AI agent governance is the runtime discipline that bounds what an autonomous AI agent is allowed to do. It rests on four primitives: agent identity, scoped capability, human-in-the-loop approval, and tamper-evident audit. Kastra enforces all four on every prompt, tool call, shell command, database write, and API request, before the action has any effect.