New

The agent governance library: control maps, field notes and practitioner guides.

Read the library

Solutions · Compliance control map

Governance evidence for what your agents do.

AI assurance frameworks converge on one demand: show that consequential automated actions followed an approved policy, and prove it afterwards. This page maps that demand to the artifacts Gleis produces at the tool-call boundary.

Decision boundary: Gleis evaluates each tool call against the policy your organisation approved and the evidence collected at the gateway. It does not determine legal rights, certify compliance, or replace legal review.

Framework mapping

What each regime expects, and what you get to show.

We do not certify, attest or advise. We produce the artifacts your assessors and counsel work from. The crosswalk ships marked unreviewed until your own owner reviews it; mapping documentation for a specific control set is prepared during a pilot.

EU AI ActArt. 12 record-keeping · Art. 14 human oversight

Every consequential tool call leaves a ledger entry naming the policy revision, the evidence and the decision. The review queue is a real oversight point with separation of duties, not a checkbox.

ISO/IEC 42001AI management system controls

Policy revisions move DRAFT to PROPOSED to APPROVED to PUBLISHED, signed at publication, with the author or proposer barred from approving their own change.

NIST AI RMFGovern · Map · Measure · Manage

Shadow observation measures what your agents actually attempt before a single call is blocked, which turns the Manage step into a decision backed by your own traffic.

DORAICT risk and third-party oversight

Third-party MCP servers become a governed dependency: which tools are visible, which actions are permitted, and an append-only record of every call that reached them.

GDPR and data minimizationArt. 5 principles · Art. 32 security

Arguments are redacted before classification and never persisted raw. The control plane never receives request payloads, and the ledger holds digests and evidence rather than content.

HIPAA and CCPA/CPRAAccess control and disclosure records

Resource sensitivity is part of every decision, so rules can bar a purpose category from a sensitivity class outright and the crosswalk can answer which entries evidence that control.

By team

One control surface, three different jobs.

Security and GRC

You are accountable for agent actions you cannot see.

Agent tool calls happen inside application processes, invisible to the SASE stack and the DLP console. Gleis gives you an inventory of what every agent attempted, by action type and resource sensitivity, and a per-decision record that maps to your control set.

  • Inventory of agents, tools and attempted action types
  • Append-only ledger entries you can sample and verify
  • Signed policy revisions instead of tribal knowledge
AI platform engineering

Every new agent reopens the same approval conversation.

One gateway serves every agent and every MCP server. The agent points at Gleis instead of the tool, nothing else in its configuration changes, and deterministic evaluation means the same policy behaves identically in test, observation and production.

  • No agent rewrite, only a config target change
  • Observation and enforcement from one policy object
  • Tool profiles keep the classifier off hot paths

By use case

Wherever an agent acts, the same checkpoint applies.

Coding agents and repositories

An approved coding agent can still delete a repository, rewrite history or push a secret. Destructive action types are their own classification, so they can be denied or routed to review without blocking ordinary reads and commits.

Agents over customer data

Reading a CRM record and exporting the whole table are different actions on the same tool. Resource sensitivity plus purpose category lets a rule permit the first and deny the second, with both recorded either way.

Payment and finance tools

Value-bearing actions deserve a human. Thresholds route a transfer above a limit to the review queue with separation of duties and an SLA, rather than trusting a model to be conservative.

Third-party MCP servers

A new MCP server is a new supplier with tool-level authority. Gleis filters tools/list to what policy could ever allow, so an agent cannot discover, let alone call, a tool you never approved.

Evidence artifacts

Six things an assessor can actually hold.

If a record is missing any of these, it is a log of events rather than evidence of a control.

Signed policy revision

Published under separation of duties and signed with Ed25519; the gateway verifies against a pinned key.

Deterministic decision

Replayable: the same request, evidence and revision produce byte-identical output.

Reason codes

Stable, aggregatable codes explaining why, suitable for metrics and for sampling.

Evidence records

Classification source, pinned model id and confidence, or the tool profile that made the model unnecessary.

Hash-chained entries

Append-only, in your database, written before the upstream call and verifiable as a chain.

Control crosswalk

Rule tags and reason codes mapped to controls, answering which entries evidence a given requirement.

Bring your control set

Map your agent controls in one working session.

We will walk your rules through the engine, show the ledger entries they produce, and be explicit about which of your requirements the product does not meet today.