Who allowed it?
The person the agent acted for, and the agent, even when nobody was at the keyboard.
AgentGate is an audit trail and decision point for the AI agents your teams built. It records who allowed an action, what the agent did, and under which policy. In private beta. Runs inside your environment.
The demo is a controlled scenario: an agent tries an action outside its task, and you see the decision and the record.
The person the agent acted for, and the agent, even when nobody was at the keyboard.
The action as attempted, and what it touched.
The policy and version in force at that moment.
Cloud Security Alliance, Autonomous but Not Controlled, Jan 2026, n=418
We record what your agents actually did, and decide at the moment of action whether it goes ahead.
A tool ran and failed. Nothing about who, what, or why.
Illustrative specimen.
Shows if it has been altered, and your auditor can verify it without relying on us.
Made where the action runs, including for agents working with nobody watching.
The content your agents touch stays where they run. Deploy it in your own environment, or use our hosted service in Canada.
The record is built for the questions auditors and regulators ask. Our first mapping is to Canada's OSFI E-23.
Record-keeping rules are arriving. Canada's OSFI E-23 applies from 1 May 2027, and the EU AI Act's automatic logging requirement from 2 December 2027 for most high-risk systems.
Agents your own teams built and run in production. Coding agents come next.
AgentGate is designed for the agents your teams built, whichever environment they run in, with a record your auditor can check without trusting us.
The record and the decision point are in place today. We are still establishing, with our beta customers, how far blocking can go without stopping legitimate work, and how consistently one decision holds across cloud, on-premises and hybrid at once. We tell you this up front, and show you what is covered in your environment before you deploy.
The content your agents touch stays where they run. The record stays in your environment, or in our hosted service in Canada. You choose.
About six weeks to your first agents governed, with blocking for the action types we agree. You provide an owner, access, and a few hours a week from security, risk and platform.
A fixed fee, agreed before we start.
You keep what you deployed. General availability terms are agreed when you join.
Yes, before you commit to anything.
We are deploying with a limited number of organizations, starting with those who have something to prove now.
Developers on coding agents too? See the identity rollout.