Product / Govern
IRIS8 Govern

Every decision on the record. Every agent under authority.

Govern is how your institution answers for its AI. Today: per-decision reconstruction and examiner-ready evidence packs. Next: runtime enforcement — scoped permissions, approval queues, the kill switch — on the same gateway. On the horizon: Guardian agents that supervise your AI against your policies.

Evidence · NowEnforcement · 2027Guardians · Horizon
app.iris8.ai/govern/reconstruction/A-58291
Agentcommercial-underwriting-v3.2
ActionRecommend: conditional approval
PolicyCredit Policy §4.2.1 (eff. 2026-03-01)
Sources3 approved · provenance ✓
Modelfrontier-lm-7 · pinned ✓
Sign-offs.reyes · Senior Credit Officer ✓
Packexported · examiner-ready ✓
<15 min

to reconstruct any material AI decision

3

sectoral pack families: SR 26-2 · NAIC · EU AI Act

<1 s

kill-switch propagation across every enforcement point

100%

of interventions filed as evidence automatically

The problem

When someone asks "why did the AI do that?" — most companies have logs, email approvals, and hope.

A log is not evidence

Raw telemetry shows what happened. It can’t show which policy governed, which version, or who approved.

Approvals in email

Material AI actions approved in Slack threads and inboxes — unsearchable, unauditable, unenforceable. And 35% of enterprises admit they couldn’t shut down a rogue agent.

Review doesn’t scale

A human can’t read every output of a hundred agents. Sampling misses exactly the cases that matter.

Capabilities in depth

Evidence today. Enforcement next. Supervision at scale.

Evidence · Now

Any decision, rebuilt end to end

For any material action: the governing policy and version, grounding sources, model and agent versions, evaluation results, and every human sign-off — assembled in minutes, chained tamper-evidently, and exported as sectoral examiner packs that maintain themselves.

  • Full lineage: policy → sources → model → output → approval
  • Tamper-evident records, verifiable without trusting IRIS8
  • SR 26-2, NAIC, and EU AI Act packs, continuously current
  • The open evidence-pack specification, published
app.iris8.ai/govern/reconstruction/A-58291
Agentcommercial-underwriting-v3.2
ActionRecommend: conditional approval
PolicyCredit Policy §4.2.1 (eff. 2026-03-01)
Sources3 approved · provenance ✓
Modelfrontier-lm-7 · pinned ✓
Sign-offs.reyes · Senior Credit Officer ✓
Packexported · examiner-ready ✓
Control · 2027

Human judgment, exactly where you want it

Every agent gets an identity, not a key: role-scoped access to models, tools, and data, with material actions routed to the right human — by role, amount, or action type — and caps, breakers, and the kill switch behind them.

  • Agent identity with per-tool MCP grants: read / write / deny
  • Approval queues routed by role and threshold, full context attached
  • Autonomy tiers: Observe → Advise → Act-with-Approval → Act-Autonomously
  • Kill switch: suspended everywhere in under a second
app.iris8.ai/govern/approvals
wire-adjustment $18,500loan-servicing agent · §5.1.2Awaiting approval
bulk email to 2,400 customerscollections agentAwaiting approval
tool grant: core-banking writenew vendor agentEscalated
rate quote outside matrixpricing agentAuto-declined
Guardians · Horizon

AI that supervises AI

At hundreds of agents, human review of every action stops scaling. Guardians are the supervisory layer: Reviewers evaluate material outputs before they leave, Monitors watch for drift and anomalous behavior, Protectors quarantine and roll back — and every guardian is itself registered, certified, and evidenced.

  • Reviewers: policy-conformance and citation checks at machine speed
  • Monitors: drift and anomalous tool use against certified baselines
  • Protectors: quarantine, revocation, and rollback within reversal windows
  • Guardians are governed too — the chain of proof goes all the way up
app.iris8.ai/govern/guardians
Reviewer: citation below thresholdwealth-advisor draft heldEscalated
Monitor: tool-use drift detectedclaims agent vs baselineWatching
Protector: agent quarantinedanomalous data accessQuarantined
Protector: action rolled backwithin reversal windowResolved
Everything included

Proof, control, and supervision — one chain of accountability.

Reconstruct

Per-decision lineage

For any material agent action: the governing policy provision and version, grounding sources with provenance, model and agent versions, evaluation results, autonomy tier, and every human intervention — assembled in under fifteen minutes.

Sectoral

Examiner packs, per regulator

SR 26-2 model and agent documentation for banking. NAIC AI Systems Evaluation artifacts for insurance. EU AI Act Annex IV technical documentation for European exposure. Always current, always exportable.

Integrity

Tamper-evident, open standard

Cryptographically chained records verifiable independently — no one, including IRIS8, can silently alter the record. The evidence-pack format is a published open specification.

Identity

Agent identity & scoped permissions

Role-scoped access to knowledge, tools, and data — per-tool read/write/deny on MCP connections, with end-user identity forwarded through every hop of agent-to-agent delegation. Enforcing 2027.

Humans

Approvals, caps & the kill switch

Act-with-Approval agents route material actions to the right human with full context. Budgets, action-rate limits, circuit breakers — and instant suspension at every enforcement point. Enforcing 2027.

Guardians

Guardian agents

Reviewers, Monitors, and Protectors supervising the estate continuously against your policies — each intervention governed, logged, and provable. The horizon layer, shaped with design partners now.

Staged honestly

Evidence first. Enforcement when it’s earned.

  1. Today — Prove & Observe. Every gateway decision is reconstructable and your policies evaluate against real traffic, flagging deviations without touching production behavior. Exam season becomes an export, not a scramble.
  2. 2027 — Act with Approval. Enforcement goes live on the same gateway: scoped permissions, approval queues, action caps, kill switch — every control defined centrally and tested before activation.
  3. The horizon — Guardian supervision. Highest-tier agents operate under continuous Guardian oversight with circuit breakers and rollback. Autonomy, on the record.
The demonstration we lead with

Any decision. Under fifteen minutes. In writing.

That's the success criterion we put in the pilot agreement — because in a regulated institution, the ability to answer "why did the AI do that?" is the difference between an AI program and an AI liability.

DECISION RECONSTRUCTIONREF #A-58291
Agentcommercial-underwriting-v3.2
ActionRecommend: conditional approval
Governing policyCredit Policy §4.2.1 (eff. 2026-03-01)
Grounding sources3 approved · provenance verified ✓
Model / versionfrontier-lm-7 · pinned · certified ✓
Evaluationpass · confidence 0.94 · threshold 0.90 ✓
Human sign-offs.reyes · Senior Credit Officer ✓
Evidence packexported · examiner-ready ✓
Questions

The short answers.

What works today vs. 2027?

Decision reconstruction, tamper-evident evidence, and policy-aware observation run today on the Clarity tier. Inline enforcement — permissions, queues, caps, kill switch — ships with the Control tier in 2027, with Guardians beyond.

Can auditors verify evidence independently?

Yes. The evidence format is an open specification with a verifiable integrity chain — no IRIS8 account required to check it.

What happens when the kill switch fires?

The agent’s identity is suspended at every enforcement point, in-flight actions inside reversal windows are rolled back, and the whole event is filed as evidence.

Don’t trust the answer. Prove it — then enforce it.

See a live reconstruction on your own traffic. Enforcement arrives on the same gateway — no migration later.

Start free