Assess action risk
Identify which agent actions require explicit authorisation and oversight.
Our proprietary agentic AI control approach is designed to check authorisation before an AI agent performs an action that changes an enterprise system.
An agent may be allowed to recommend a change without being allowed to execute it. Our approach puts a control between the proposed action and its execution.
Each permit is single-use, cryptographically bound to the exact action and verified at execution. The design addresses approval reuse, changes to approved actions, bypass of the approved route and duplicate execution.
Describe exactly what the agent may change and under what conditions.
Require a valid, action-specific permit rather than a reusable approval.
Check the permit, hard rules and required data before the action occurs.
Fail closed where the underlying data is stale or incomplete.
The control design connects approval to the action being executed, with hard safety rules taking precedence over statistical models.
A permit is designed for one authorised action and one use.
The permit is bound to the exact action, so changes invalidate that authorisation.
Hard safety conditions remain decisive at execution.
The control fails closed when required data conditions are not met.
A working prototype of each core component has been built and tested. A UK patent application is pending.
Discuss suitability, integration requirements and evaluation scope for your environment. Production deployment, scalability and independent validation would require further assessment.
Identify which agent actions require explicit authorisation and oversight.
Map permissions, safety conditions and evidence needs to your systems.
Agree the environment, success criteria and evaluation of the approach.
The current capability is a working prototype. Any evaluation or integration is scoped around the organisation’s systems, requirements and environment.
No. A UK patent application has been filed and is currently pending. The control is described here at a high level.
No. Runtime authorisation is one part of a wider system of governance, oversight, monitoring and assurance. Policies and accountability remain necessary.
Discuss the risks of agents acting on your enterprise systems and the controls those actions require.