AAES Govern / Control

An action requested. A decision you can check.

AAES Govern checks permissions, required approvals, and spending limits for actions routed through it. Keep signed decision records you can check offline. Self-hosted on your infrastructure.

Work / Approvals
APR 2410 / ANALYTICSAwaiting approval

Export customer records

One routed request. A decision bound to its exact scope.

Agent
RA Reporting Agent
Authorized approver
PR Priya Raman
Capability
crm.contacts.export
Scope
2,400 records
BEFORE AUTHORIZATION

✓ Registered identity

✓ Capability in scope

◷ Required person’s approval

$10.00reserved against $50.00
Approval covers this request only.No action dispatched

AAES Govern, from AAES (Autonomous Agentic Enterprise Systems), is an AI governance platform for the action layer: permissions, approvals by authorized persons, and spending limits on requests routed through it, with a sealed record of each completed decision.

Controls for the requested action.

What it checks

AAES Govern acts at the moment an agent requests an action, not on the model behind it. For supported actions routed through it, Govern applies four controls:

  • Permissions. Each registered agent has at least one accountable manager, ultimately answerable to a person, and permission for specific registered capabilities. Managers can be people or agents; you can require a person as every agent’s direct manager. Govern refuses a request outside that permission set and records the refusal.
  • Approvals by authorized persons. AAES Govern requires an authorized person’s approval for capabilities registered as irreversible. Each approval covers the exact request, expires, and cannot be supplied by the requesting agent.
  • Spending reservations. Govern reserves the evaluated amount against the configured budget before it authorizes the request, and refuses requests over the ceiling. This limits evaluated commitments on supported actions routed through Govern; it does not guarantee final provider charges or cap spending outside those paths.
  • Records you can check offline. Govern seals a record of each completed decision. Check exported AAES Govern records for integrity without connecting to an AAES service.

Agents it works with

Create and run agents in AAES Operate, or connect agents you already run. AAES Govern applies permissions, approvals, spending controls, and records to actions routed through its governed paths.

Existing agents can include Microsoft Copilot Studio, Azure Foundry, and your own hosted runtime; the agent keeps running where it runs today. To create and run new agents, use AAES Operate. Each agent registered in Govern has an accountable manager whose chain of managers ends at a person, and employee access stays in your identity provider.

Know what is enforced and recorded.

Enforcement boundary

AAES Govern can block an action when it controls the required credentials and the agent cannot bypass that path. Enforcement requires control of the agent's credential path. Other activity is visible only where telemetry is supplied; observation cannot block it.

An agent with credentials it can use directly may bypass Govern. Observation-only registrations record reported activity and cannot stop the call.

Credentials. On a grant path, AAES Govern issues short-lived permission for a specific task, called an AAES grant. This is an authorization, not a credential for the downstream service. On a brokered-execution path, AAES Govern uses the configured credential to make the permitted call and returns the result without giving that credential to the agent. A short-lived grant does not shorten the lifetime of the downstream secret. Observation-only registrations record reported activity and cannot stop the call.

Outages. If AAES Govern is unavailable or cannot write the required decision journal, new requests on enforced paths are refused. This is called fail closed. Grants issued before the failure remain usable until expiry, at most 15 minutes from issue.

The dated capability matrix lists implemented, lab-only, planned, and refused credential paths.

Records and offline verification

Check exported AAES Govern records for integrity without connecting to an AAES service. Offline verification checks export integrity using a separately trusted public key. It cannot prove complete capture or downstream execution. An optional independent witness or timestamp authority can corroborate the signed journal summary.

The verification guide explains what an exported record does and does not establish.

Deploy and evaluate on your stack.

Deployment

AAES Govern is client-operated and single-tenant. You run it on your infrastructure and hold the keys, storage, and availability.

  • Single VM. Docker Compose.
  • Kubernetes. Helm and Terraform from the evaluation package.
  • Isolated or on-premises. Air-gapped and on-premises environments you control.

Managed hosting is planned and not currently offered.

Pricing

AAES Govern has no license fee per person or per agent. The planned production model meters governed-decision capacity: capacity for requests Govern evaluates and records, including permits and refusals. The design-partner offer is USD 40,000 for three months and covers AAES Govern and AAES Operate; the term begins once the agreement is signed and onboarding is complete. Production rates have not been published.

The pricing comparison sets out the charging model and the questions still open.

