Agent Control Plane·Governance layer under your GCC

One control plane for every enterprise AI agent

Centralised control over AI agents regardless of which model, framework, language or runtime they use. Registry, identity, authentication and authorization, policy enforcement, MCP and A2A gateways, human approvals, audit, observability, FinOps and lifecycle management.

It is not an agent framework, not a model, and not an agent runtime. It governs the runtimes you already have, including every agent in GCC-in-a-Box and any agent your teams build themselves.

3
Policy outcomes: ALLOW, DENY, REQUIRE_APPROVAL
10 min
Agent token lifetime. No permanent API keys.
8
Lifecycle states, with no shortcut to production
26
Published architecture decision records
The execution path

What happens when an agent calls a tool

Every tool call and every agent-to-agent message goes through the same gateway, in the same order. Click a step, or watch it play.

    Capabilities

    Everything an agent estate needs to be governed

    ▤

    Agent registry and lifecycle

    Each agent has one accountable human owner, immutable version snapshots, a risk level and an environment. An enforced lifecycle (draft → registered → testing → approved → deployed → active, with suspend and retire) has no shortcuts: every path to production goes through approval, and the specification freezes once approved.

    ⚿

    Agent identity

    Exactly one machine identity per agent. Agents authenticate with OAuth 2.0 client credentials and a signed assertion (RFC 7523, Ed25519) and receive a ten-minute token. Credentials must expire, and for key-based credentials only the public key is stored: a database leak is not an impersonation event.

    ☷

    Policy on OPA

    Policies in Rego, evaluated by Open Policy Agent. Every protected action resolves to ALLOW, DENY or REQUIRE_APPROVAL. Versions are immutable, bindings target an organisation, agent, environment or risk level, deny always overrides, and an unreachable engine fails closed. Every decision is recorded with its exact input.

    ⇄

    MCP gateway

    Built on the official Model Context Protocol SDK. An agent's tool list shows only what it is bound to; an unbound tool is indistinguishable from one that does not exist. Refusals return as structured tool results, so the agent can reason about them rather than crash.

    ⇆

    A2A gateway

    A2A v1.0 through the official SDK. Each agent gets its own URL and agent card; peer bindings are explicit and one-directional, and every message must name the skill it wants. A denied message looks exactly like a target that does not exist.

    ⏸

    Human approvals

    Asynchronous and durable, so they survive restarts. Bound to a SHA-256 fingerprint of tool, permissions and arguments; single-use; expiring; and the agent's owner cannot approve. Rego decides whether a human must look, an approval policy decides who.

    ⛓

    Audit

    Append-only and hash-chained in PostgreSQL. The application role can only read and insert, events are relayed through a transactional outbox, and the chain can be verified through the API. There is no write route over HTTP.

    ◉

    Observability

    OpenTelemetry spans for agent execution, tool invocation, policy evaluation and approvals, with W3C Trace Context. Events are labelled observed or reported, so it is always clear which lines are evidence and which are an agent's own claims.

    $

    FinOps

    A spend ledger priced from a versioned, provider-independent rate card. Costs are labelled as estimates; an unpriced model shows as unknown, never zero. Budgets per organisation, agent or department return ALLOW, WARN or DENY, with a monitor mode to watch before enforcing.

    ▦

    Tool registry and connector

    Tools have owners, risk levels, versioned schemas and declared permissions. The gateway makes every outbound call: exact-hostname egress allow-lists, private addresses refused, redirects refused, secrets resolved from Vault at call time and never handed to the agent.

    ☰

    Shared memory and decision ledger

    Organisational knowledge owned by the control plane so it can be shared across providers. Nothing is overwritten: corrections supersede, contradictions are kept, every memory records its provenance, and audit never contains memory content.

    ◫

    Context engine and console

    A ranked, budgeted package of what an agent should be told, deterministic and never containing anything the agent could not fetch itself. An operator console where every figure is a real count and a figure you cannot see shows "—", never zero.

    Interactive

    Policy decision simulator

    Change the inputs and watch the decision change. The rules mirror the example policies that ship with the control plane: a read-only baseline, production guardrails, high-value purchases and data residency, plus the budget gate.

    There are no wildcards. An unbound tool does not exist as far as the agent is concerned.
    Only applies to purchases. Approval above $5,000; hard ceiling at $50,000.

