Trust every
AI decision.

Caught in CI. Enforced at runtime.

support-agent enforced in the request path
read_order_historyAllow
search_knowledge_baseAllow
issue_refund > $500Approval required
delete_customer_accountBlock
Blocked before the tool ran.
policy no-destructive-actions · record AG-28491 · exportable

Most AI tools watch what already happened.
We decide what is allowed to happen — then keep the proof.

Both ends of the lifecycleCaught in CI. Enforced at runtime. One record across both.
Mapped to the frameworksNIST AI RMF · EU AI Act · OWASP
Open at the design-time edgeApache-2.0, offline by default, no telemetry
Deployed on your termsSaaS or self-hosted, in your own cloud
The failure mode

Agents break differently.

Not a breach. A correct-looking system doing a permitted thing, thousands of times, with nothing in the execution path to stop it.

Day −11
Four lines merged.
Reviewed. Approved. Shipped. No AI-specific gate was checking for the missing bound.
Hour 0
The agent starts looping.
Every call succeeds. Every response is valid. Nothing alerts, because nothing is wrong.
Hour 9
The invoice finds it.
Not monitoring. Not an alert. Billing — nine hours in.
9hours
Undetected
Between the first loop and the first person who noticed.
4lines
Root cause
A missing iteration bound. Caught by a static rule in under a second.
1invoice
The detection channel
The only system that noticed was the one that charges for tokens.

The agent wasn't attacked. The control was missing.

Not an isolated shape. In July 2025 a coding agent deleted a live production database during an explicit code freeze. The freeze existed only in the prompt.
Fortune · Fast Company · Jul 2025
The thesis

Enforced twice.

Once before the code ships. Once while the agent runs. Both ends know the same defect by the same name, and write to the same record.

Before it ships

Plumbline

Static analysis that reasons about what agent code actually does — loops without bounds, calls without limits, secrets on the wrong path.

Code
PLB-AGT-001
CI gate

Apache-2.0 · SARIF 2.1.0 · offline by default

While it runs

AgentGuard

Policy in the request path. Every call is checked against what that agent may do — before it executes, not after.

Agent action
Policy
Allow Read only Approval required Block

Same defect. Same identity. Same evidence.

61
Published
taxonomy
32
Rules
implemented
12
Runtime
controls
1
Record per
decision
The layer underneath

Control starts with knowing.

You cannot govern AI you cannot inventory. Before anyone says what an agent may not do, someone has to say what agents exist, who owns them, and what they reach.

Customer support agent Model GPT-5.x Claude Opus 5 Tools Salesforce MCP Stripe API Data Customer PII Billing records Owner CX Engineering · Priya N. Risk class High — customer data, financial action

AI Registry

Private preview

The system of record for the AI you already have. It sits underneath the two products above.

DiscoverAgents, models, MCP servers and tools, in the repositories you already run.
OwnAn engineering, business and risk owner against every component.
UnderstandWhat each one depends on, and what it can reach.
ApproveWhat it is permitted to do — the policy AgentGuard enforces.
Join the private preview
Control

Decide what AI may do.

Not a filter on the output. A permission model on the action — declared per agent, enforced in the request path, before the tool runs.

Claims agent tool_permission · enforced in both SDKs
read_customer_profileAllow
search_policy_recordsAllow
modify_customer_recordRead only
approve_claim > $10,000Approval required
export_customer_dataBlock
delete_recordBlock
ModelsToolsDataCostActions

Approval required is human-in-the-loop as a guardrail — the reviewer sees the action, the arguments, and the policy that stopped it.

Evidence

Every decision leaves evidence.

One record per decision — what the agent tried, which policy applied, what it cost, and whether the answer held up.

AG-284912026-08-28 · 11:04:22 UTC
Agentclaims-agent
Actionapprove_claim
Toolpolicy-api / v3
Modelgpt-5.x
Policyhigh-value-approval
DecisionApproval required
Trace
Complete
Guardrails
12 / 12 ran
Evaluation
0.94
Cost
$0.08
Latency
1.7 s
Evidence
Exportable
Trust Profile

Trust is earned from evidence.

Not a dashboard average. Gated on the weakest dimension — and when the evidence isn't there, it says so instead of producing a number.

System A · support-agentInstrumented
91Trust
Security94
Reliability91
Quality87
Governance93

Ninety days of production evidence behind every number.

System B · claims-agentNewly onboarded
Insufficient evidence
Security
Reliability
Quality
Governance

We will not manufacture a number because a dashboard has space for one.

The category

Built for AI TRiSM.

Four questions, in the order a regulated enterprise has to answer them.

Know
What AI exists?
AI Registry · preview
Control
What may it do?
Plumbline · AgentGuard
Verify
Did it behave correctly?
AgentGuard
Prove
Can you show what happened?
AgentGuard
ActaClad One record, carried across all four.
NIST AI RMFMapped EU AI ActMapped OWASPMapped ISO/IEC 42001On the roadmap

Turn production behaviour into governance evidence.

Where you stand

How mature is your AI control plane?

Most enterprises running agents in production are at L0 or L1, and have not been told which.

L0
Unknown
You don't know what AI you have.
L1
Visible
You can see it. Traced and costed.
L2
Guarded
You can stop it — before it ships, and while it runs.
L3
Scored
You can verify it. Regressions block the release.
L4
Accountable
You can prove it. Identity, authorization, replay.
Where to start

Start before production.

Nobody has to approve the first one.

Developer

Catch it in CI.

Scan your own repository and see what a gate would have stopped. No telemetry, no account.

pip install actaclad-plumbline
Install free
Enterprise

Control production AI.

Bring one live agent. We instrument it, put policy in its request path, and show you the record.

AgentGuard · runtime control & evidence
Talk to us
Emerging capability

Map your AI estate.

A few design partners are running the Registry against their own repositories. Selective and unpriced.

AI Registry · private preview
Join the preview
Talk to us

Bring one AI system.

Going into production, already live, or heading into an audit — start with a conversation. No slideware.