Govern is how your institution answers for its AI. Today: per-decision reconstruction and examiner-ready evidence packs. Next: runtime enforcement — scoped permissions, approval queues, the kill switch — on the same gateway. On the horizon: Guardian agents that supervise your AI against your policies.
to reconstruct any material AI decision
sectoral pack families: SR 26-2 · NAIC · EU AI Act
kill-switch propagation across every enforcement point
of interventions filed as evidence automatically
Raw telemetry shows what happened. It can’t show which policy governed, which version, or who approved.
Material AI actions approved in Slack threads and inboxes — unsearchable, unauditable, unenforceable. And 35% of enterprises admit they couldn’t shut down a rogue agent.
A human can’t read every output of a hundred agents. Sampling misses exactly the cases that matter.
For any material action: the governing policy and version, grounding sources, model and agent versions, evaluation results, and every human sign-off — assembled in minutes, chained tamper-evidently, and exported as sectoral examiner packs that maintain themselves.
Every agent gets an identity, not a key: role-scoped access to models, tools, and data, with material actions routed to the right human — by role, amount, or action type — and caps, breakers, and the kill switch behind them.
At hundreds of agents, human review of every action stops scaling. Guardians are the supervisory layer: Reviewers evaluate material outputs before they leave, Monitors watch for drift and anomalous behavior, Protectors quarantine and roll back — and every guardian is itself registered, certified, and evidenced.
For any material agent action: the governing policy provision and version, grounding sources with provenance, model and agent versions, evaluation results, autonomy tier, and every human intervention — assembled in under fifteen minutes.
SR 26-2 model and agent documentation for banking. NAIC AI Systems Evaluation artifacts for insurance. EU AI Act Annex IV technical documentation for European exposure. Always current, always exportable.
Cryptographically chained records verifiable independently — no one, including IRIS8, can silently alter the record. The evidence-pack format is a published open specification.
Role-scoped access to knowledge, tools, and data — per-tool read/write/deny on MCP connections, with end-user identity forwarded through every hop of agent-to-agent delegation. Enforcing 2027.
Act-with-Approval agents route material actions to the right human with full context. Budgets, action-rate limits, circuit breakers — and instant suspension at every enforcement point. Enforcing 2027.
Reviewers, Monitors, and Protectors supervising the estate continuously against your policies — each intervention governed, logged, and provable. The horizon layer, shaped with design partners now.
That's the success criterion we put in the pilot agreement — because in a regulated institution, the ability to answer "why did the AI do that?" is the difference between an AI program and an AI liability.
Decision reconstruction, tamper-evident evidence, and policy-aware observation run today on the Clarity tier. Inline enforcement — permissions, queues, caps, kill switch — ships with the Control tier in 2027, with Guardians beyond.
Yes. The evidence format is an open specification with a verifiable integrity chain — no IRIS8 account required to check it.
The agent’s identity is suspended at every enforcement point, in-flight actions inside reversal windows are rolled back, and the whole event is filed as evidence.
See a live reconstruction on your own traffic. Enforcement arrives on the same gateway — no migration later.
Start free