The person the agent was acting for, the agent itself, and the chain between them, including when nobody was at the keyboard.
Your agents acted last quarter. Can you prove what they did?
AgentGate is the evidence layer for AI agents that take action. It records who allowed an action, what happened, and under which policy, and it is built so that record holds up in a security review or an audit. In private beta. Canadian-resident. From the team at JUTEQ Governance.
Three questions, asked after the fact, that a log file cannot answer.
The action as it was attempted, what it touched, and what it was permitted to touch. Not a summary written afterwards.
The policy in force at that moment, the version, and the decision it produced, so the same question gets the same answer a year later.
The controls most teams already own each stop short of the action itself.
Sees the tool calls that pass through it. Does not see the shell command, the file write, or the commit.
Contains the blast radius. Does not decide whether the action should have happened.
Built for a person moving a file, not an agent composing one out of three queries.
A human in the loop works when a human is there. Your autonomous agents run when nobody is, so the prompt either stalls the job or gets switched off.
The control point moved to the act. Most stacks are still watching the old one.
Cloud Security Alliance, Autonomous but Not Controlled, Jan 2026, n=418
Most organizations have already seen it happen. When an agent steps outside its scope, roughly one in ten can stop it in the moment. The rest find out afterwards, and then have to work out what it did.
Others tell you what your agents were supposed to do. We record what they actually did, and stop what they should not have.
The same blocked action, as a log line and as a record.
agent=agent‑7 tool=sql_query exit=1
Tells you a tool ran and failed. Not who stood behind it, what it tried to reach, or why it was stopped.
- sealed
- 2026‑09‑03T02:14:07.339Z
- on behalf of
- a.okafor@bank.example
- agent
- ops‑reconcile/agent‑7, autonomous
- attempted
- export from prod‑pg‑01, customer.accounts
- decision
- denied · production export, no human present
- policy
- v14, prod‑data‑export
- chain
- prev 9c1f…a07 → this 4be2…d11
- content
- kept on the device
Specimen record. Illustrative; the final field set is being settled with early customers.
Three things AgentGate holds.
The record
Each governed action produces a chained entry, exportable to the tools your security and audit teams already use, and mapped to the requirements they are assessed against. Designed to support an audit or security review, and honest about what it does and does not cover.
The decision, at the act
The decision belongs at the moment of action, where the action runs. That includes the agent your own team built, working at 3am with nobody there to approve anything.
Canadian-resident
The content an agent touches stays where the agent runs. What leaves is the record of the decision, held in Canada or entirely inside your own environment, with the evidence mapped to OSFI E‑23, PIPEDA and Law 25.
In private beta today for the autonomous agents your own teams have built and run in production, in regulated organizations. Coding agents on developer machines and in pipelines come next. Everything beyond that is roadmap, not a promise.
OSFI E‑23 takes effect for federally regulated financial institutions on 1 May 2027. Whatever you will be able to show by then, you are building it this year.
Request access
AgentGate is in private beta. We are deploying with a limited number of organizations ahead of general availability, starting with those who have a question to answer now. Tell us what you would need to prove, and to whom.
- A person reads every request. If the beta is a fit for you, you will hear from us within a few days and we can talk about deploying.
- Otherwise we write when there is something for you to try, and not before.
Your developers are on coding agents too? The JUTEQ Governance engagement brings those under your identity provider, with a first record, in four to eight weeks, on what your vendors already ship. See the engagement
JUTEQ Governance. Approve a rollout you can stand behind, govern agents when they act, and keep the evidence.
The practice behind AgentGate works with security, platform and risk teams in regulated organizations, from initial assessment through governed action and review-ready records.