set policies that auto-gate risky capabilities, and can see exactly what changed and why.

Promote

Move a verified domain agent to production so it can run.

Promotion makes a domain agent version the live, production one. It requires passing evals + shadow and a governance/IT approval. Promotion is append-only and reversible — you can always roll back to a previous version.

Deployment

A live, running instance of a promoted domain agent.

A promoted domain agent deployed to a runtime (Tacit-hosted by default, or your own cloud). It exposes an endpoint that can be invoked by the UI, an API call, or a webhook.

Questions people ask about this

How do I see what I’ve submitted that’s waiting on IT?
On My agents, the amber “Waiting on IT” section lists every agent with an open approval request and how long it’s been waiting; “View IT queue” jumps to the full queue. Agents that are live show under “Working live” (green), and ones still being set up under “In progress”. Every row also shows the process it belongs to as a blue tag you can click to open. On an agent’s own Overview, once you’ve sent it to IT the tracker shows “Sent to IT — waiting for approval” — it no longer prompts you to submit what’s already submitted.
I submitted domain agents for IT review but they don’t show on the IT approvals page — why?
IT only ever sees validated domain agents, so submission is gated on two things: each domain agent must (1) have its required tools connected and (2) pass an eval run (≥80%). A fresh domain agent with no eval runs is blocked at submit and stays in Draft — nothing reaches the approvals queue. The shadow TRIAL is NOT a submit gate (it can’t be — real agreement is earned only after go-live, from actual human decisions), so a running-or-skipped trial never blocks submission. Open each domain agent, connect any required tools and run its evals, then submit. The submit result lists exactly which domain agents are blocked and what’s missing.
In what order do I do this — build, evals, submit, connect, go live, autonomy?
The business builds and validates; IT connects and approves — a clean handoff. The order: (1) BUSINESS builds the agents and runs evals (≥80% pass) — that’s all it takes to submit; you do NOT need tools connected first. (2) BUSINESS clicks “Submit the whole process for IT review”. (3) IT picks it up: connects the required tools and binds the API fields in Integrations. (4) IT approves — approval is the go-live gate, so it can’t approve until the tools are connected, and nothing ever runs unconnected. (5) It deploys live in domain agent mode. Then the domain agent trial / agreement begins: it works alongside a human who approves each draft in the queue, and earns the right to act UNATTENDED once it agrees with real human decisions ≥90% over ≥10 real cases. IMPORTANT: the “domain agent trial” agreement is NOT a pre-launch step — the platform never fakes “what a human decided,” so the score stays empty until it’s live and people review its drafts. Two separate gates: Evals + IT approval (with tools connected) make it LIVE (human-in-the-loop); agreement with real decisions earns AUTONOMY (unattended).
Where do I submit an agent for IT approval?
Two equivalent places. (1) On a single agent’s Overview: once its two gates are green — required tools connected + checks passed — a “Send to IT to approve” button appears. (2) On the PROCESS page (business or IT view): a “Submit N for IT review” button submits every ready agent in that process at once and shows a per-agent result (submitted / already in queue / needs validation first). Either way, only an owner or editor can submit, and IT gives the final OK before anything goes live. If an agent isn’t ready (e.g. connections still missing), it won’t be included — open it to finish setup first.
Do I have to test my agent or run checks before it can go live?
No — Tacit runs the checks for you, automatically. As soon as you finish describing it (or change it), we quietly run the quality checks and a safe trial in the background. The agent’s Overview shows a simple tracker — Built → Checking it works → Approved by IT → Live. When the checks pass and any needed platforms are connected, the agent points you to “Submit the whole process for review” — agents go to IT together as one process, not one at a time. Your IT team gives the final OK before anything goes live — you never have to run evals or trials by hand.

More in the FAQ and the glossary.

Related

See it on one of your own processes. Free for the whole product for a trial period, no card needed to start, every write held for your approval.