The Governance Layer for AI Agents

Who governs your AI agents?

Know what your agents are doing. Stop them when you need to. Prove it happened.

Agentomy is the operating layer for discovering agents, enforcing runtime policies, and producing audit-ready proof across the agent stack.

GovernanceBench 224/224/VIGIL 148/148/18,221+ tests/6 verticals/22 integration points
$npx governancebench run --target https://your-platform-url

Self-hosted by design. Bring your own model, bring your own key. Your data never leaves your infrastructure. Read the sovereignty model →

Runtime events from governed agents.

Every agent action passes through identity, permission, audit, and policy gates. The events below are sampled from a demo environment.

Governance event streamLIVE 12:42:08
Agent
Action
Policy
Result
Time
PRPermissionRouter
data_access_request
vendor-access
Blocked
12:42:08
ALAuditLogger
output_validation
audit-trail
Allowed
12:41:54
TSTrustScorer
policy_check
runtime-score
Allowed
12:41:37
RMRuntimeMonitor
behavior_drift
drift-threshold
Flagged
12:40:58
HPHaltProtocol
halt_initiated
unsafe-action
Blocked
12:40:21
ECEthicsConstraint
prompt_review
restricted-output
Flagged
12:39:46
DLDecisionLog
evidence_recorded
decision-proof
Allowed
12:39:12
Governance events today: 12,842Demo environment

Discover. Enforce. Prove. Govern.

A practical governance loop: find the agents already operating, enforce policy at runtime, produce evidence, and govern the system as it evolves.

01 Discover

Find agents your organization does not know it runs.

Map agent activity, ownership, frameworks, connectors, model routes, and runtime permissions across the stack.

02 Enforce

Policies that enforce themselves at runtime.

Turn policy into runtime decisions: allow, block, quarantine, route, or review.

03 Prove

Audit-ready proof, not audit-ready promises.

Convert policy decisions and runtime events into traceable evidence with cryptographic chain-of-custody.

04 Govern

One governance layer for every agent framework.

Coordinate governance across frameworks, connectors, models, and runtime environments.

Governance has to produce evidence.

Agentomy is designed around traceability. Every policy decision, runtime exception, connector request, and approval path becomes part of an evidence trail.

Cryptographic audit trail. Tamper-evident, operator-owned, independently verifiable.
Adversarial governance testing. GovernanceBench tests whether the governance layer itself can be bypassed.
Vendor-neutral halt. One command stops all connected agents regardless of platform, with cryptographic proof of halt.

Our governance benchmark is published open source under Apache 2.0. Every claim is reproducible from a fresh clone.

Real incidents, real consequences.

Documented governance failures from the last 90 days. Each maps to specific Agentomy detection capabilities.

Lilli Breach, February 2026

46.5M messages exfiltrated in under 2 hours.

Autonomous agent exploited 22 unauthenticated API endpoints at a major consultancy. 57K user accounts, 384K AI assistants compromised. 95 system prompts were writable; attacker could reprogram thousands of consultants' AI without deploying code. No agent identity verification, no authorization checks, no audit trail, no kill switch. (CodeWall disclosure, February 2026.)

Detected by: Identity Resolution, Permission Enforcement, Behavioral Baseline, Content Scanning, Hash-Chain Audit, Fleet Halt

Shai-Hulud Worm, May 2026

Anti-remediation: wipes the machine if you revoke tokens.

Autonomously constructed worm spreads through agent processes. Steals credentials from agent environments, triggers immediate machine destruction if defenders attempt token revocation. Defense requires halting the agent BEFORE revocation.

Detected by: Shadow Discovery, Content Scanner, Behavioral Monitor, Desktop Interceptor, Sovereign Halt

node-ipc Supply Chain, May 2026

822K weekly downloads, 90+ credential categories stolen.

Attacker re-registered a maintainer's expired email domain, hijacked npm account, published three poisoned versions. Fires on require() with no postinstall script. First npm attack targeting AI tool configs.

Detected by: IOC Package Flagging, Version Pinning, C2 Domain Detection, Obfuscated Script Detection

Six verticals. Per-vertical incident references. Per-vertical governance patterns.

57 governance threats catalogued across six verticals. 41 critical, 16 high. Each vertical page lists its threats in severity-ranked order with its matching SDK adapter.

RPA automation

Govern your bots like you govern your agents.

Unauthorized macro escalation, credential abuse, scheduled-bot drift, unmanaged execution windows. 10 patterns + adapter + benchmark suite.

Critical 5  /  High 5

See RPA coverage →
Algorithmic trading

Your algorithms trade. Your governance doesn't.

Position-limit breaches, fat-finger orders, runaway strategies, post-trade attribution gaps. 12 patterns + adapter + benchmark suite.

Critical 9  /  High 3

See algo trading coverage →
Medical device

Your algorithms diagnose. Your governance doesn't.

Diagnostic-model drift, off-label inference, FDA SaMD scope boundary, clinical override audit. 10 patterns + adapter + benchmark suite.

