Write it in plain words
“Refunds over €500 need finance sign-off.” “No PII to external tools.” Say it the way you would to a colleague.
Describe what agents may do in plain business language. TapPass compiles it into deterministic rules that fire the same way on every call, in milliseconds — one source of truth for every agent and every framework.
“Refunds over €500 need finance sign-off.” “No PII to external tools.” Say it the way you would to a colleague.
Each rule becomes deterministic logic that fires the same way every time — no model in the decision path, no surprises.
The check sits in the request path and adds a few milliseconds. Fast enough for every call, from every agent.
One rulebook for every agent and every framework — LangChain, CrewAI, MCP, your own. Write once; it holds everywhere.
Governance is intent-based: rules are written against what an agent is trying to do, not the endpoint it calls — so add or remove an MCP, or change a tool’s definition, and your policy still holds.
Which tools an agent may use, per team, project or user — or compose a virtual MCP with exactly the tools a job needs.
Least privilege by default: the tools a job needs, not the thirty-four the server exposes — with human approval on the risky ones.
Spend and token budgets, per agent and per team. Hold or block the moment an agent runs past its envelope.
When agents may act. Deploys outside the change window, actions out of hours — held for a person.
PII redacted in transit, EU data residency enforced, bulk exports held for a DPO. Raw data never leaves your region.
The order and steps an agent may follow — govern what it is trying to do, not just the endpoint it called.
A practical risk assessment framework for evaluating AI agents before production.
Everyone races to give AI agents more power.
AI agents deploy faster than governance can follow.
Watch first, enforce when you’re ready — live in your EU region in two weeks, on the stack you already run.