Agents on operational systems, under control.
Where an agent’s action can move something physical, the margin for error is zero. TapPass runs airgapped, keeps agents to the narrowest remit, and puts a person in the loop before anything consequential happens.
In OT, a wrong call isn’t a bad log line — it’s downtime, or worse.
Operational systems don’t forgive ungoverned access. TapPass treats every agent action as something to be proven safe before it runs.
Contained by design.
Airgapped deployment
No outbound internet required — governance activates through a local licence server.
Human on the consequential
Physical or high-impact actions stop for an authorised person, with strong-auth approval.
Narrow remit
Least privilege, always. An agent can touch exactly the systems its job requires, and no more.
Keep reading
Sandboxing AI Agents: Why Isolation Alone Is Not Enough
Kernel sandboxes like Landlock and Seatbelt can lock down an AI agent process.
Zero Trust for AI Agents: What Least Privilege Actually Means
Least privilege for humans is well understood.
Securing AI Agents in Regulated Industries
When a bad AI decision has a cost, a patient outcome, or legal liability, security is not optional.