Deny by default
Each tool call from an enrolled agent carries a short-lived, signed intent token. A call outside the agent's policy is refused. A call that breaks a hard rule also removes the agent's authority until an operator restores it.
Sentri
Sentri decides what each enrolled AI agent may do, holds sensitive actions for a person, and keeps a tamper-evident record of its decisions.
Everything in this section is running in production.
Each tool call from an enrolled agent carries a short-lived, signed intent token. A call outside the agent's policy is refused. A call that breaks a hard rule also removes the agent's authority until an operator restores it.
Policies describe who may act, on what, when, where, why and how. Sensitive actions are held for an operator to approve or reject from the console, with a reason.
Contain an agent, release it, or revoke its authority. Console access is role-based (viewer, operator, admin), and sign-in requires an authenticator code.
The gateway and its companion services keep hash-chained records. Verification names the exact row where a record was changed.
For any agent: where it was first seen, the host it runs on, what it was stopped from doing, what it could reach, and its state now. Anything not recorded is labeled as a gap, not filled in.
On an enrolled host, an attempt to go around the gateway is cut off on the host and raised as a critical alert in the console and by email.
Built and tested in our lower environment. Not yet running for customers.
Agent actions tied to the named person they act for. Actions with no person attached are refused unless policy marks them as unattended.
Enrolled hosts report the AI runtimes running on them, and an operator registers or blocks each finding.
Periodic review of what each agent may do against what it actually used, with keep, narrow or revoke decisions on the record.
Behavioral baselines for each agent that propose a review when behavior drifts.
About EYEQTalk with the people who build and run Cipherion, in Dallas.