Govern the action, not just the paperwork.
A policy in a document cannot stop an agent issuing a refund. Ez AI Governance sits in front of the action: every tool call, transaction and delegation is checked against the policy in force, allowed, held for a human or blocked — and written to a signed record you can hand an auditor.
EU AI Act, ISO 42001, NIST AI RMF and OWASP Agentic, mapped to controls you can actually prove.
Policy becomes a control at the moment it matters.
A dashboard tells you what happened. Runtime governance decides what is allowed to happen — and leaves behind a record that stands up outside your engineering team.
Per-action gate
Agents present each action before they take it. Within policy it proceeds; above its transaction authority it is held for a named human; outside its approved tools it is refused. The sidecar fails closed, so an unreachable gate stops the action rather than waving it through.
Authority that expires
An agent acts under a certificate issued through separation of duties, or under a scoped delegation that narrows what it inherits. Certificates expire and are invalidated by material change; delegations carry their provenance and can be withdrawn, cascading to everything delegated beneath them.
Evidence you can verify
Every decision and every eval result is hashed into a signed, hash-linked ledger. The public key is published and the chain head is anchored outside the database, so an auditor can check the record without access to the system — or to us.
Human approval
Reviewers see the raw action, never the agent's summary of it.
Kill switch & breakers
Pause or kill an agent instantly; rate, spend and failure breakers trip on their own.
t₀ reconstruction
Each decision records the model, prompt, knowledge base and policy versions in force when it was made.
Coverage detection
A gate governs only what routes through it, so we tell you which registered agents have gone quiet.
Green because the evidence says so.
Attestation is a claim. Attach a rule to a control — a metric threshold, a freshness window, a signed attestation — and your CI pushes the result. The platform, not the submitter, decides pass or fail, and flags the control when the two disagree.
Evidence API & connectors
Post eval, bias, drift and guardrail results straight from your pipeline, or import from promptfoo, RAGAS and Bedrock Guardrails. Each submission is hashed and witnessed, so an edited result cannot pass unnoticed.
Tier-driven obligations
Autonomy decides the burden. A T4 agent carries controls a T1 assistant does not, and the obligation calendar tracks the EU AI Act dates that apply to you — with what is done, due and overdue.
Shadow AI discovery
Feed in what your cloud, MCP gateway and repositories already know. Unregistered agents and model endpoints surface for triage instead of appearing first in an incident.
AI bill of materials
CycloneDX export of models, tools, guardrails and data behind each system.
DPIA & FRIA
Structured assessments with scoring, mitigations, approvals and attachments.
Serious incidents
Article 73 reporting with deadlines tracked from the moment of detection.
Evidence packs
One download: controls, AIBOM, ledger excerpt, public key and verification steps.
From registration to a decision you can defend.
Register and classify
Inventory each AI system and agent, assign accountable owners, and let autonomy set the governance tier and the controls that come with it.
Certify
Evidence is submitted, independently approved, evaluated and certified by separate people — then promoted stage by stage toward production.
Enforce
Point your agents at the gate. Actions are allowed, held or blocked against the certificate, the tool registry, the data register and live circuit breakers.
Demonstrate
Export the pack. Controls, evidence, the signed ledger and the key to verify it — without anyone having to take your word for it.
Mapped once, answered many times.
Controls are crosswalked, so evidence gathered for one framework answers the equivalent clause in another. Sector packs are switched on only by the organisations they apply to.
EU AI Act
Provider and deployer duties, Art. 4 literacy, Art. 26 obligations, Art. 27 FRIA, Art. 50 transparency, Art. 73 incidents, Art. 12 logging.
ISO 42001 & NIST AI RMF
Management-system clauses and the Govern / Map / Measure / Manage functions, including the GenAI profile.
OWASP Agentic & runtime safety
Goal hijack, tool misuse, identity abuse, memory poisoning and rogue-agent controls, enforced at the gate rather than described.
Sector packs
AI quality management for Art. 17, GMP Annex 22 for medicinal products, financial-services model risk and clinical AI safety.
What we will tell you before you ask.
A runtime gate governs the actions that route through it. Anything an agent reaches another way is outside it — which is why the platform reports how many of your registered agents actually call the gate, alerts when a production agent falls silent, and states the gate's own latency instead of leaving you to find out. Governance that hides its own limits is not governance.
See it stop an action.
A short walkthrough: register an agent, certify it, watch the gate hold a refund above its authority — then verify the signed record without trusting the system that produced it.
Request a product demo