by the job

What are you actually trying to stop happening?

Start from the thing you are trying to stop happening, which is the shape most people actually arrive in rather than a list of features. Each page walks the job end to end, then ends on what it still does not solve once you have done all of it — because every one of these leaves a residue, and knowing the shape of that residue in advance is the difference between trusting a control correctly and trusting it too far.
Jobs covered
8
Steps in total
48
Things they still do not solve
32
That end on “and then you are done”
0
01

Stop agents leaking personal data and secrets to model providers

Detect on both legs, mask or tokenise before the payload leaves, and publish what the detector cannot see.

Free-text personal data — a name, an address, a described condition

6 steps
02

Cap what an AI agent can spend, rather than find out afterwards

Refused before egress, priced against everything the route could reach, and never estimated at zero.

One billable egress: no retry, no failover

6 steps
03

Produce audit evidence for AI agents that an auditor accepts

One bundle with a verification verdict inside it, and the protection level stated beside the verdict.

Nothing was altered without recomputing — read the protection level

6 steps
04

Control which tools an AI agent may actually call

Grants re-checked at execution rather than at the list, and a descriptor that changed is quarantined.

A tool the agent calls from its own process, never routed through it

6 steps
05

Find the AI use happening outside your controls

Five evidence sources, and a coverage report that refuses to call a dead feed a clean estate.

It detects and reports. It blocks nothing at all

6 steps
06

Put a person in front of a consequential agent action

One decision, bound to one exact payload, spendable once — and nothing calls the agent back.

An approval takes effect only when the agent retries

6 steps
07

Stop one agent, a whole team, or everything, now

Checked first, before every other control, and honest about refusing new work rather than recalling old.

It refuses new work; it cannot recall a dispatched request

6 steps
08

Answer whether an agent was allowed to do that, after the fact

The authority as it stood at the moment of the call, the decision taken on it, and a review bound to a digest.

No answer text is stored; the prompt is a 4,000-character excerpt

6 steps
a note on these

Why every one of them ends badly, on purpose.

Each page finishes with what the job does not solve. That is not modesty and it is not a disclaimer: it is the most operationally useful part of the page. A team that installs a control believing it closes a gap completely stops looking at the gap, and the part that was still open is the part that eventually matters.

The residues are real and they recur. Traffic that never came through the gateway is not governed by it. Detection that is heuristic has false negatives. An approval queue nobody reads is a rubber stamp with extra steps. None of those is fixed by any product on the market, including this one, and a page that implied otherwise would be the sort a reader discovers is wrong in production.

get in touch

Which of these is the one keeping you up?

The jobs above are the general shapes. Which of them matters, and what your version of it looks like, depends on what your agents actually do — say that and you will get a straight answer about where to start.

no form · no qualification step · no sales desk · the other three ways in