Critical 7  /  High 3

See medical device coverage →
Autonomous vehicle fleet

Your vehicles drive. Your governance doesn't.

ODD boundary violations, sensor degradation under safety threshold, remote operator override authority, per-vehicle policy attestation. 10 patterns + adapter + benchmark suite.

Critical 7  /  High 3

See AV fleet coverage →
Industrial IoT

Your controllers operate. Your governance doesn't.

PLC firmware integrity, OT/IT boundary crossing, anomalous setpoint changes, safety-instrumented-system override audit. 10 patterns + adapter + benchmark suite.

Critical 9  /  High 1

See industrial IoT coverage →
Cloud infrastructure

Your agents operate the cloud. Your governance doesn't.

IAM privilege escalation by agents, cross-account resource creation, runaway-spend before circuit-breaker, infrastructure-as-code drift attribution. Adapter + benchmark suite.

Critical 4  /  High 1

See cloud infrastructure coverage →
Honest readiness

No third-party certifications. Self-assessed readiness mapped per control.

Procurement teams filter for the cert. We do not have it. Here is what we have instead, and how to verify each claim against the actual source.

What is mapped (self-assessed, per control)
SOC 2 readiness
EU AI Act
GDPR
HIPAA readiness
ISO 27001 aligned
PCI DSS controls
NIST SP 800-53
NIST PQC planned
SOX planned
FERPA planned

12 regulatory frameworks with 100+ controls mapped. 9 at self-assessed readiness today. The remaining 3 are control-mapped and planned. Source: compliance/ directory, traceable per control.

What we honestly do NOT claim
SOC 2 Type II report
External ISO 27001 attestation
HIPAA BAA-signed
PCI DSS attestation
FedRAMP authorization
Third-party audit
Independent pen test report
ISO 42001 mapping

SOC 2 Type II is not pursued. HIPAA requires a deployer-supplied BAA. PCI DSS infrastructure controls are provided but Agentomy itself handles no payment card data. FedRAMP needs a federal sponsor and 3PAO engagement. ISO 42001 (2023 AI Management System standard) acknowledged but not yet mapped.

When you need formal compliance verification: engage a qualified auditor against the deployed Agentomy instance and the mapped controls. Honest framing protects the deployer; ambiguous "compliant" claims do not survive audit. Read the full honest disclosure →

Discover. Enforce. Prove. Govern.

Each governance capability runs in the platform layer. The data panels below sample the operating state.

Find agents your organization does not know it runs.

Maps active agents, frameworks, permissions, and runtime state before they become ungoverned risk.

Agent registryDemo environment
AgentTypeStatusModuleScore
sales-research-agentResearchActiveRuntimeMonitor92
support-triage-agentSupportActiveAuditLogger88
vendor-review-agentProcurementMonitoredPermissionRouter74
finance-extract-agentFinanceQuarantinedHaltProtocol41
policy-draft-agentLegalMonitoredEthicsConstraint79
report-builder-agentOpsActiveDecisionLog90

Policies that enforce themselves at runtime.

Runtime checks route decisions through policy controls before sensitive actions execute.

Enforcement policiesDemo environment
EU AI Act evidence captureTrustScorerActiveUpdated 4m ago
NIST RMF runtime reviewRuntimeMonitorActiveUpdated 9m ago
OWASP Agentic Top 10 guardrailEthicsConstraintPendingUpdated 16m ago
Vendor connector permissioningPermissionRouterViolatedUpdated 22m ago
Unsafe execution haltHaltProtocolActiveUpdated 31m ago

Audit-ready proof, not audit-ready promises.

Every evaluated action becomes a traceable evidence record with policy context and decision history.

Evidence chainHash-linked
TimeAgentActionResultHash
12:42:08PermissionRouterdata_access_requestBlocked...9f2a81c4
12:41:54AuditLoggeroutput_validationAllowed...3d91a0be
12:41:37TrustScorerpolicy_checkAllowed...71e43d22
12:40:58RuntimeMonitorbehavior_driftFlagged...a48c0e19
12:40:21HaltProtocolhalt_initiatedBlocked...6be802aa

One governance layer for every agent framework.

Unify policy state, agent visibility, runtime controls, and evidence records across the agent stack.

Governance overviewOperating state
86%Governance score
47agents governed
18policies active
12,842demo events today
12:40last halt event

A command center for governed agents.

Monitor agent inventory, policy coverage, enforcement actions, evidence records, and model routing from one operational surface.

