The six-layer framework for governing AI agents
A six-layer framework for governing AI agents: agent identity, delegated authority, policy at every tool call, accountability, audit evidence and security.
Last reviewed: 28 September 2026.
Everything around the model that makes an agent operable: orchestration, tool permissions, evaluation, guardrails, logging and a way to stop it. We work on boundaries, structured outputs, rollback and observability.
AI across specification, code generation, review, testing, CI/CD and release, with a quality gate at each step. A record of AI-assisted changes keeps audit and incident review working.
Engineering and business workflows where the output has to be structured and the failure mode defined in advance. Each step has an output schema, a check that rejects bad output, and a route to a person.
A six-layer framework for governing AI agents, from identity and delegated authority to audit evidence and runtime security. For any agent action: who acted, for whom, under which policy, with what result.
Practical guides from our R&D on engineering and governing AI in production, written by Alex Vakhitov and reviewed against primary sources. Each shows when it was last reviewed.
A six-layer framework for governing AI agents: agent identity, delegated authority, policy at every tool call, accountability, audit evidence and security.
Last reviewed: 28 September 2026.
A practical guide to governing AI agents in production: tool permissions, evaluation, audit trails, human oversight, stopping safely and framework mapping.
Last reviewed: 27 September 2026.
When the EU AI Act reaches UK organisations, which duties already apply, the 2027 and 2028 high-risk dates, and how UK rules fit. Plain-English guide.
Last reviewed: 27 September 2026.
Proxed.AI
AGPL-3.0
Split-key proxy that keeps full AI provider keys off iOS devices.
Source on GitHub (opens in new tab)Plop
AGPL-3.0
Stores and normalises inbound email, with access through a UI and an API.
Source on GitHub (opens in new tab)Bounded contexts set clear limits on what an agent may call. Composition decides how tools, evaluation and guardrails stack on top of each other. The same pattern runs through the SDLC, with a quality gate at each step. We write the boundary down first, evaluate before and after release, and keep a way back.
Questions about the R&D, the guides or the open-source code: write to us.
Contact