Governance

You see everything your AI does, and you stop it in real time

By default, everything passes. Your rules say what must not, for your teams and for external agents alike. Every decision is sealed: facing an auditor or the AI Act, you prove instead of declaring.

Decide

4 possible decisions

A rule does more than refuse. It lets through, stops the request, keeps a doubtful answer to itself, or lets through while flagging. You dose control without slowing your teams.

  • Allow

    The request proceeds. This is the default decision when no rule applies.

  • Deny

    The request is stopped outright: the question, action or hand-off it targets does not happen. For what must never be attempted.

  • Withhold

    The agent does its work, then its answer is checked before delivery. Not reliable, for instance claims your documents do not support? Contains data that must not leave? The user receives your message instead. To judge on the evidence, not on the question.

  • Flag

    The request goes through and the event is marked in the log, so someone takes a look.

Enforce

7 moments where a rule can act

You choose when the rule steps in, from the incoming question to the delivered answer. Block a question, deny access to a document, forbid an action, bound a hand-off, withhold an answer: every moment has its rule.

  1. 01 When the question arrives
  2. 02 When a previous answer is reused
  3. 03 When the agent searches your documents
  4. 04 When the agent acts in one of your tools
  5. 05 When the agent hands off to another agent
  6. 06 When the answer goes out to the user
  7. 07 When an administrator changes a rule or a setting

Redact

10 data classes, 6 placements

A detector recognizes sensitive data and replaces it before it leaves. In the question, the history, the context sent to the model, tool arguments, delegation and the answer.

What is detected

  • Email
  • Phone
  • IBAN
  • Social security number
  • Payment card
  • Postal address
  • Postal code
  • IP address
  • API key
  • Date of birth

Where redaction applies

  1. Query
  2. History
  3. Model context
  4. Tool arguments
  5. Delegation
  6. Response

Prove

Every action leaves a trace, kept 5 years

An auditor, a customer or the AI Act asks what your AI did? The log answers, line by line. Nobody can alter it afterward: every entry is sealed to the previous one. You export it in one click.

What the log tells

  • Every question evaluated, and the decision taken
  • Every refusal: document access, action in a tool, hand-off to another agent
  • Every answer withheld, every piece of data redacted, every hidden text flagged
  • Every rule created, changed or deleted, every export, every verification of the log

The 14 recorded actions

  • Turn evaluated
  • Query blocked
  • Document access denied
  • Tool call denied
  • Delegation denied
  • Response withheld
  • Content redacted
  • Hidden text flagged
  • Engine failure
  • Rule created
  • Rule updated
  • Rule deleted
  • Chain verified
  • Export generated

The proof

The audit log

Every action is recorded in a timestamped, tamper-evident, exportable log.

TimestampChainRequesterActionDecision
2026-09-01 12:06:00 Horizon - Home
conversa
system · api
Content redacted Flagged
2026-09-01 12:06:00 Horizon - Home
visitor_
visitor · widget
Request blocked Denied
2026-09-01 12:05:38 Admin chain
Virginie Legrand
user · backoffice
Rule created Allowed

Governance questions

Does governance slow users down?
Not by default: with no rule, everything passes. Rules apply at the precise moment they target, and only the requests concerned are refused, withheld or flagged.
Are external agents covered?
Yes. An external agent going through your MCP or A2A servers crosses the same enforcement points as your teams: tool call, delegation, output. Its decision is traced like the others. See the Orchestration page.
How does an auditor verify the log?
Every line is chained and timestamped. The chain verifies end to end, and the export delivers the lines with their integrity proof. Contractual retention is 5 years. The access log is described on the Security page.
How much does the governance offer cost?
On request, depending on scope and number of administrators. It includes everything the Enterprise AI Platform offer does and adds control. Compare both offers on the offers page, then book a demo to scope it together.

With governance : pricing.governedprice

Scope and administrators to be set together

Book a demo