Every consequential tool call leaves a ledger entry naming the policy revision, the evidence and the decision. The review queue is a real oversight point with separation of duties, not a checkbox.
Solutions · Compliance control map
Governance evidence for what your agents do.
AI assurance frameworks converge on one demand: show that consequential automated actions followed an approved policy, and prove it afterwards. This page maps that demand to the artifacts Gleis produces at the tool-call boundary.
Decision boundary: Gleis evaluates each tool call against the policy your organisation approved and the evidence collected at the gateway. It does not determine legal rights, certify compliance, or replace legal review.
Framework mapping
What each regime expects, and what you get to show.
We do not certify, attest or advise. We produce the artifacts your assessors and counsel work from. The crosswalk ships marked unreviewed until your own owner reviews it; mapping documentation for a specific control set is prepared during a pilot.
Policy revisions move DRAFT to PROPOSED to APPROVED to PUBLISHED, signed at publication, with the author or proposer barred from approving their own change.
Shadow observation measures what your agents actually attempt before a single call is blocked, which turns the Manage step into a decision backed by your own traffic.
Third-party MCP servers become a governed dependency: which tools are visible, which actions are permitted, and an append-only record of every call that reached them.
Arguments are redacted before classification and never persisted raw. The control plane never receives request payloads, and the ledger holds digests and evidence rather than content.
Resource sensitivity is part of every decision, so rules can bar a purpose category from a sensitivity class outright and the crosswalk can answer which entries evidence that control.
By team
One control surface, three different jobs.
You are accountable for agent actions you cannot see.
Agent tool calls happen inside application processes, invisible to the SASE stack and the DLP console. Gleis gives you an inventory of what every agent attempted, by action type and resource sensitivity, and a per-decision record that maps to your control set.
- Inventory of agents, tools and attempted action types
- Append-only ledger entries you can sample and verify
- Signed policy revisions instead of tribal knowledge
Nobody can say which data an agent touched, or why.
Resource sensitivity and purpose category are part of every decision, so a rule can bar a purpose from a sensitivity class outright. Arguments are redacted before classification and never persisted raw, and the control plane never receives request payloads at all.
- Purpose and sensitivity recorded per call
- Data stays inside your own tenant by construction
- Review queue gives ambiguity a named owner
Every new agent reopens the same approval conversation.
One gateway serves every agent and every MCP server. The agent points at Gleis instead of the tool, nothing else in its configuration changes, and deterministic evaluation means the same policy behaves identically in test, observation and production.
- No agent rewrite, only a config target change
- Observation and enforcement from one policy object
- Tool profiles keep the classifier off hot paths
By use case
Wherever an agent acts, the same checkpoint applies.
Coding agents and repositories
An approved coding agent can still delete a repository, rewrite history or push a secret. Destructive action types are their own classification, so they can be denied or routed to review without blocking ordinary reads and commits.
Agents over customer data
Reading a CRM record and exporting the whole table are different actions on the same tool. Resource sensitivity plus purpose category lets a rule permit the first and deny the second, with both recorded either way.
Payment and finance tools
Value-bearing actions deserve a human. Thresholds route a transfer above a limit to the review queue with separation of duties and an SLA, rather than trusting a model to be conservative.
Third-party MCP servers
A new MCP server is a new supplier with tool-level authority. Gleis filters tools/list to what policy could ever allow, so an agent cannot discover, let alone call, a tool you never approved.
Evidence artifacts
Six things an assessor can actually hold.
If a record is missing any of these, it is a log of events rather than evidence of a control.
Published under separation of duties and signed with Ed25519; the gateway verifies against a pinned key.
Replayable: the same request, evidence and revision produce byte-identical output.
Stable, aggregatable codes explaining why, suitable for metrics and for sampling.
Classification source, pinned model id and confidence, or the tool profile that made the model unnecessary.
Append-only, in your database, written before the upstream call and verifiable as a chain.
Rule tags and reason codes mapped to controls, answering which entries evidence a given requirement.
Bring your control set
Map your agent controls in one working session.
We will walk your rules through the engine, show the ledger entries they produce, and be explicit about which of your requirements the product does not meet today.