See every AI agent.
Control every action.
Prove every decision.
Discover AI agents and MCP servers across your stack. Map what they can reach, enforce runtime policies, and preserve verifiable evidence of every important action.
MCP · A2A · OpenTelemetry · BYOK · Verifiable Evidence
Watch one refund get stopped.
One agent, one MCP tool, one €8,250 refund — and the record it leaves behind.
-
1
An agent turns up
Invoice Agentowner: Finance Platform
Seen in your OpenTelemetry traces, then adopted — it now has an identity of its own.
-
2
Its connections are inventoried
Customer databaseStripe MCPSlack
Stripe MCP: 12 tools, each listed with what it does.
-
3
One permission matters more than the rest
stripe.refund — write · moves moneycustomer records — read
What it can do, and to what. No score, no colour-coding.
-
4
The agent tries to use it
REQUEST · agent invoice-agent · action stripe.refund · amount €8,250
-
5
Praesidia evaluates the call
Identity Valid
Permission Allowed
Policy Amount > €500
Approval Missing
-
6
The refund does not happen
BLOCKED
Refunds above €500 require human approval.
-
7
The decision leaves evidence
actorinvoice-agentactionstripe.refundamount8250 EURpolicyrefund-approval v3 (amount > 500)decisionBLOCKED — human approval requiredreasonHUMAN_APPROVAL_REQUIREDevidencesigned + hash-chained · VERIFIED
Enforcement applies when the organization runs in enforce mode. Human approval for sensitive tool calls is an Enterprise capability.
Find the AI agents you didn’t know were running.
Agents surface from your OpenTelemetry traces, from the API and SDK you register them with, and from strangers that try to talk to the ones you already run. Agents with no owner are listed too — the first question every review asks.
Every registered MCP server is inventoried tool by tool, and a tool definition that changes after you approved it is flagged as drift.
Invoice Agent
- Customer database
- Stripe MCP
- Slack
12 tools
stripe.refund
write · moves money
Invoice Agent
- Owner
- Finance Platform
- Connections
- 3
- Tool permissions
- stripe.refund — writecustomer records — read
- Rule
- stripe.refund — approval required above €500
Decide exactly what every agent can do.
Enforce identity, per-tool permissions, argument conditions and approval policies before a sensitive action runs — then quarantine, suspend or revoke an agent in one move.
Rules read the arguments, so the same tool can be allowed under €500 and held for a person above it. New policies run in observe mode first — the verdict is recorded without changing the outcome — until you turn enforcement on.
Enforcement applies in enforce mode; approvals are an Enterprise capability.
Know exactly what happened — and prove it.
Every governed call leaves an append-only, hash-chained record, signed under the default configuration, naming the actor, the action, the argument that mattered, the rule that matched, and the decision.
Export the records as a signed bundle, CSV or JSON, then check them without us: praesidia-verify is an independent offline verifier that re-walks every signature and the whole chain on your own machine.
Built for the stack you run and the auditors you answer to.
Praesidia sits on the connection between your agents and everything they reach, so nothing has to be rewritten to be governed — and the controls line up with the frameworks your compliance team already asks about.
Framework mappings support your review; they do not constitute certification or a guarantee of compliance.
Check us before you trust us: run the independent verifier, read the public changelog, browse the documentation, or open the integration catalog.
Design partners
We are taking on a small number of design partners running agents in production. You work directly with the team and have a say in what gets built next.
Secure your first production agent.
Create your workspace, connect one agent, and inspect the decisions it produces.