Agent & Skill risk scores
Composite risk per agent, trust score per tool; cross a threshold and the Kill Switch is one click away.
AIControls governs every AI agent and model call in your Kubernetes clusters — enforced by policy, logged for audit.
AIControls extends Enterprise Kyverno's Admission control with three additional control points for AI workloads and agents — Pipeline, Gateway, and Runtime — so an agent is governed before it ships, on every model and tool call it makes, and while it runs.
One engine · One audit log
Requests are checked for identity and privacy before they go out. Responses are checked for cost, security, and policy before they come back — with PII redacted in both directions and a human gated on anything high-risk.
Not a log to correlate by hand. A graph of who delegated to which agent, every tool it called, every resource it touched — with the policy verdict on each one.
Governance enforced while the agent is acting, not policy reviewed after the fact. Real screens from AIControls running on real clusters — not hypothetical failure modes.
AIControls builds a live inventory of every server your agents actually talk to — not just the ones your team knows about.
Most content-safety tools only scan an agent’s outbound request. AIControls scans the response too — catching an attack hidden in a document before the agent ever reads it.
AIControls baselines each agent’s normal token use, call rate, and prompt patterns, and flags the moment one breaks its own pattern — before a monthly cap would ever notice.
No policy to write, no deploy to wait on. Scope it to all traffic, MCP only, LLM only, or just egress — and fully reversible.
A hard cap either blocks real work or gets overridden under pressure. AIControls holds the request for a named approver instead — decision on record, no ticket thread.
Identity your IdP already issues, enforcement your auditors already understand.
Who is this agent, and what is it entitled to reach?
What is the agent doing right now — and should it be allowed to proceed?
"We were already writing Kyverno policies for our clusters. Governing AI agents turned out to be the same language and the same approval process, which is why this took days rather than a quarter."
— AIControls design partnerRisk scoring, identity, cost control, and MCP governance — the controls that round out AIControls Gateway.
Composite risk per agent, trust score per tool; cross a threshold and the Kill Switch is one click away.
Developer, workload, or delegated agent — verified via your IdP.
Spend attributed to team, user, and model as it happens; budgets enforced before overrun.
Per-tool and per-datasource policy, argument validation, discovery scoped to identity.
Deploy inline as your LLM/MCP gateway, or as an ext_proc filter in front of Envoy or LiteLLM. HA, PostgreSQL-backed, running in under 30 minutes.
A short working session on your own clusters — no agent changes, no code changes, nothing enforced until you decide it should be.