One control plane for every enterprise AI agent
Centralised control over AI agents regardless of which model, framework, language or runtime they use. Registry, identity, authentication and authorization, policy enforcement, MCP and A2A gateways, human approvals, audit, observability, FinOps and lifecycle management.
It is not an agent framework, not a model, and not an agent runtime. It governs the runtimes you already have, including every agent in GCC-in-a-Box and any agent your teams build themselves.
What happens when an agent calls a tool
Every tool call and every agent-to-agent message goes through the same gateway, in the same order. Click a step, or watch it play.
Everything an agent estate needs to be governed
Agent registry and lifecycle
Each agent has one accountable human owner, immutable version snapshots, a risk level and an environment. An enforced lifecycle (draft → registered → testing → approved → deployed → active, with suspend and retire) has no shortcuts: every path to production goes through approval, and the specification freezes once approved.
Agent identity
Exactly one machine identity per agent. Agents authenticate with OAuth 2.0 client credentials and a signed assertion (RFC 7523, Ed25519) and receive a ten-minute token. Credentials must expire, and for key-based credentials only the public key is stored: a database leak is not an impersonation event.
Policy on OPA
Policies in Rego, evaluated by Open Policy Agent. Every protected action resolves to ALLOW, DENY or REQUIRE_APPROVAL. Versions are immutable, bindings target an organisation, agent, environment or risk level, deny always overrides, and an unreachable engine fails closed. Every decision is recorded with its exact input.
MCP gateway
Built on the official Model Context Protocol SDK. An agent's tool list shows only what it is bound to; an unbound tool is indistinguishable from one that does not exist. Refusals return as structured tool results, so the agent can reason about them rather than crash.
A2A gateway
A2A v1.0 through the official SDK. Each agent gets its own URL and agent card; peer bindings are explicit and one-directional, and every message must name the skill it wants. A denied message looks exactly like a target that does not exist.
Human approvals
Asynchronous and durable, so they survive restarts. Bound to a SHA-256 fingerprint of tool, permissions and arguments; single-use; expiring; and the agent's owner cannot approve. Rego decides whether a human must look, an approval policy decides who.
Audit
Append-only and hash-chained in PostgreSQL. The application role can only read and insert, events are relayed through a transactional outbox, and the chain can be verified through the API. There is no write route over HTTP.
Observability
OpenTelemetry spans for agent execution, tool invocation, policy evaluation and approvals, with W3C Trace Context. Events are labelled observed or reported, so it is always clear which lines are evidence and which are an agent's own claims.
FinOps
A spend ledger priced from a versioned, provider-independent rate card. Costs are labelled as estimates; an unpriced model shows as unknown, never zero. Budgets per organisation, agent or department return ALLOW, WARN or DENY, with a monitor mode to watch before enforcing.
Tool registry and connector
Tools have owners, risk levels, versioned schemas and declared permissions. The gateway makes every outbound call: exact-hostname egress allow-lists, private addresses refused, redirects refused, secrets resolved from Vault at call time and never handed to the agent.
Shared memory and decision ledger
Organisational knowledge owned by the control plane so it can be shared across providers. Nothing is overwritten: corrections supersede, contradictions are kept, every memory records its provenance, and audit never contains memory content.
Context engine and console
A ranked, budgeted package of what an agent should be told, deterministic and never containing anything the agent could not fetch itself. An operator console where every figure is a real count and a figure you cannot see shows "—", never zero.
Policy decision simulator
Change the inputs and watch the decision change. The rules mirror the example policies that ship with the control plane: a read-only baseline, production guardrails, high-value purchases and data residency, plus the budget gate.
This is an illustration running in your browser. In the product, the same inputs go to OPA, and the decision and its input are written to the decision record.
package acp.high_value_purchases
default decision := "ALLOW"
decision := "DENY" {
input.action == "purchase"
input.amount >= 50000
}
decision := "REQUIRE_APPROVAL" {
input.action == "purchase"
input.amount >= 5000
input.amount < 50000
}
Claims you can check, not assurances you have to trust
The threat model lists fifteen threats, each with the test that covers it. A threat model that lists only solved problems is marketing, so the residual risks are published too.
- ✓Agents never hold permanent API keysCredentials must expire; tokens last minutes; only public keys are stored for key-based credentials.
- ✓Revocation is immediateIdentity and agent status are re-checked on every request.
- ✓Tenants are isolated twiceApplication scoping plus PostgreSQL row-level security, enabled and forced. Cross-tenant lookups return not-found.
- ✓The audit trail is tamper-evidentAppend-only, hash-chained, verifiable by anyone; update and delete are revoked at the database level.
- ✓Fails closedAn unavailable policy engine never becomes an implicit allow.
- ✓No implicit accessTools, peer agents and memory each need an explicit binding or grant.
- ✓One approval, one callEach approval authorises one exact invocation, once, and cannot be reused or altered.
- ✓Secrets stay in the gatewayUpstream credentials live in Vault and never reach the agent.
- ✓Attempt-limited authenticationEvery authentication endpoint is limited per address and per identifier, with identical failure responses.
Open standards at every seam
No proprietary protocol, and no policy language of our own. Where a standard exists, the official implementation owns the protocol.
Protocols and specifications
Identity and runtimes
Any OIDC identity provider for people (Keycloak is tested end to end). Two runtime adapters ship today, one in-process for Claude and one for an external runtime that receives only a gateway address and a short-lived credential. The adapter interface names no provider.
Roadmap LangChain and CrewAI adapters · TypeScript and Python enforcement SDKs · SCIM group mapping
Deployment
Helm chart with API, console, optional separate gateway, OPA and an OpenTelemetry collector. Autoscaling, disruption budgets, default-deny network policy, TLS via cert-manager, secrets from Vault through External Secrets. Images run as non-root with a read-only filesystem.
PostgreSQL is the source of truth; lose the analytics store and governance continues. Recovery targets: RPO ≤ 5 min, RTO ≤ 1 h.
Built, and honestly labelled
Every architecture document ends with a section called "what is not here". This is the summary.
Swipe sideways to see the whole table.
| Capability | Status | Notes |
|---|---|---|
| Registry, identity, lifecycle, OIDC sign-in | Built | Eight-state lifecycle, five roles, invitation-only provisioning |
| Policy engine on OPA | Built | Immutable versions, bindings, every decision recorded |
| MCP gateway, tool registry, outbound connector | Built | HTTP and MCP upstreams, egress allow-lists, Vault secrets |
| A2A gateway | Built | Brokered, not reimplemented. Streaming and federation are roadmap. |
| Human approvals | Built | Tool calls only; delegation and escalation are roadmap |
| Audit, observability, FinOps | Built | Hash-chained audit, OTel spans, budgets with monitor mode |
| Shared memory, decision ledger, context engine | Built | Semantic search over memory is roadmap |
| Kubernetes Helm chart | Built | Terraform modules are roadmap |
| Enforcement SDK for agent-side actions | Phase 1 | Single-use grants for local actions; SDKs and framework adapters follow |
| Built-in evaluation service | Roadmap | Evaluation today lives in the application layers |
See governance on one of your centre's agents
Bring an agent you already run. We register it, bind a tool, write a policy, trigger an approval and verify the audit chain together.