Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Platform · Controls

You cannot control what nobody wrote down.

Most organizations find out during an audit that nobody has a current list of the AI they are running. Here the list writes itself while policy is enforced: an agent enters the register on its first call.

Rules only, so changing one needs no release.

What is on the record for each agent

What it isname, owner, business purpose
What it sits in front ofthe model, the provider, the endpoint
What it may calltools, endpoints, and the limits on each
What governs itthe ruleset and the version in force
What it has doneevery decision, with the rule that produced it

Nobody types an agent into it. The first time an agent calls, its row is written in the same transaction that records the call. The row is written even when policy refuses that call: refusing an agent is not a reason to leave it out of the inventory. You declare an owner and a risk level on top of a row the traffic already created, so the register cannot go out of date the way a spreadsheet does.

Documentation you write against

The declarations, the rule versions and the decision history are the raw material for a technical file: what the system does, what controls sit on it, what it decided and on which version. Export it and write.

We do not decide your system's risk tier. That is a legal decision about how you use the system, made by you, usually with your lawyers. Any vendor offering to make it for you is selling something they cannot deliver. See our read of the EU AI Act for where that line sits.

Related: AI governance · what an agent may call
Book a demo