Agent & MCP Governance

Autonomous agents, on a leash you define.

Discover every agent and MCP server, detect drift from the approved baseline, and enforce blast radius inline.

Concentric mint containment rings around a central agent node, with one outbound path blocked in red
How it works

From prompt to verdict in four stages.

  1. 01

    DISCOVER

    Agents and MCP servers are identified automatically from proxied traffic and tool-call patterns.

  2. 02

    BASELINE

    Approve behaviour, allowed tools, egress domains and resource ceilings for each agent.

  3. 03

    ENFORCE

    Every tool call is checked against the blast-radius policy at the proxy before it reaches the system.

  4. 04

    CONTAIN

    Violators are blocked and quarantined. The event, reasoning and hash are written to the audit chain.

Capabilities

What it does.

AG-01

Automatic agent discovery

Find agents by observing traffic, SDK calls and MCP handshakes — no manual registration required.

AG-02

Agent inventory

A central registry of every agent with owner, purpose, status, baseline and last-seen activity.

AG-03

Drift detection

Get notified when an agent's behaviour, tool use or scope changes from the approved baseline.

AG-04

Blast-radius policy

Define allowed tools, allowed egress domains, hourly request ceilings and daily spend ceilings per agent.

AG-05

Inline enforcement

Policy violations force a block decision at the proxy before the tool call is executed.

AG-06

Automatic quarantine

Agents that breach policy are quarantined instantly and can be reactivated only after review.

AG-07

Agent governance checklist

Built-in checks for sandboxing, tool-access controls, output review and least-privilege design.

AG-08

MCP server registry

Catalog MCP servers, exposed tools, scope and risk rating. Approve or block, and detect when new tools appear.

AG-09

GenAI tool inventory

Track every GenAI tool in use with an approval workflow before it is reachable by users or agents.

In practice

One agent, one blast radius.

policy · verdictlive

policy > "Agent 'billing-reconciler' may only call tools in the finance suite, reach *.internal APIs, and spend under $50 per hour"

agent: "billing-reconciler"

requested_tool: "web_search.public"

requested_domain: "api.public-search.example"

violation: "domain outside allowed egress list"

verdict: "BLOCK_AND_QUARANTINE"

hourly_spend: $12.40 / $50.00

action: "quarantine_agent"

audit_hash: "ed25519:7d1a…e03b" — appended to tamper-evident chain

Framework mapping
OWASP LLM06 Excessive AgencyOWASP LLM08 Vector & Embedding WeaknessesISO/IEC 42001NIST AI RMF GOVERN

Controls align with the agency and governance clauses your frameworks already expect.

Blast radius

Three rings. One hard boundary.

An agent can operate freely inside its approved rings. Any request that crosses the outer boundary is blocked before it executes.

01Allowed tools
02Allowed domains
03Rate & spend ceilings
Blocked attemptbounces at boundary
Next step

See it run against your own prompts.