Let AI agents work.
Keep people in control.

The governance layer for enterprise AI agents.
Every identity owned. Every decision governed. Every action accounted for.

Your infrastructure. Your identities. Your authority.

Workspace/Approvals
Illustrative workspace⌘ K

Approval queue

4All managers
Needs reviewRecent decisions
Awaiting a human4
Earlier today4
APR 2406Send weekly summaryApprovedMC1h
×APR 2405Export exceeds budgetRefusedPR1h
APR 2404Deploy reporting serviceApprovedJL2h
APR 2403Export pipeline reportApprovedPR3h
APR 2410 · Analytics

Export customer records

Read and export 2,400 customer records from Salesforce through crm.contacts.export.

Status
Awaiting approval
Agent
Aanalytics_01
Manager
PRPriya Raman
Capability
crm.contacts.export
Budget
$10.00 of $50.00
Registered identity
Capability in scope
Human approval required

One action. One named approver.

Built to run on the stack you already trust

Microsoft Entra Okta Google Workspace Slack HashiCorp Vault Splunk

Enterprise autonomy.
Not a leap of faith.

Agents can already reach your applications and your data. AAES puts identity, human authority, and enforceable boundaries in front of the actions that matter.

Identity & approvals

Behind every agent,
a person accountable.

Every agent has a registered identity and a named human manager.
Delete, send, pay, deploy, and approve always reach a person.

Learn more
Authority, by designIllustrative product preview
PR
Priya RamanData Operations Manager
named human manager
A1
analytics_01Analytics agent
Registered
crm.contacts.readcrm.contacts.exportreports.read
Only permitted capabilities are visible
Approval requestAPR 2410

A data export needs your approval

analytics_01 requests permission to export customer records.

Requested action
crm.contacts.export
Data
2,400 records
Approver
PRPriya Raman
Scope
This action only
Identity and permissions checked

Try a decision. This is an illustrative interaction.

An identity, not a shared key

Know which agent is acting and which human is responsible.

Permission shapes discovery

Agents only see what they are allowed. For anything else, they request human access.

A person at the decision

Consequential actions need a human. An agent cannot approve itself.

Budgets & policy

A spending limit.
Not a spending alert.

Budgets are reserved when the decision is made.
Over the ceiling, the call never leaves. The refusal becomes part of the record.

Learn more
Control before executionIllustrative product preview
Budgets/Analytics operations
Current period
Reserved at decision time
$10.00of $50.00
Reserved$40.00 available
MONTUEWEDTHUFRISATSUN
$45.00 export refused. Requested amount exceeds the $40.00 remaining.
No call dispatched
AgentReservedCeilingUtilizationDecision
analytics_01$10.00$50.00
Within budget
support_02$3.20$20.00
Within budget
data_04$44.50$45.00
Near ceiling
research_07$12.00$30.00
Within budget

Reserve, then act

Account for the spend before the action, not after the bill arrives.

A ceiling that holds

An over budget request is refused before a call can leave AAES.

Even a no has a record

Refusals stay visible, alongside the decisions that went through.

How it works

One action.
A complete chain of trust.

From an agent's request to a sealed record. The controls happen on the path to execution, not in a review after the fact.

EXAMPLE · EXPORT 2,400 RECORDS01 / 06

An intent, not a credential.

The agent names the capability it wants to use. The destination and credential come from the registration, never from the agent.

Actoranalytics_01
Capabilitycrm.contacts.export
Requested data2,400 records
Your existing stack

A governance layer.
Not a replacement stack.

Keep your identity provider, collaboration tools, vault, and monitoring. AAES works with the infrastructure your enterprise already runs.

Native adapter

Microsoft Entra

Identity & directory

Native adapter

Okta

Identity & directory

Native adapter

Google Workspace

Directory & collaboration

Native adapter

Slack

Enterprise communication

Native adapter

HashiCorp Vault

Secrets & key custody

Native adapter

Splunk

Evidence & monitoring

65Native adapters
3Interface only
17Named gaps

Native means an adapter exists and is tested against a local server speaking the vendor's API format. None has been verified against a live vendor tenant. Interface only is not a shipped vendor adapter.

Coverage is explicit. Unsupported means unsupported.Explore the coverage matrix
Deployment

Your boundary.
Your control.

From a single VM to an isolated enterprise environment.
Choose where the system runs and where your data and keys live.

SINGLE VMCUSTOMER OPERATED
YOUR INFRASTRUCTURE
AAES · Docker Compose
Local data volume
Your keys or vault

Start with a single VM.

Run the daemon, ledger anchor, and operator CLI with Docker Compose. Your records live on your host. You create and control the keys.

docker compose up
Sealed records

Evidence you can verify.
Without trusting us.

One sealed, hash chained record per action.
Verify it offline against a key AAES does not hold. No dashboard required.

Explore the evidence
From decision to independent verificationIllustrative example
Action record #4182Sealed
Registered actoranalytics_01
Actioncrm.contacts.export · 2,400 records
Human approverPriya Raman
Policyallow_export · R3
Budget reserved$10.00 / $50.00
EnforcementEnforced
#4180e94d…f7c0
#418177b1…03aa
#41823f9c…8e21
SHA256 · 3f9ca41d…8e21Hash chained
Offline verifier · example output
Verify exported record bundle
Record integrityPASS
Hash chainPASS
Signature checkPASS
Network calls0
✓ Record #4182 verified
Verification key held outside AAES.

What the record establishes

The recorded authorization, scope, named approver, and integrity of the sealed bytes. The evidence travels with you, not with a subscription.

What it does not establish

Work outside AAES is invisible. A confirmed call does not prove the intended outcome, and a source label does not authenticate external evidence. Observed is never presented as enforced.

A few clear answers

Good questions.
Honest answers.

Have something else in mind?
Talk to us

What is AAES, exactly?

AAES stands for Autonomous Agentic Enterprise Systems. It is a governance layer for enterprise AI agents, connecting registered identities and human managers to permissions, approvals, budgets, and sealed action records.

Does this replace our identity provider?

No. AAES can govern your agents while people remain in your existing identity provider. It works with Microsoft Entra, Okta, and Google Workspace. You do not need a new directory to get started.

Which agents does it work with?

An agent that can call an API or MCP can integrate with AAES. The system sits on the action path, not inside a particular agent framework. The agent only discovers the capabilities it is entitled to use.

Can we observe before we enforce?

Yes. A capability can be registered as observed, with every record labeled accordingly. AAES cannot stop calls while the agent retains its own direct credentials. Enforcement requires moving credential authority and blocking the agent's direct path to the vendor.

Are the integrations verified in production?

Not yet. The coverage matrix lists 65 native adapters, 3 interface only entries, and 17 named gaps. Native adapters are tested against local servers speaking vendor API formats, not live vendor tenants. No live verification or production adoption is claimed.

Is an AAES hosted deployment available?

No. The AAES hosted cell is a planned deployment mode, gated on SOC 2 Type I. AAES has no SOC 2 report today. Single VM, Kubernetes, and air gapped or on premises deployment modes run on customer infrastructure.

What happens if AAES goes away?

You retain the exported records and verifier. Verification works offline against a key AAES does not hold. No external witness or timestamp authority is wired yet, and the tools make that limitation explicit.

AAES

Give your agents room to work.
And boundaries you can trust.

Thirty minutes. One governed action.
A human approval and a sealed record you can take with you.

Pre pilot. Built for scrutiny, not overclaiming.