Refund requires
human approval.
support.issue_refund Independent AI execution governance
Assess agents before release. In production, govern model access, MCP tool calls and agent actions with policy enforcement, human approvals and compliance evidence across supported integrations.
support.issue_refund Write policy once. Enforce it everywhere.
Native controls where a platform has them. Ours where it doesn’t.
See what each surface can carry outControl model access, inspect inputs and outputs, and apply data policies.
Explore model governanceReview MCP servers, inspect tool-call arguments, and authorize invocations.
Explore MCP governanceAllow, deny or hold refunds, data transfers and production changes for authorized review.
Explore action governanceAvailable controls depend on the integration and enforcement path.
Identity, security and tool permission can all pass an action. GovernorAI decides whether this one should proceed.

The interactive example works offline. Watch the published walkthrough on SentinelLayer, or return to the example.
Open published recordingpolicy refunds, version 14 (signed)
allow_support_tools support.issue_refund is permitted
original_destination_only any other destination is denied
hold_high_value_refunds over $10,000 waits for finance-approver;
deny where the path cannot hold
Deny wins over hold. Hold wins over allow.Digest sha256:…
Held before dispatch.
An agent version is assessed against the policy it will run under before it ships. Once it is live, that same policy decides each consequential action. See assurance
One policy model and one evidence schema at every supported enforcement point. Each integration states what it can enforce.
The refund rule, enforced in three places
All three share one evidence schema and policy version.
Capabilities differ by surface, and event-based controls are not inline.
View capability matrixAgents chain dozens of tool calls, so governance overhead compounds. GovernorAI signs approved policy once and pushes it to a sidecar beside each agent.
When policy changes
Decisions name the active policy digest sha256:…
When an agent acts
In-process Go benchmark (Apple M4), excluding transport, serialization and audit write; about 1.6 µs for a large rule set. On supported paths, an unreachable control plane fails closed. Benchmark method
The policy revision your release gate assessed is the one that decides each action and the one named in every record. When the policy changes, the history shows which revision governed each action.
asset→assessed version→policy revision→decision→human response→evidence
Evaluate the action before it takes effect. Allow it, deny it, or hold it for an authorized approver where the integration supports that outcome.
Outcomes vary by enforcement point.
Explore runtime enforcement“Can your evidence prove that the policy that passed your pre-production gate is the policy that made this decision?”
Each event carries the hash of the one before it.
Each event names the policy digest that decided it and chains to the one before. Edit one, and verification fails.
Partial coverage. These records support assessment; additional organizational evidence is required.
Controls, decisions and evidence come from the same system, so a review starts from records instead of reconstruction.
Connect governance requirements to the policies and controls your teams assess.
Apply policy and authorized review at supported enforcement points, tied to the policy revision.
Inspect decision records, policy references and human responses for control reviews and audits.
Mapped to eight frameworks, including SOC 2, NIST AI RMF and ISO/IEC 42001, with every control marked automatic, partial or manual attestation. Evidence supports an assessment; it does not confer certification. How evidence is produced
Begin with one action that matters to your business. Define the control, check integration fit, and agree what success looks like.
For your team: Security, GRC, Platform and AI engineering
Former President of Software & Platform Engineering at Viasat (850+ engineers) and its Executive Sponsor for AI Governance. Dual CCIE (Security), CISSP, Cisco Press author.
Leads platform engineering, SDKs and developer experience, runtime systems and integrations.
In 30 minutes we’ll map the workflow, check integration fit and agree whether a six-week evaluation makes sense.
We reply within 48 hours.
Design-partner terms
Production is priced separately.