Command centerLive preview
Overview
EU AI ActAlignment
78%
NIST RMFAlignment
92%
OWASP AgenticAlignment
85%
12:42PermissionRouterVendor access blocked
12:41AuditLoggerEvidence record generated
12:40RuntimeMonitorBehavior drift flagged
12:39TrustScorerGovernance score updated
12:38TraceBindingConnector trace attached
12:37DecisionLogPolicy decision recorded
Agent registry
92sales-research-agentActive · RuntimeMonitor
88support-triage-agentActive · AuditLogger
74vendor-review-agentMonitored · PermissionRouter
41finance-extract-agentQuarantined · HaltProtocol
79policy-draft-agentMonitored · EthicsConstraint
90report-builder-agentActive · DecisionLog
Active policies
vendorPermissionRouterBlock external data access without approval
auditAuditLoggerRecord every governed action as evidence
scoreTrustScorerScore each action against policy at runtime
driftRuntimeMonitorFlag behavior drift beyond baseline
haltHaltProtocolHalt agents on unsafe action attempts
reviewEthicsConstraintQueue restricted output for review
Runtime events
12:42PermissionRouterdata_access_request blocked (vendor-access)
12:41AuditLoggeroutput_validation allowed (audit-trail)
12:40RuntimeMonitorbehavior_drift flagged (drift-threshold)
12:39TrustScorerpolicy_check allowed (runtime-score)
12:38TraceBindingconnector_trace allowed (crm-access)
12:35HaltProtocolhalt_initiated blocked (unsafe-action)
Audit trail · hash-linked
#a7f312:42:08PermissionRouter / data_access_request / Blocked
#a7f212:41:54AuditLogger / output_validation / Allowed
#a7f112:41:37TrustScorer / policy_check / Allowed
#a7f012:40:58RuntimeMonitor / behavior_drift / Flagged
#a7ef12:40:21HaltProtocol / halt_initiated / Blocked
Connectors
crmCRM connectorTrace-bound
warehouseData warehouseTrace-bound
ticketingTicketingTrace-bound
repoRepositoryMonitored
messagingMessagingTrace-bound
Framework alignment · self-assessed
EU AI ActAlignment
78%
NIST RMFAlignment
92%
OWASP AgenticAlignment
85%

Every Agentomy primitive ships in the Agent Skills format.

AI agent platforms discover capabilities through the open Agent Skills spec. Agentomy ships 16 spec-conformant skills covering every named primitive in our vocabulary, discoverable in the agent's native namespace.

SovereignSkillRegistry

Runtime-loaded registry of every spec-conformant SKILL.md. SHA-256 contentHash per skill plus registryHash (hash-of-hashes) for tamper-detect across the full inventory. Public discovery at GET /api/skills/registry/status.

SignedSkillAttestation

Ed25519 attestation binds skill content + version to the constant Agentomy issuer. Verifier returns five specific tamper reasons. Differentiates from unsigned community skill libraries.

govern.skill() SDK

Three-gate decision that turns "loaded a skill" into "loaded a governed skill". Skill exists in registry, caller tier permits, attestation verifies. const r = await agent.skill("agent-certificate", { callerTier: "Operator" }).

22 governed integration points across AI frameworks and verticals.

Agentomy Agent ships adapters that wrap the standard call surface of each supported framework or vertical with governance: identity, permission boundary, audit, override, behavioral monitoring. One govern() call swaps in the governance layer; the rest of the framework code stays the same.

AI agent frameworks · 16
LangChain
LangGraph
AutoGen
CrewAI
Haystack
Google ADK
Microsoft Agent
Semantic Kernel
Dify
Flowise
OpenAI Agents SDK
Azure AI Foundry
AWS Bedrock
Agno
Hermes
OpenClaw
Vertical adapters · 6
RPA automation
Algorithmic trading
Medical device
Autonomous vehicle fleet
Industrial IoT
Cloud infrastructure

Source-verifiable in agentomy-agent/src/adapters/. Install via npm install agentomy-agent. Each adapter exports the same governance contract; integration is one method call (agent.govern()) per framework instance.

Open where trust begins. Commercial where governance scales.

Agentomy Agent gives builders an open governed agent framework. Agentomy builds the commercial governance layer around discovery, enforcement, evidence, and enterprise control.

PermissionRouter
AuditLogger
HaltProtocol
ExecutionTimer
AgentSandbox
DecisionLog
TraceBinding
TeamCoordinator
EthicsConstraint
TrustScorer
RuntimeMonitor
DeploymentManifest
Discover, enforce, prove.

Bring Your Own Key. Self-hosted (Tier 1) or API key (Tier 2). Your governance data stays in your infrastructure. Deploy to Azure Container Apps, Kubernetes, Docker, or air-gapped environments. Self-hosted deployment eliminates network transport exposure entirely.

$ npm install agentomy-agent
import { GovernancePipeline } from 'agentomy-agent'
const gov = new GovernancePipeline()
const result = await gov.evaluate({ action: 'data_export' })
console.log(result.auditTrail)
By the numbers

Open foundation. Governance scale. Honest licensing.

12 / 250+Open source / governance modules
18,221+Automated tests
5 / 5GovernanceBench suites confirmed
MIT / Apache 2.0 / AGPLOpen source licensing
Governance is not the opposite of innovation. It is the structure that makes innovation possible.

Govern the agents already operating inside your organization.

Agentomy gives teams the operating layer to discover, enforce, prove, and govern AI agent activity before it becomes unmanaged risk.

Get started freeView open source