    This is an illustration running in your browser. In the product, the same inputs go to OPA, and the decision and its input are written to the decision record.

    package acp.high_value_purchases
    
    default decision := "ALLOW"
    
    decision := "DENY" {
      input.action == "purchase"
      input.amount >= 50000
    }
    
    decision := "REQUIRE_APPROVAL" {
      input.action == "purchase"
      input.amount >= 5000
      input.amount < 50000
    }
    Security and governance guarantees

    Claims you can check, not assurances you have to trust

    The threat model lists fifteen threats, each with the test that covers it. A threat model that lists only solved problems is marketing, so the residual risks are published too.

    • ✓
      Agents never hold permanent API keysCredentials must expire; tokens last minutes; only public keys are stored for key-based credentials.
    • ✓
      Revocation is immediateIdentity and agent status are re-checked on every request.
    • ✓
      Tenants are isolated twiceApplication scoping plus PostgreSQL row-level security, enabled and forced. Cross-tenant lookups return not-found.
    • ✓
      The audit trail is tamper-evidentAppend-only, hash-chained, verifiable by anyone; update and delete are revoked at the database level.
    • ✓
      Fails closedAn unavailable policy engine never becomes an implicit allow.
    • ✓
      No implicit accessTools, peer agents and memory each need an explicit binding or grant.
    • ✓
      One approval, one callEach approval authorises one exact invocation, once, and cannot be reused or altered.
    • ✓
      Secrets stay in the gatewayUpstream credentials live in Vault and never reach the agent.
    • ✓
      Attempt-limited authenticationEvery authentication endpoint is limited per address and per identifier, with identical failure responses.
    Standards, integrations, deployment

    Open standards at every seam

    No proprietary protocol, and no policy language of our own. Where a standard exists, the official implementation owns the protocol.

    Protocols and specifications

    MCPA2A v1.0OIDC / OAuth 2 + PKCERFC 7523OPA / RegoOpenTelemetryW3C Trace ContextOpenAPI 3.1RFC 9457

    Identity and runtimes

    Any OIDC identity provider for people (Keycloak is tested end to end). Two runtime adapters ship today, one in-process for Claude and one for an external runtime that receives only a gateway address and a short-lived credential. The adapter interface names no provider.

    Roadmap LangChain and CrewAI adapters · TypeScript and Python enforcement SDKs · SCIM group mapping

    Deployment

    Helm chart with API, console, optional separate gateway, OPA and an OpenTelemetry collector. Autoscaling, disruption budgets, default-deny network policy, TLS via cert-manager, secrets from Vault through External Secrets. Images run as non-root with a read-only filesystem.

    PostgreSQL is the source of truth; lose the analytics store and governance continues. Recovery targets: RPO ≤ 5 min, RTO ≤ 1 h.

    What is in the box today

    Built, and honestly labelled

    Every architecture document ends with a section called "what is not here". This is the summary.

    Swipe sideways to see the whole table.

    CapabilityStatusNotes
    Registry, identity, lifecycle, OIDC sign-inBuiltEight-state lifecycle, five roles, invitation-only provisioning
    Policy engine on OPABuiltImmutable versions, bindings, every decision recorded
    MCP gateway, tool registry, outbound connectorBuiltHTTP and MCP upstreams, egress allow-lists, Vault secrets
    A2A gatewayBuiltBrokered, not reimplemented. Streaming and federation are roadmap.
    Human approvalsBuiltTool calls only; delegation and escalation are roadmap
    Audit, observability, FinOpsBuiltHash-chained audit, OTel spans, budgets with monitor mode
    Shared memory, decision ledger, context engineBuiltSemantic search over memory is roadmap
    Kubernetes Helm chartBuiltTerraform modules are roadmap
    Enforcement SDK for agent-side actionsPhase 1Single-use grants for local actions; SDKs and framework adapters follow
    Built-in evaluation serviceRoadmapEvaluation today lives in the application layers

    See governance on one of your centre's agents

    Bring an agent you already run. We register it, bind a tool, write a policy, trigger an approval and verify the audit chain together.

    Sys-online//Hyderabad, India Est. 2013//GCC setup & operations ⛨ISO 27001/ISO 9001/CMMI-aligned
    Start your GCC setup Policy simulator