Governance
You see everything your AI does, and you stop it in real time
By default, everything passes. Your rules say what must not, for your teams and for external agents alike. Every decision is sealed: facing an auditor or the AI Act, you prove instead of declaring.
Decide
4 possible decisions
A rule does more than refuse. It lets through, stops the request, keeps a doubtful answer to itself, or lets through while flagging. You dose control without slowing your teams.
- Allow
The request proceeds. This is the default decision when no rule applies.
- Deny
The request is stopped outright: the question, action or hand-off it targets does not happen. For what must never be attempted.
- Withhold
The agent does its work, then its answer is checked before delivery. Not reliable, for instance claims your documents do not support? Contains data that must not leave? The user receives your message instead. To judge on the evidence, not on the question.
- Flag
The request goes through and the event is marked in the log, so someone takes a look.
Enforce
7 moments where a rule can act
You choose when the rule steps in, from the incoming question to the delivered answer. Block a question, deny access to a document, forbid an action, bound a hand-off, withhold an answer: every moment has its rule.
- 01 When the question arrives Turn entry
- 02 When a previous answer is reused Response cache
- 03 When the agent searches your documents Retrieval
- 04 When the agent acts in one of your tools Tool call
- 05 When the agent hands off to another agent Agent delegation
- 06 When the answer goes out to the user Turn exit
- 07 When an administrator changes a rule or a setting Administration
Redact
10 data classes, 6 placements
A detector recognizes sensitive data and replaces it before it leaves. In the question, the history, the context sent to the model, tool arguments, delegation and the answer.
What is detected
- Phone
- IBAN
- Social security number
- Payment card
- Postal address
- Postal code
- IP address
- API key
- Date of birth
Where redaction applies
- Query
- History
- Model context
- Tool arguments
- Delegation
- Response
Prove
Every action leaves a trace, kept 5 years
An auditor, a customer or the AI Act asks what your AI did? The log answers, line by line. Nobody can alter it afterward: every entry is sealed to the previous one. You export it in one click.
What the log tells
- Every question evaluated, and the decision taken
- Every refusal: document access, action in a tool, hand-off to another agent
- Every answer withheld, every piece of data redacted, every hidden text flagged
- Every rule created, changed or deleted, every export, every verification of the log
The 14 recorded actions
- Turn evaluated
- Query blocked
- Document access denied
- Tool call denied
- Delegation denied
- Response withheld
- Content redacted
- Hidden text flagged
- Engine failure
- Rule created
- Rule updated
- Rule deleted
- Chain verified
- Export generated
The proof
The audit log
Every action is recorded in a timestamped, tamper-evident, exportable log.
| Timestamp | Chain | Requester | Action | Decision |
|---|---|---|---|---|
| 2026-09-01 12:06:00 | Horizon - Home | conversa system · api | Content redacted | Flagged |
| 2026-09-01 12:06:00 | Horizon - Home | visitor_ visitor · widget | Request blocked | Denied |
| 2026-09-01 12:05:38 | Admin chain | Virginie Legrand user · backoffice | Rule created | Allowed |
Governance questions
- Does governance slow users down?
- Not by default: with no rule, everything passes. Rules apply at the precise moment they target, and only the requests concerned are refused, withheld or flagged.
- Are external agents covered?
- Yes. An external agent going through your MCP or A2A servers crosses the same enforcement points as your teams: tool call, delegation, output. Its decision is traced like the others. See the Orchestration page.
- How does an auditor verify the log?
- Every line is chained and timestamped. The chain verifies end to end, and the export delivers the lines with their integrity proof. Contractual retention is 5 years. The access log is described on the Security page.
- How much does the governance offer cost?
- On request, depending on scope and number of administrators. It includes everything the Enterprise AI Platform offer does and adds control. Compare both offers on the pricing page, then book a demo to scope it together.