Skip to main content
  • Solutions
  • for Consumers
  • Stories
  • About us

  • Newsroom
  • Careers
  • Contact us
NewsroomCareersContact us

Invalid URL

Invalid URL

Invalid URL

Tuesday, September 29, 2026
Stories / Insights /

Trusted Agentic Environments: more science, safely

A researcher  sitting beside a computer monitor displaying the "Workbench - Trusted Agentic Environment interface.

Author

David Glazer, Verily Workbench CTO

Published

Tuesday, September 29, 2026

Share

Invalid URL

Invalid URL

Invalid URL

For years, Verily has built the Pre platform to help researchers turn sensitive biomedical data into discoveries, with governance embedded in how the data is accessed and used. Built on Pre, Verily Workbench automates policies that give data stewards and researchers control at scale: who can access data, how it can be used, and where geographically it can be accessed. Those controls are built in, with access and use tracked and traceable.

That foundation matters more than ever as agentic AI becomes part of biomedical research. Agents can explore growing data volumes, synthesize across modalities, write and debug analysis code, and accelerate time to insight. Bringing those capabilities to sensitive health data requires governance that operates wherever the work happens, for both researchers and the agents they use.

Workbench’s governance is embedded as code, so the same policies that govern researchers’ access to and use of data also apply when they build and use agentic AI on that data. Agents work within the researcher’s permissions, with activity visible and auditable. This builds on an architectural choice we made from the beginning: governance belongs in the platform and travels with the data.

Imagine a research environment where humans and agents work side by side as genuine collaborators: a researcher poses a question in plain language, and an agent proposes an analysis, flags a confounder, drafts the code, and surfaces a relevant paper, all while remaining fully visible and accountable to the researcher.

That future isn’t hypothetical. At Verily Health, we call this a Trusted Agentic Environment (TAE): agentic capabilities built on years of experience supporting the demands of biomedical research.

Agents work within the researcher’s permissions, with activity visible and auditable.

Agentic AI needs context, control, and choice

Three forces are driving urgency.

Context drives value. Agents are only as good as their inputs. More capable agents need access to richer data, more tools, and more specialized skills. In a world where AI task-completion horizons are at least doubling every seven months, enabling governed, controlled access to healthcare context is essential.

Guardrails support safe use. Doing more things faster means it’s possible to do more harmful things faster. Powerful agents demand sophisticated governance, in the same way that faster cars need better brakes. With unexpected agent behavior making the headlines regularly, computational guardrails designed for healthcare allow data stewards to define what agents can and can’t do.

Flexibility is essential. New models and capabilities emerge rapidly – in the last twelve months there has been a notable model release roughly every two days. Organizations need research infrastructure that keeps up with those changes, supporting a choice of models, of cloud infrastructure, and of GPU access.

Built-in governance for human-agent collaboration

Trusted Research Environments (TREs) give researchers a secure setting to analyze sensitive data under defined access and usage controls. Trusted Agentic Environments extend those safeguards to human–agent collaboration, adding context and oversight for agent-assisted work. In Workbench, the foundation is governance already embedded in the platform. The table below shows how those safeguards extend to agents.

Trusted Research Environment

Trusted Agentic Environment

Who it supports
Human researchers
Human researchers and AI agents
What policy controls
Who can access which data, what can be egressed
Agent-specific access limitations (e.g. specific queries vs. bulk reads) and rate limits; which agents are allowed
What it supplies
Data, compute, analysis methods
Agent-targeted context: tools and skills to access schemas, documentation, and environment capabilities
When humans review
When granting access and approving egress
Policy-defined triggers for in-flight oversight of significant agent actions (as defined by human accountable)
What’s audited
Researcher access to data and methods
Models used, actions taken, actions blocked

Verily Workbench: A TAE built for biomedical research

Verily Workbench is the Trusted Agentic Environment within Verily Pre, the governed health AI platform. It is purpose-built for biomedical researchers, including the thousands who use it to work with the largest integrated genomics and health database in the world, the NIH's All of Us Research Program. Workbench brings sensitive data and flexible analysis tools together in secure, collaborative Workspaces. It supports workloads ranging from large-scale genomic pipelines to AI model development and evaluation, with the flexibility to use your preferred tools and models. Governance policies travel with the data and apply across Workspaces, helping teams move faster from data to discovery while maintaining control over access and use. See the documentation for how Workspaces and policies work today.

When people donate their data to science, they trust it will be shared wisely. That is why we’re building on years of embedded governance to help researchers bring agentic capabilities to their work, safely.

Researcher flexibility with data steward control

Five capabilities help researchers and their agents work with sensitive data while keeping data stewards in control.

Governance that travels with the data. Data steward-defined policies attach directly to Data Collections and are automatically applied to all Workspaces accessing that data.

Workbench tools and expertise for agents. Our Model Context Protocol (MCP) server gives agents an industry-standard wrapper of Workbench capabilities, and our library of skills guides them on best practices.

Cross-source analysis with data steward control. Our Data Collections give each data steward control over how their data is accessed, and our Workspaces provide a single virtual environment for discovery, exploration, and analysis across multiple sources.

Your choice of models and cloud infrastructure. Researchers choose the proprietary or open-weight model they want and run it in their organization’s preferred cloud infrastructure.

Traceable actions within researcher limits. Agents work within the permissions of the researcher who runs them, and their activity is added to the logs already made available to researchers and data stewards.

From questions to reproducible insights

Consider a question that comes up regularly in drug development. A trial missed its primary endpoint, but a minority of patients showed a strong response. Can we identify and target the subgroup that benefits? Answering often means bringing internal trial data together with external clinical and genomic cohorts. Here’s how that unfolds in the agentic era.

