Solutions Platform Product Governance Security Pricing Standards Contact Log in Request a demo
Governance & trust

Governance by construction —
not bolt-on.

Most platforms add guardrails after the fact. Aegis builds them into the architecture: every agent is born inside an authority envelope it cannot widen, every action is checked against the org chart, and every decision leaves a verifiable trail. Autonomy and control stop being a trade-off.

Dual-plane model Operating envelopes Verification gradient Trust lineage
The dual-plane model

Humans set direction. Agents do the work.

Aegis separates the enterprise into two planes. People live on the trust plane, where they set intent and grant authority. Agents act on the execution plane, where they carry out governed work. The human is always on the loop — observing, steering, intervening — never trapped in it for every keystroke.

Trust plane — the people

Where humans define the operating envelope: who may do what, how much they may spend, what they may see, and when. Authority is granted here and flows down the chart. Decisions that need a person stay with a person.

Execution plane — the agents

Where function-focused agents carry out the actual work, each mirroring a role and acting strictly inside the authority that role allows. Everything they do is observable on the trust plane in real time.

The Mirror Thesis. Trust is validated against what an agent actually does — not what it promises. The trust plane watches the execution plane, and adjusts authority based on demonstrated behaviour.
Operating envelopes

Authority can only narrow — never widen

Every role defines an operating envelope for the roles beneath it across five dimensions. A task may tighten that envelope further but can never loosen it. What an agent may actually do is the intersection of every envelope from the top of the chart down to the task in hand — the tightest limit always wins.

  • Financial — spend ceilings and budget authority.
  • Operational — which actions and systems are in scope.
  • Temporal — when, and for how long, authority applies.
  • Data access — what classification of information may be touched.
  • Communication — who and what the agent may communicate with.

Effective envelope = the intersection

Organization envelope
the outer bound, set at the top
Role envelope
narrower — the standing limits of a role
Task envelope
tightest — where the agent acts

Fails closed. If any envelope in the chain is missing or undefined, the action is denied — governance is never assumed.

The verification gradient

Not just approve or reject — a spectrum

Binary gates force a false choice: block everything for review, or wave it all through. Aegis grades each action into one of four zones, so routine work flows and only genuinely consequential decisions reach a human.

Auto-approved

Inside every limit. The agent proceeds on its own; humans can review it afterwards.

Flagged

Proceeds, but a human is notified and can step in if something looks off.

Held

Pauses for a specific, bounded human approval before going any further.

Blocked

Outside the envelope. The action is denied automatically — no human action needed.

Trust lineage

Every agent carries a verifiable chain of trust

An agent's authority isn't an assumption — it's a documented lineage of five elements, backed by instant cascade revocation. Together they answer, for any action at any moment: who granted this, how far does it reach, and can it be proven after the fact?

Genesis record

The root of authority — where this chain of trust began and who established it.

Delegation records

The hand-offs of authority down the chart — each one signed, each one traceable to its source.

Constraint envelope

The exact limits in force for this agent — the five dimensions, intersected to the tightest bound.

Capability attestation

Proof of what this agent is actually permitted and able to do — verified, not claimed.

Audit anchor

The append-only landing point for every action, so the whole chain can be replayed and reviewed later.

The capability that enforces the lineage

Cascade revocation

The five elements above make authority auditable. Cascade revocation is what makes it enforceable: pull authority at any point in the chain and everything downstream loses it instantly — no orphaned permissions, no lingering access.

Trust postures

Five levels of autonomy — earned, not granted

Every agent runs at one of five trust postures. The posture caps both what the agent may do and how sensitive the data it may reach. Upgrades require demonstrated performance and a human gate; downgrades happen automatically and instantly the moment conditions change.

Upgrades are human-gated. An agent can never promote itself. More autonomy is earned through a track record of acting well within its limits — and confirmed by a person.
Downgrades are automatic. Cross a boundary or change the conditions, and trust tightens immediately — the system never waits for someone to notice.
When you need to pull back

A stop button that actually stops things

Autonomy is only safe if you can take it away faster than it can be misused. Aegis's controls are structural and automatic — they don't depend on someone watching a dashboard at the right moment.

Cascade revocation

Pull authority from any role and, in the same operation, every agent below it on the chart loses that authority too. There's no window where a revoked branch keeps acting.

Automatic downgrade on risk

Cross a boundary or change the conditions and the agent's posture tightens by itself — instantly, with no human in the loop. The system is the gate for taking trust away.

Time-boxed emergency bypass

When an incident needs more room, authority can be widened — but only with a hard expiry (4 hours by default, 72 at most), escalated to the reporting superior, and never beyond that superior's own limits.

"Instantly" means deterministic. Revocation and expiry are enforced by a timer and a single operation — not by an agent choosing to comply. When the clock runs out, the bypass is gone whether or not anyone made a request.
Every bypass is reviewed. Emergency widening leaves its own audit anchors and triggers a post-incident review within seven days. Breaking the glass is always possible — and always accounted for.
Always auditable

No governed action goes off the record

Every governed action lands on a complete, append-only audit trail — what was attempted, which envelope applied, which zone it fell into, and how it resolved. Compliance stops being a quarterly scramble and becomes a continuous, queryable fact.

179distinct governed audit actions
7governance state machines
5constraint dimensions enforced
5elements in every trust lineage

Governance you can demonstrate, not just describe.

See an agent get blocked, flagged, and held in real time — and watch the audit trail capture every decision as it happens.