Three governed domains. One plane.
Govern the things that matter at the point they matter.
Security teams should not have to reconstruct control from a patchwork of model
settings, agent logs, connector permissions, and cost dashboards.
01 / Knowledge
Who sees what.
Answers carry provenance. Team and tenant boundaries are enforced at the row. PII and topic guardrails run before a request reaches a model.
Knowledge that agents can be trusted to act on—and controls your security team can sign.
02 / Agents
What agents may do.
Workers are permission-scoped, allow-listed, capped, costed, and auditable. An off-list tool is not refused at runtime. It was never offered.
A workforce you can let act—and prove what it did afterward.
03 / Usage
Where the spend goes.
Every routed model call contributes to one view of usage, budgets, policy, and audit—per model, team, user, and Worker.
Organization-wide AI spend you can see, cap, and audit from day one.