
For years, platform teams built internal platforms for one kind of user: a developer at a keyboard. Now a second kind of user has arrived. AI agents open pull requests, run tests, provision environments, and call internal APIs, often faster and more often than any person.
Platform engineering for AI agents is the practice of giving AI agents governed, self-service ways to act on your software systems. Agents get the same foundations developers rely on, adapted for users that act quickly and lack human judgment:
The case for doing this is strong. Google Cloud's 2025 DORA report found that when platform quality is high, AI adoption has a strong, positive effect on organizational performance. When platform quality is low, the effect is negligible.
The case for doing this is strong. Google Cloud's 2025 DORA report found that when platform quality is high, AI adoption has a strong, positive effect on organizational performance. When platform quality is low, the effect is negligible.
The phrase is used in two ways, and both matter:
This guide focuses on the first meaning, because it is where most organizations meet agents today. For the second, see the comparison of platforms for running AI agents.
It also helps to be clear about what platform engineering for agents is not. It is not MLOps, which covers training and serving machine learning models. It is not an agent framework either. A framework such as LangGraph defines how an agent reasons, while the platform decides where it runs and what it may touch.
Three trends meet here: platforms are now common, AI amplifies whatever system it lands in, and many agent projects fail on controls rather than capability.
Platforms are now the norm. According to DORA's platform engineering research, 90% of organizations use an internal developer platform, and 76% have a dedicated platform team. The 2025 report, based on a survey of nearly 5,000 technology professionals, describes AI as an amplifier. It makes strong systems stronger and weak systems more visibly weak.
Agent projects fail on controls. Gartner predicts that over 40% of agentic AI projects will be canceled by the end of 2027. It names three causes: rising costs, unclear business value, and inadequate risk controls. Cost visibility and risk controls are both problems a platform can solve.
Agents are spreading without a common model. Teams adopt agents one tool at a time. A coding agent in one repository, a review bot in another, and an operations agent on a third provider each bring their own pipeline, runbook, and audit process. Without a shared platform, every security review means gathering evidence from separate consoles by hand.
How is an AI agent different from a human developer as a platform user?
An AI agent uses the platform like a developer, but with different strengths and weaknesses. The differences explain why the platform itself has to change.
| Human developer | AI Agents | |
| Identity | A named person with an account | Often a shared token, unless the platform issues one per run |
| Speed | A few changes a day | Many changes an hour, in parallel |
| Judgement | Notices when something is wrong | Follows instructions, including bad or injected ones |
| Context | Knows the team’s conventions | Knows only what is given |
| Typical failure | An honest mistake, usually caught in review | The same mistake repeated at speed |
| Accountability | Owns the change | Cannot own the change; a person must |
The pattern is clear. An agent brings speed but not judgment, so the platform has to supply the judgment. It does that through controls that run on every action, rather than trusting each run to behave.
A platform for AI agents needs seven capabilities. Each one answers a question a security reviewer or engineering lead will eventually ask.
Capability | The question it answers | What good looks like |
| Identity | Who acted? | Each agent run has its own verifiable identity, with access scoped to one task |
| Golden paths and context | Did the agent act the approved way? | Agents use documented workflows, skills, and tools instead of improvising |
| Sandboxed execution | Where did the agent work? | Each run works in an isolated, disposable environment with network access restricted by default |
| Human gates | Who approved it? | A person approves actions that are hard to undo, such as merging, deploying, or changing data |
| Test environments | Does the change work? | Agent changes are tested in an environment that matches production before release |
| Audit trail | What happened? | Each run records its trigger, plan, approver, and outcome, and the record cannot be changed |
| Cost attribution | What did it cost? | The cost of each run is tied to a team, workflow, or feature |
Golden paths deserve extra attention, because agents follow instructions literally. A developer can ask a colleague how deployments work. An agent only knows what the platform hands it. That is why platform teams now publish agent-readable context: repository instructions, reusable skills, and MCP servers that expose approved actions. Microsoft's platform engineering team describes the same shift, from modules to instructions, skills, and policy.
A governed agent change follows one path, and each step applies one of the controls above.
Read it from the trigger at the top left. The work runs under a scoped identity, follows the golden path, and happens in a sandbox. The result is tested in an environment that matches production. A person then approves or rejects it. Rejected work returns to the agent, and every step is recorded in the audit trail.
You do not need a new platform to start. Most teams can extend the one they have in six steps:
Start with gates everywhere. As trust builds, remove them at your own discretion, one action at a time.
Upsun offers two products that cover different parts of this model. Each works on its own, and they work well together.
Upsun offers two products that cover different parts of this model. Each works on its own, and they work well together.
Upsun Dispatch governs how AI agents change your code. It provides:
Upsun Cloud provides the golden path for running and testing applications. Infrastructure is defined as code in YAML configuration stored with the application in Git. Every Git branch can get a preview environment that clones production apps, services, and data. Coding agents can work with Upsun Cloud through its MCP server and skill.
Together, they close the loop. An agent's pull request can be tested in an environment that matches production before a person approves the merge.
What is agentic platform engineering?
Agentic platform engineering is another name for platform engineering that treats AI agents as users of the internal platform. It gives agents identities, golden paths, sandboxes, human gates, and audit trails, alongside the tools developers already use.
Is platform engineering for AI agents the same as MLOps?
No. MLOps covers training, deploying, and monitoring machine learning models. Platform engineering for AI agents covers how agents safely act on software systems, such as code, environments, and deployments.
Do AI agents need their own identity?
Yes. A separate identity for each agent run limits what the agent can access and shows exactly which run made each change. Shared tokens make both impossible.
Should AI agents deploy to production?
Most teams start with a person approving every deployment an agent proposes. Teams can remove that gate for low-risk changes once the agent has a reliable track record.
How do you audit what an AI agent did?
Record each run's trigger, context, plan, approver, outcome, and cost in a log that cannot be changed. Tie each record to the run's identity, so reviewers can trace any change back to its source
What role do MCP servers play in platform engineering?
MCP servers let AI agents discover and use a platform's approved actions through a standard interface. They make the golden path readable by agents, not just by people.