The researcher creates a “clean room” and requests access to both sources. Each data steward’s policies apply automatically: which methods the agent can use, which individual and aggregate data it can reach, what can leave. The researcher activates their preferred agent and asks the question in plain language; the agent proposes a stratification, writes the code, and runs it.

An association appears. The agent flags that it may not be real — the responders are concentrated in one ancestry group, so the signal could reflect population structure rather than the variant. It proposes an adjustment and documents the rationale. The researcher approves and runs the revised approach. The signal holds in one subgroup and disappears in another.

The researcher asks the agent to prepare a downloadable summary with the supporting evidence. The agent does so, flags that data steward policies require explicit approval because of re-identification risk, and drafts an egress justification for the researcher to review. The researcher reviews, the agent submits, the data steward approves, the results are downloaded.

The final work product contains a reproducible summary of inputs, methods, and results. All activity is audited, blocked actions are flagged, and no protected data leaves the environment.

A diagram titled "Audit trail throughout" showing how data stewards, researchers, and AI agents interface with a central governed data and AI control plane to deliver approved results.

Agent work under researcher oversight

Agents make mistakes, sometimes on their own and sometimes because their input pushed them. Agent-written code can run cleanly while doing the wrong thing, and documents can contain text crafted to redirect agents. The job of a TAE is to help prevent, detect, and contain these risks while supporting researchers’ scientific review.

Our starting principles are that an agent is limited by the permissions of the researcher who runs it, and uses the same primitives that the researcher uses. The agent has no credentials of its own, no private path to the data, and no API surface the researcher doesn’t already have. When it builds a cohort, it produces a cohort definition in the same form the graphical cohort builder produces. When it runs an analysis, it leaves a notebook. Its work is visible, reviewable, and editable because it’s made of the same parts as human work.

These principles protect against the risk of working with agents: they can’t reach data the researcher couldn’t, and they can’t move results out without normal approvals. They also support reproducibility – the agent is stochastic; its recorded code and execution context provide a basis for reproducibility. Agents should borrow a researcher’s authority rather than holding their own, and should work in the open where their work can be checked.

We continue to build on these safeguards as agent capabilities evolve. We are exploring automated support to help reviewers identify potential re-identification risks during egress review, and developing more granular policies to limit agents to specific queries rather than bulk reads. These efforts build on the permissions, oversight, and approval processes already embedded in Workbench.

Faster insights, broader discovery

Trusted Agentic Environments will accelerate science in several ways.

The immediate benefit is improved individual researcher productivity. In the same way that agent-assisted coding has transformed software development, the governance controls and automatic context provided by TAEs allow agent-assisted analysis to transform scientific inquiry. As foundation models continue to improve, researchers will spend less time on the mundane tasks of understanding data formats, figuring out the syntax of method libraries, parsing logs, and troubleshooting infrastructure errors – and more time focused on science.

The intermediate benefit is faster time to research insights. Governed access brings high-value datasets into AI-assisted research, without asking data stewards to lower their guard. As more confidence is gained in the TAE governance controls, more data can be shared widely. Interfaces that provide context to agents simplify cross-source analysis within a single virtual environment, helping researchers move more quickly from questions to evidence-based insights.

The long-term benefit is even more significant, enabling pursuit of novel research directions at scale. Strong governance will allow researchers to work with teams of proactive agentic collaborators, not just accelerating what they already planned to do, but prompting them to ask and answer new questions. A persistent, multi-agent system can monitor internal data and external literature on an ongoing basis, surfacing novel hypotheses and automatically generating validation workflows for each one. Adding a grad student to your team lets you code faster; adding a post-doc lets you research faster; adding a team of scientific collaborators changes the game.

Adding a grad student to your team lets you code faster; adding a post-doc lets you research faster; adding a team of scientific collaborators changes the game.

Shaping the future of governed AI research

We have been working for years to help data stewards safely share some of the world’s most valuable and most sensitive biomedical data, and to help researchers turn data into discoveries. The same policies embedded as code now govern how researchers and their agents use data in Workbench, helping teams move faster from data to insight while preserving control.

No single company is going to define this future. Datasets will continue to be generated and managed by many different data stewards, each responsible to the people who donate the data. The norms for putting agents to work, with the proper context and guardrails, are still being written. They’ll be better norms if the people on the front lines help shape them.

So if you’re working to make your data more widely and wisely used, or deciding now how to help your researchers collaborate with the more capable agents of the future, we’d like to hear from you. Science awaits.

1METR.org, “Time Horizon 1.1” (January 29, 2026), https://metr.org/blog/2026-1-29-time-horizon-1-1/

2BenchLM.ai, "LLM Statistics" (September 18, 2026), https://benchlm.ai/stats/model-releases

3NIH.gov, “NIH's All of Us Research Program is now the largest integrated genomics and health database in the world” (June 30, 2026), https://www.nih.gov/news-events/news-releases/nihs-all-us-research-program-now-largest-integrated-genomics-health-database-world


More from Verily

 The Verily Pre logo — an AI-native platform for precision health.
Verily Pre Platform
Clinical researcher at a study site, using a clinical trial management system.
Verily Viewpoint
A woman having a CGM device applied to her arm as part of her Verily care program.
Verily Lightpath

Stay in the know. Subscribe to receive communications from Verily.

This email sign up is available for business email addresses for US users only.
  • Verily
  • Stories
  • About us
  • Resources
  • Contact
  • Publications
  • Newsroom
  • Press kit
  • Support
  • Security and Trust
  • Connect
  • X
  • LinkedIn
  • YouTube

  • © Verily Health | 2026
  • Accessibility
  • Code of Conduct
  • Verily Ethics Hotline
  • Privacy policy
  • Terms of use
  • Responsible supply chain
  • Your Privacy Choices
  • Consumer Health Data Privacy Policy

protected by reCAPTCHA