Action Governance
Control the action before it becomes an outcome.
Every AI agent action that touches money, infrastructure, or sensitive data is evaluated by Guard before it executes. Allow, approve, or block — with a signed record of why.
Three stories. One engine.
The same Guard policy engine handles the full range of consequential business actions. The decision, the rule, and the reason are the same data structure across all three.
Refund over the cap
A support agent attempts to process a $840 refund for customer C-8911. The refund-cap policy blocks it. A smaller refund ($120) on the same account proceeds immediately.
Production deployment outside change window
A deploy agent attempts to push to production at 14:32 UTC — outside the approved change window. Guard routes to Slack for human approval rather than blocking outright.
Secret read in production environment
An agent attempts to read a production secret during a scheduled task. Guard blocks the action — secret access from automated agents requires an explicit exemption.
Policy at the action, not at the report.
Action governance is not an audit log you review after the fact. Guard runs at the moment the agent calls the action — before money moves, before the deployment lands, before the secret is read. The decision is made then, with a receipt that proves it.
