Skip to main content
Home/Case Studies/AI Runtime Governance
Platform Initiative · AI Governance

Governing enterprise AI before it governs itself.

A platform we are actively building — a runtime governance layer that understands enterprise AI as a graph of users, agents, models, tools and data, and controls what each can actually reach. This is our forward view and current R&D focus, not a completed client engagement.

Platform initiative — in active development. Design partners welcome.
At a glance
AI apps & agents proliferate
Reach outpaces control
AI runtime governance
Controlled, audited AI

A single control layer for security, policy, risk, observability and compliance — across every model and agent.

The Opportunity

AI is being deployed faster than it can be governed.

Every department is shipping copilots and agents. Each one authenticates differently, logs differently, and reaches into real systems — CRM, ERP, payments, HR. Security and compliance teams are asked to sign off on an estate they can't see, using tools that only inspect the text of a prompt.

Signal 01

Agent sprawl

Autonomous agents now call tools and APIs on their own. User-level RBAC never anticipated a non-human identity that acts across systems.

Signal 02

Invisible reach

A prompt looks harmless in isolation. What matters is what it can reach — payroll, PII, an external model — and today that's rarely mapped.

Signal 03

Audit gap

When something goes wrong, teams can't reconstruct who asked what, through which agent, to which system. There's no graph to query.

The Problem, Visualized

A prompt is never really "just a prompt."

Borrowing attack-path analysis from cybersecurity: follow a single request past the model and you see what it can actually touch. The question governance must answer isn't "is this text allowed?" — it's "what is the blast radius?"

Blast radius: this request can reach customer PII and push it to an external service. A keyword filter waves it through — a graph that knows the path stops it, or routes it to human approval. Illustrative path.

Our Approach

Model the whole AI operation as one graph.

Users, sessions, agents, policies, models, tools, APIs and data assets become nodes; every request is a path through them. Governance decisions are then made on reach and permission — not the words in a prompt.

Every request passes through policy & model User, agent, tool or data asset Edges = who / what can reach what
Capability · Agent RBAC/ABAC

Permissions for agents, not just people.

An autonomous agent is a new kind of identity — it acts on its own. It needs fine-grained, per-action permissions, scoped to exactly what its job requires and nothing more. The graph makes those permissions enforceable, because it knows what each action would actually reach.

Illustrative policy for a single agent.

AgentExpense Assistant
Read invoices
Create draft reimbursements
Approve payments
Delete invoices
Access HR records
Capability · Risk Intelligence

One score hides the risk. We break it apart.

A single "risk: high" tells an executive nothing actionable. We score each dimension separately, with a plain-language reason — so the team knows why a system is risky and what to do about it.

Illustrative — one AI application

Illustrative risk exposure by dimension (higher = more exposure).

Where This Is Going

How we're building it — with design partners.

This is an active initiative. We'd rather build it in the open with a handful of enterprises than behind closed doors.

Phase 1 · Now

Inventory & graph

Discover the AI estate — apps, agents, models, tools, data — and build the relationship graph. Read-only, in your environment.

Phase 2

Observe & score

Route AI traffic through the runtime to observe real paths, then produce risk intelligence and trust scores grounded in what actually happens.

Phase 3

Govern & enforce

Turn on the policy engine and agent permissions — governance-as-code, with human-approval routing on high-risk paths.

Built on public techniques

Approach & building blocks

Combined in a way that's designed and implemented independently. See the full platform overview →

Knowledge graph Attack-path analysis RBAC / ABAC Policy engine Risk scoring Observability Governance-as-code

Want to shape this as a design partner?

We're looking for enterprises deploying AI at scale to build and validate this with. Let's talk about your governance gaps.

Become a design partner