AAES (Autonomous Agentic Enterprise Systems) is an AI governance platform for the action layer: permissions, approvals by authorized persons, and spending limits on requests routed through it, with a sealed record of each completed decision. Enforcement requires control of the agent's credential path. Other activity is visible only where telemetry is supplied; observation cannot block it. Offline verification checks export integrity using a separately trusted public key. It cannot prove complete capture or downstream execution. An optional independent witness or timestamp authority can corroborate the signed journal summary.
What AAES governs
AAES governs the moment an agent acts, not the model behind it. On enforced paths, AAES applies four controls to requests routed through it:
- Permissions. Each registered agent has at least one accountable human manager and permission for specific registered capabilities. A request outside that permission set is refused, and the refusal is recorded.
- Approvals by authorized persons. AAES requires an authorized person’s approval for capabilities registered as irreversible. Each approval covers the exact request, expires, and cannot be supplied by the requesting agent.
- Spending limits. Configured budgets are reserved before dispatch, and requests over the ceiling are refused. This caps what is routed through AAES; it does not cap spending that takes place outside it.
- Records. Check exported records for integrity without connecting to an AAES service. On an enforced path, a request that cannot be recorded is refused rather than executed unrecorded.
Observation-only registrations record reported activity and cannot stop the call.
Deployment and limits, stated plainly
AAES runs as a client-operated, single-tenant deployment on your infrastructure: a single VM, Kubernetes, or an isolated on-premises environment. Managed hosting is planned and not currently offered.
Credentials. On a grant path, AAES issues short-lived permission for a specific task, called an AAES grant. This is an authorization, not a credential for the downstream service. On a brokered-execution path, AAES uses the configured credential to make the permitted call and returns the result without giving that credential to the agent. A short-lived grant does not shorten the lifetime of the downstream secret. Observation-only registrations record reported activity and cannot stop the call.
Enforcement boundary. Enforcement requires control of the agent's credential path. Other activity is visible only where telemetry is supplied; observation cannot block it.
Outages. If AAES is unavailable or cannot write the required decision journal, new requests on enforced paths are refused. This is called fail closed. Grants issued before the failure remain usable until expiry, at most 15 minutes from issue.
Assurance status. No SOC 2 report exists, and no penetration test has been performed. The platform evaluation package runs in your environment and is included only in the paid design partnership.
The dated capability matrix identifies implemented, lab-only, planned, and refused credential paths, and the verification guide explains what an exported record does and does not establish.
Evaluate on one bounded workflow
Pick one workflow with an irreversible action — a payment, a production change, an external message — and test the controls directly: an action without approval, an approval reused on a changed request, and a self-approval attempt should each be refused and recorded; concurrent requests near a budget limit must not double-spend; and exported records should verify with the network disabled. A direct-credential bypass is not stopped by AAES; confirm at the downstream provider that a refused action had no effect. The evaluation guide walks through each step, and the full evaluation scorecard lists the evidence to request from every candidate.
The platform evaluation package runs in your environment and is included only in the paid design partnership. The design-partner offer is USD 40,000 for three months; the term begins once the agreement is signed and onboarding is complete. Public documentation, the Apache-2.0 verifier and sample pack, and published Python and TypeScript SDK packages are available separately. They do not grant a platform software license or access to a running deployment.
Frequently asked questions
What does an AI governance platform govern?
That depends on the product category. Model-governance platforms manage the model lifecycle: registration, validation, and monitoring. Agent-governance platforms constrain what a deployed agent may do: which capabilities it may use, who approves irreversible actions, and what it may spend. AAES is the second kind. It applies permissions, approvals by authorized persons, and spending limits to actions routed through it, and it does not govern model behavior.
What should an enterprise look for in an AI governance platform?
Test five things on one bounded workflow: a per-capability permission model with an accountable human manager for each agent; approval by an authorized person for irreversible actions, bound to the exact request; spending limits reserved before dispatch; whether enforcement depends on controlling the agent's credential path, and what happens on paths the platform does not control; and whether records can be exported and checked for integrity without the vendor's service. Ask each candidate to state its assurance status, including any independent assessment or SOC 2 report, in writing.
Is AAES certified, and does it have a SOC 2 report?
No. AAES has no independent certification or assessment. No SOC 2 report exists, and no penetration test has been performed. The design-partner offer is USD 40,000 for three months; the term begins once the agreement is signed and onboarding is complete. Managed hosting is planned and not currently offered.
How do we evaluate AAES as our AI governance platform?
Pick one bounded workflow with an irreversible action, register the capability, name the approver, and test refusal, changed-request reuse, and self-approval; each should be refused and recorded. The platform evaluation package runs in your environment and is included only in the paid design partnership. Public documentation, the Apache-2.0 verifier and sample pack, and published Python and TypeScript SDK packages are available separately. They do not grant a platform software license or access to a running deployment.
For a side-by-side view of governance approaches, see the AI agent governance comparison and the enterprise AI governance platforms guide. For the action-layer threat model, see agentic AI security.
