ZERO-TRUST CONTROL PLANE FOR AI AGENTS

See every AI agent.
Control every action.
Prove every decision.

Discover AI agents and MCP servers across your stack. Map what they can reach, enforce runtime policies, and preserve verifiable evidence of every important action.

MCP · A2A · OpenTelemetry · BYOK · Verifiable Evidence

Apps
Agents
MCP Servers
Praesidia Praesidia
Authentication
Guardrails
Policies
Apps
Agents
MCP Servers
60-second demo

Watch one refund get stopped.

One agent, one MCP tool, one €8,250 refund — and the record it leaves behind.

Illustrative scenario — real rule shape
  1. 1

    An agent turns up

    Invoice Agentowner: Finance Platform

    Seen in your OpenTelemetry traces, then adopted — it now has an identity of its own.

  2. 2

    Its connections are inventoried

    Customer databaseStripe MCPSlack

    Stripe MCP: 12 tools, each listed with what it does.

  3. 3

    One permission matters more than the rest

    stripe.refund — write · moves moneycustomer records — read

    What it can do, and to what. No score, no colour-coding.

  4. 4

    The agent tries to use it

    REQUEST · agent invoice-agent · action stripe.refund · amount €8,250

  5. 5

    Praesidia evaluates the call

    Identity Valid

    Permission Allowed

    Policy Amount > €500

    Approval Missing

  6. 6

    The refund does not happen

    BLOCKED

    Refunds above €500 require human approval.

  7. 7

    The decision leaves evidence

    actorinvoice-agent
    actionstripe.refund
    amount8250 EUR
    policyrefund-approval v3 (amount > 500)
    decisionBLOCKED — human approval required
    reasonHUMAN_APPROVAL_REQUIRED
    evidencesigned + hash-chained · VERIFIED

    Verify it yourself

Enforcement applies when the organization runs in enforce mode. Human approval for sensitive tool calls is an Enterprise capability.

Approvals queue with one pending request: an Agent Tool Step-Up raised by the Invoice Agent, described as "Approve refund_payment for agent Invoice Agent", status Pending, expiring 21 September 2026, with approve and reject actions on the row.
Sixty seconds in, this is the part a person owns: the refund the agent was not allowed to approve for itself.
Discover

Find the AI agents you didn’t know were running.

Agents surface from your OpenTelemetry traces, from the API and SDK you register them with, and from strangers that try to talk to the ones you already run. Agents with no owner are listed too — the first question every review asks.

Every registered MCP server is inventoried tool by tool, and a tool definition that changes after you approved it is flagged as drift.

Explore Agent Discovery

Illustrative

Invoice Agent

  • Customer database
  • Stripe MCP
  • Slack

12 tools

stripe.refund

write · moves money

Invoice Agent

Owner
Finance Platform
Connections
3
Tool permissions
stripe.refund — writecustomer records — read
Rule
stripe.refund — approval required above €500
Control

Decide exactly what every agent can do.

Enforce identity, per-tool permissions, argument conditions and approval policies before a sensitive action runs — then quarantine, suspend or revoke an agent in one move.

Rules read the arguments, so the same tool can be allowed under €500 and held for a person above it. New policies run in observe mode first — the verdict is recorded without changing the outcome — until you turn enforcement on.

Explore Runtime Security

One tool call, evaluated
REQUESTagent invoice-agent · action stripe.refund · amount €8,250
1Identity VALID — short-lived capability token
2Tool permitted for this connection
3Rule matched: amount > 500
BLOCKEDhuman approval required

Enforcement applies in enforce mode; approvals are an Enterprise capability.

Prove

Know exactly what happened — and prove it.

Every governed call leaves an append-only, hash-chained record, signed under the default configuration, naming the actor, the action, the argument that mattered, the rule that matched, and the decision.

Export the records as a signed bundle, CSV or JSON, then check them without us: praesidia-verify is an independent offline verifier that re-walks every signature and the whole chain on your own machine.

Explore Audit & Evidence

Decision record
Illustrative — the fields a stopped refund leaves behind
actorinvoice-agent
actionstripe.refund
policyrefund-approval v3 (amount > 500)
decisionBLOCKED — human approval required
signature VERIFIED
Verified offline, against the previous record’s hash.
Enterprise trust

Built for the stack you run and the auditors you answer to.

Praesidia sits on the connection between your agents and everything they reach, so nothing has to be rewritten to be governed — and the controls line up with the frameworks your compliance team already asks about.

OpenAI Claude LangGraph MCP A2A OpenTelemetry SSO — SAML & OIDC (Enterprise) SCIM (Enterprise) SIEM export (Advanced)
SOC 2 GDPR EU AI Act ISO/IEC 42001 NIST AI RMF OWASP LLM Top 10 OWASP Agentic AI Top 10

Framework mappings support your review; they do not constitute certification or a guarantee of compliance.

Check us before you trust us: run the independent verifier, read the public changelog, browse the documentation, or open the integration catalog.

Review the Trust Center

Proud member of

NVIDIA Inception Program

Design partners

We are taking on a small number of design partners running agents in production. You work directly with the team and have a say in what gets built next.

Apply to become a design partner

Secure your first production agent.

Create your workspace, connect one agent, and inspect the decisions it produces.