Assurance status

AAES has no independent certification or assessment. No SOC 2 report exists, and no penetration test has been performed yet; an independent test is planned for Q4 2026.

The platform evaluation package for AAES Govern and AAES Operate runs in your environment and is included only in the paid design partnership.

Request an evaluation

Read the evaluation guide, or browse the evidence library.

Frequently asked questions

Do we create agents in AAES or connect our existing agents?

Both. Create and run agents in AAES Operate using your existing model-provider access, or connect an agent you already run and route its actions through AAES Govern. Each agent registered in Govern has an accountable manager whose chain of managers ends at a person. Govern governs actions routed through its controlled paths.

Agents in AAES Operate can use OpenAI, Anthropic, Google Gemini, xAI Grok, a supported Azure Foundry OpenAI v1 endpoint, and OpenAI-compatible self-hosted endpoints. Existing agents connected to Govern can include Microsoft Copilot Studio, Azure Foundry, and your own hosted runtime. Copilot Studio agents stay in your Microsoft environment.

Does this replace our identity provider?

No. Keep employee access in Microsoft Entra, Okta, or your existing identity provider. Name the agent’s first approver in AAES Govern. A directory integration can supply additional approvers where required; live tenant compatibility is validated during the design partnership.

Which actions require approval by an authorized person?

Actions registered as irreversible always require an authorized person’s approval on enforced paths. Your policies can require approval for other actions too. An action approval covers the exact request and expires; changing the request means asking again.

An access approval instead grants a specific permission for a limited scope and lifetime. Eligible manager agents can approve where policy permits, but cannot provide a required human approval. Agents cannot approve themselves.

Can we observe before we enforce?

Yes. Register an action as observation-only to record the activity reported to AAES Govern. Its records are labeled observed. If the agent keeps credentials it can use directly, Govern cannot stop those calls.

AAES Govern can block an action when it controls the required credentials and the agent cannot bypass that path. Switching to enforcement therefore requires configuring and testing the credential path, not simply changing a label.

What happens if AAES Govern is unavailable?

If AAES Govern is unavailable or cannot write the required decision record, requests needing a new decision are refused on enforced paths. Govern authorizes no new grant or brokered execution through that path. This behavior is called fail closed.

Previously issued grants remain usable until expiry, at most 15 minutes from issue. An outage does not cancel work already authorized, undo downstream effects, or stop observation-only and bypass activity. Employee access stays with your identity provider. You operate AAES on your infrastructure; no availability SLA is offered today.

Does AAES Govern see everything my agents do?

No. AAES Govern checks supported actions routed through it. AAES Govern can block an action when it controls the required credentials and the agent cannot bypass that path. An agent with credentials it can use directly may bypass Govern, and observation-only registrations record reported activity without stopping the call. Enforcement requires control of the agent's credential path. Other activity is visible only where telemetry is supplied; observation cannot block it.

Do I need AAES Operate to use AAES Govern?

No. Govern connects agents you already run, such as Microsoft Copilot Studio, Azure Foundry, or your own runtime. AAES Operate is a separate product for creating, running, and coordinating agents on your infrastructure.

How is AAES Govern priced?

AAES Govern has no license fee per person or per agent. The planned production model meters governed-decision capacity: capacity for requests Govern evaluates and records, including permits and refusals. The design-partner offer is USD 40,000 for three months and covers AAES Govern and AAES Operate; the term begins once the agreement is signed and onboarding is complete. Production rates have not been published.

Is AAES Govern certified, and does it have a SOC 2 report?

No. AAES has no independent certification or assessment. No SOC 2 report exists, and no penetration test has been performed yet; an independent test is planned for Q4 2026. The platform evaluation package for AAES Govern and AAES Operate runs in your environment and is included only in the paid design partnership.

AAES Operate + AAES Govern

Run the work.
Govern the routed actions.

Use either product on its own, or evaluate both against one real workflow.

01 / AAES Operate

Runs and coordinates the agents.

Agent teams, projects, tasks, and operational controls on your infrastructure.

02 / AAES Govern

Checks and records routed actions.

Permissions, required approvals, spending reservations, and signed decision records.

Whether the actions of agents that AAES Operate runs can be routed through AAES Govern is evaluated workflow by workflow in the design partnership. Govern checks only the actions routed through it.

AAES Govern adds what Operate does not have: spending reserved before an action is authorized, signed decision records you can check offline, and governance for agents you already run on other platforms.

Scope Govern, Operate, or both with us