Platform · AI Control Plane

Runtime Governance
for AI Agents

Every autonomous action, decided at the perimeter.

Allow, redact, throttle, escalate, or block — before dispatch. Signed, sub-50ms. The AI control plane your agents dispatch through.

Built for AI agents performing autonomous actions.

Empirical proof
89%
Detection rate · 1,200 adversarial probes
1,800/s
Sustained ops · 20 concurrent workers
<1ms
Scoring latency · p99
36/36
Cross-backend matrix · Postgres, SQLite, DuckDB, MySQL
KYP
Know Your Principal · one governance surface for humans, agents, services, machines (W3C DID)
Source: KYA paper (Quadri, 2027) →
What runtime governance actually does

Observability tells you when.
Runtime governance tells you why to stop it.

Observability
Detect after the fact. Harm already done.
10:04:12agent.dispatch
10:04:13tool.invoke · db.query
10:04:14tool.invoke · file.write
10:04:15tool.invoke · email.send
⚠ Alert fired+2h 14m later

Traditional tools log actions and alert hours later. By the time someone sees it, the damage is done.

Runtime Governance
Decide before dispatch.
Gate · <50ms
Allow
Redact
Throttle
Escalate
Block

Every action evaluated at the perimeter. Allow, redact, throttle, escalate, or block. Signed to a principal, sub-50ms.

“Harm prevented. Not investigated.”

91%
Run AI agents · 2026 DBIR
10%
Can prove authorization
Allow · Redact · Throttle · Escalate · Block · Signed
How it works

Three orthogonal layers. One intersection.

Layer 01

Authentication & RBAC

Identity and roles resolved from a JWT. Veldt reads, doesn’t own.

Owns: caller identity
Layer 02 · The Action Gate

Policy conformance

Payload scored against tenant weights, data class, blast radius, cost caps.

Owns: the verdict
Layer 03

Tool RBAC

Every tool call checks roles against the tool’s required set. Tenants tighten, never loosen.

Owns: per-tool scope
The output

Five verdicts. One signed record per action.

allow

Green-lit

Passes all three layers. Signed and dispatched.

redact

Sanitized

PII, PHI, or classified content stripped.

throttle

Rate-limited

Bounded rate. Blast-radius caps enforced.

flag_for_review

Human-in-the-loop

Held for operator sign-off.

block

Refused

Policy violation or attack-chain match. Refusal signed.

Why the verdict fired

Every decision is explained.

Policy violation

Explicit rule fired

Tenant, regulator, or platform rule fired. Reason code names it.

RBAC denied

Authority exceeded

Principal lacks the grant. Blame attributes to dispatcher.

Out-of-scope tool

Undeclared tool attempt

Tool outside declared scope. Trust debited.

Cross-tenant attempt

Isolation boundary breached

Cross-tenant reach. Blocked, high severity.

Data leak

Sensitive egress

PII, PHI, or classified heading to untrusted egress. Redacted, flagged, or blocked.

Governance block

Human-gate enforced

HITL mode. Blocked pending sign-off.

In production

A four-agent loan fleet. Three regulators.

A US regional bank: NYDFS Part 500, ECOA, CFPB UDAAP. What each layer catches:

The fleet
loan_triage_agent
Orchestrator
doc_verify_sub
OCR + KYC
ofac_screening_sub
Sanctions lookup
risk_review_agent
Credit-policy reasoner
Layer 01
Underwriter opens the console
Role = underwriter. Auth + RBAC passes.
→ allow
Layer 02
risk_review_agent tries to write a decision quoting the applicant’s SSN
Data class = pii/ssn. ECOA forbids raw identifiers in decision letters. Gate strips SSN, lets it proceed.
→ redact
Layer 03
doc_verify_sub calls the OFAC screening API directly
OFAC isn’t in doc_verify_sub’s scope. Refused; loan_triage_agent’s trust debits.
→ block
Six months later
NYDFS auditor asks: “show me every decision on file #A‑4471.”
HMAC chain replays every verdict, principal, and reason code. One console.
→ signed
Inside runtime governance

What Veldt ships.

Sub-50ms verdicts
Every action allow / redact / throttle / escalate / block before dispatch. Not log-then-react.
Continuous trust scoring
Driven by identity, authority, policy, behavior, and runtime signals. Not a static allow/deny.
Invariants that only tighten
Scopes can only get stricter downstream, never looser. Mathematically guaranteed by the runtime.
Human oversight, on rails
Route high-risk actions to an approval queue with signed decisions. Every override, attributable.
Instant quarantine
Trust → 0. RBAC revoked. All future invocations denied — in one call.

Full methodology and adversarial corpus: the KYA paper.

Run this against your data.

Bring a threat model or real agent fleet. Thirty minutes: verdict + signed record on every action.

Book a demo → Get started →