THE GOVERNANCE LAYER FOR AI AGENTS

Put AI agents to work.Before you trust them.

Let agents do the work. Let your policies decide what they can do. Sensitive actions require clearance, and every decision traces back to an accountable human.

GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC.

See the approval flow
AN ACTION, WITH ACCOUNTABILITY
AI agentProposes an action
GembaOS
  1. 01Policy check
  2. 02Human sign-off
  3. 03Single-use clearance
Your production systems

An agent proposes. Your organization authorizes.

Your infrastructureYour approval policiesYour choice of model

01 / CORE PILLARS

Intelligence is flexible. Authority is defined.

Three controls between an agent’s intent and an action in production.

01

One action. One clearance.

Keep credentials out of context.

Agents do not hold long-lived business-system keys. An approved request receives a single-use clearance token bound to its exact parameters. Change the parameters, and the clearance no longer applies.

Clearance Token · argsHash
02

Every action has an owner.

Delegation without extra privilege.

Agents act on behalf of a named employee, within that employee’s authority. High-risk actions follow your approval chain. Decision records preserve who approved what, and why.

On-Behalf-Of · Signature Chain
03

Change models. Keep policy.

Your rules outlast a model version.

Use self-hosted or cloud models. Policy checks stay outside the model, while shadow replay and golden regression tests help verify behavior before a model change reaches production.

Model Agnostic · Policy Replay

02 / IN PRACTICE

Start with a real workflow.

Give agents useful work, with a clear boundary around every sensitive action.

A production change, without an open-ended key.

The challenge

Agents can help investigate incidents. Unrestricted production access is a different decision.

With GembaOS

The agent investigates in a restricted sandbox and drafts a ChangeSet. Privileged actions pass through the gateway and enter the change approval process.

The control point
  1. 01
    RequestDraft ChangeSet
  2. 02
    ReviewChange / CAB review
  3. 03
    AuthorizeIssue clearance
  4. 04
    ExecuteProduction adapter

The human owner reviews the change. A parameter-bound clearance permits the production adapter to execute the approved action once.

See it in the console

INSIDE GEMBAOS

From request to a traceable decision.

One captured flow per scenario, from the real console. Pick a flow and follow it through the screens: the pending desk, the human signature, the execution, the audit replay.

A refund request, start to finish.

Follow one refund request through the whole approval flow: the pending desk, the human signature, the executed refund and the audit replay.

GembaOS approval desk showing a sample refund request awaiting the human supervisor View full-size capture
01

Three agent stamps are in place. The human supervisor sees the machine-verified facts, the amount and the reasons before deciding.

Actual console capture · isolated demo data · stub model · mock passkey

03 / SECURITY & DEPLOYMENT

A boundary you can inspect.

Concrete controls. Deployed where your business runs.

01

Inside your infrastructure

A single binary, deployed on-premises or in a private VPC. Use self-hosted models when inference must also remain within your network.

PRIVATE DEPLOYMENT
02

Secrets stay at the gateway

Business-system credentials are held by the gateway and adapters, outside the agent’s prompt context.

CREDENTIAL ISOLATION
03

Decisions you can replay

Re-evaluate recorded policy decisions and inspect hash-chained audit events to understand why an action passed or stopped.

DETERMINISTIC POLICY
04

Adversarial tests, repeatable

Review test cases covering prompt injection, parameter tampering and privilege escalation with your technical team.

RED-TEAM VALIDATION

Deployment boundaries depend on the models and integrations you configure. Review the architecture and test evidence for your environment.

04 / DESIGN PARTNER PROGRAM

One workflow. Six weeks to prove it.

Apply as a design partner

Shape the governance runtime with our architects. The program is designed for five enterprise partners per quarter, with focused adapter support and a path from shadow mode to controlled execution.

Consultation is free. Pilot scope and fees are agreed individually; eligible partners can agree a 24-month production price lock.

Program details
  1. WEEKS 01—02

    Define the boundary

    Select a workflow, connect your directory and define delegated authority.

  2. WEEKS 03—04

    Connect & verify

    Integrate target systems. Run golden regression and adversarial tests.

  3. WEEK 05

    Observe in shadow mode

    Agents draft work. Designated human owners review every proposed action.

  4. WEEK 06

    Release in tiers

    Enable agreed low-risk actions and review weekly audit evidence.

05 / FAQ

Questions before you start.

Integration, operations and the people involved.

All questions
01Can we start before our SOPs are fully documented?

Yes. The Gap Register records missing procedures or ambiguous boundaries. Agents can draft proposed instructions; a responsible human reviews and approves them before they become operational policy.

02Do we need to rebuild our LangGraph or Dify agents?

Gateway Mode supports bringing your own agents. Route supported tool calls or MCP connections through GembaOS. We assess your tool interfaces and adapter requirements during the architecture consultation.

03Will approvals slow down everyday operations?

Low-risk reads and operations within configured limits can pass automatically. Only actions that require approval under your policy go to a human, such as above-limit refunds or privileged production changes.

04Can our data and models stay on our own network?

GembaOS can run on-premises or in a private VPC with self-hosted models. Cloud models and external integrations create their own data paths; configure these deliberately, including gateway-level field scrubbing where appropriate.

05How much time does our team need for the six-week pilot?

Our architects work alongside your team. Plan for an IT or DevOps liaison during setup and named business approvers during shadow mode. The exact effort depends on your integrations and is agreed when scoping the pilot.

LET’S START WITH YOUR WORKFLOW

Bring your constraints. We’ll map the control points.

A free, 30-minute architecture conversation about your systems, your approval process and where agents could help.

We reply by email.

I’m interested in

Required fields are marked *.

About your information

Your entries are sent to Lux Mentis Limited so that we can reply. They are stored on our own server and forwarded to our team by email. Nothing else is done with them. Read the privacy notice