Skip to content

Governed AI agents

Every agent action is checked before it runs.

Give every agent an identity, a policy on every action and a sandbox. qbrin checks the evidence, the authority and the policy before an agent acts, and a person signs off on the risky steps.

  • Checked before it runs
  • Least privilege by default
  • Every decision on the record
support-agent · acting for Priya S.Illustrative
  • KnowEarly access

    Listed with its owner. Last active today.

  • ScopeEarly access

    Reads the help desk and the docs. Cannot read finance or HR.

  • CheckLive

    Refund above the limit: Ask a person

Why it matters

Four questions every agent has to answer.

Your security team will ask them. Security, containment, manageability and observability: get all four right and you have confidence at any scale.

Who is this agent?

Each agent gets a stable identity, bound to the person it acts for. No anonymous automation.

What is it doing?

Every run writes a trace you can read, filter and replay.

Was it allowed?

Each action meets a policy before it happens. The riskiest wait for a person.

Can it hurt anything?

Agent code runs in a sandbox with no way out to your files or network.

01 · Identity

Every agent acts as someone.

Before an agent does anything, it gets a stable identity and is bound to the person it acts for. Every action traces back to a named agent and a named person. Know Early access lists them all in one place.

  • A stable identity per agent, the subject of every decision
  • Bound to a named human owner
  • A trust tier the policy layer keys on
See Know
Agent identityIllustrative
Principal
agent:7f3c…a91
Acting for
Priya S., support lead
Current run
run_2k9 · running
Trust tier
Scoped
Bound to a person

02 · Observability

Every thought, on the record.

What did the agent read? What did it decide, and why? Each run writes a structured trace you can read, filter and replay. Nothing the agent does is a black box.

  • A step-by-step trace you can inspect
  • A fleet view across every run and agent
  • Replay any decision after the fact
Run trace · run_2k9Illustrative
  1. ThoughtA customer asks for a refund on order #4471. Check that it exists first.
  2. Tool callorders.lookup("#4471")
  3. ResultOrder found. $128.00. Eligible.
  4. PolicyRefunds need a person to sign off. Ask a person
  5. FinalRefund drafted. Waiting for approval from Priya S.

03 · Governance

Every action meets a policy first.

Reading, writing, running code or sending a message is checked against a policy before it happens. Check Live answers go, hold or ask a person. Writes, code and sends are denied unless you grant them.

  • Default-deny on writes, code and sends
  • Allow-lists per agent or per org
  • High-risk actions wait for a person to approve
  • Pilot it on one team, then turn it on per org
See Check
Policy checkIllustrative
  • readSearch the knowledge baseGo
  • writeCreate a ticketGo
  • codeRun a migration scriptHold
  • sendEmail the customerAsk a person

Default-deny on writes, code and sends. Every decision is recorded.

04 · Containment

Code runs in a sealed room.

Agents can write and run code. That code runs in a sandbox with no way to reach your filesystem, your network or the host machine, under a hard time limit. It can compute. It cannot reach out.

  • No filesystem, network or host-process access
  • A hard time limit stops a runaway
  • Container isolation for untrusted code
Sandbox · agent codeIllustrative
  • ReachFilesystemDenied
  • ReachNetworkDenied
  • ReachHost processDenied
  • ReachEnvironmentDenied
  • LimitA run that never endsKilled

No filesystem, no network, no host access, and a hard time limit.

05 · Active defense

When the agent itself is the target.

Identity, policy and the sandbox assume the agent is on your side. But an agent reads untrusted text all day, and an attacker can hide instructions in it. So qbrin inspects every untrusted input and every outbound action.

  • Prompt-injection and jailbreak attempts are neutralized in place
  • Secrets and bulk data are stopped before they leave
  • A tamper-evident record that cannot be quietly rewritten
Read how we measured it
Threat monitorIllustrative
  • Prompt injectionHidden instructions in a web page or a ticketNeutralized
  • Data exfiltrationA reply that leaks a secret or bulk dataBlocked
  • Memory poisoningA saved note that says to export customer dataRefused
  • Audit tamperingAn edit to a step in the recordDetected
  • Runaway costA loop that burns through the token budgetCapped

06 · Manageability

A person stays in command.

A run sends a heartbeat while it works, so you can watch the fleet live. The moment one strays, you cancel it and it stops. Any run that goes dark is reaped, not left hanging.

  • Approve the high-risk steps
  • Cancel a run at any time
  • Replay any step afterwards
Run control · run_2k9Illustrative
Heartbeat: running
  • Approve high-risk actions
  • Stop a rogue run
  • Replay any step

A run that goes dark is reaped, not left hanging.

Evidence

Checked on a live process. Published in full.

Each number below comes from a run we wrote up. Each describes one setup, not agents in general.

63,589

requests checked on a plant simulator

29 eight-hour runs of a public chemical-process model. The agent had to give a true reason for each request. No invented reason moved a valve. One run on one setup.

4 vs 0

unsafe actions run, without and with qbrin

A LangGraph agent and five calls: one valid, four with missing, mismatched, stale or cross-tenant proof. Without qbrin all four unsafe calls ran. With it none did, and the valid one still ran.

4/87

maximum-power requests allowed

A small computer under an AI's control. The agent asked for maximum power 87 times and was allowed it 4. Every reason it gave was checked against the real sensor readings.

What you can build

Real agents, all on your data.

Legal assistants, support bots, voice agents. Each one answers from your company's own knowledge, cited, permission-aware and contained.

  • Legal and policy AI

    Reviews contracts and answers policy questions with the exact clause cited, not an invented one.

    Grounded in your data
  • Support agents

    Answer customers from your real docs, and ask a person instead of guessing when they cannot.

    Grounded in your data
  • Voice agents

    Phone agents that quote the right policy live on the call: grounded, not improvised.

    Grounded in your data
  • Account and sales briefs

    Prep every call from email, chat and CRM, with sources, before you dial.

    Grounded in your data
  • Onboarding buddies

    New hires ask how things are done here and get the real, current answer with its source.

    Grounded in your data
  • Compliance and audit

    Answer auditors with the record behind every claim, or say plainly that there is not one.

    Grounded in your data

Status

What is live, and what is not yet.

Check is live. Know and Scope are built and in early access, so we say plainly what they do not cover.

FAQ

Questions, answered.

How do I stop an AI agent from taking actions it should not?

Check every action before it runs. qbrin tests each action against current evidence, permissions and policy, then answers go, hold or ask a person. Writes, code runs and sends are denied unless you grant them, and the riskiest steps wait for a person to sign off.

What is least privilege for an AI agent?

Give the agent only what its job needs. In qbrin that means a policy per agent or per org, allow-lists for resources, and default-deny on writes, code and sends. Scope Early access narrows the data an agent can read to the sources its job needs.

Is there an approval step before an agent acts?

Yes. An agent proposes an action and qbrin checks it. High-risk actions wait for a person to approve them, and a person can cancel a run at any time.

Can I see what an agent did?

Each run writes a structured trace: thought, tool call, observation, policy decision and result. You can read it, filter it and replay any step. The record is tamper-evident, so it cannot be quietly rewritten.

How do I give an agent access to internal systems safely?

Give it an identity bound to a named person. Grant only the actions and resources it needs. Put a check in front of every action that changes something. Pilot enforcement on one team first, then turn it on for the whole org.

What protects an agent from prompt injection?

An agent reads untrusted text all day: web pages, support tickets, tool results. qbrin inspects every untrusted input and every outbound action. It covers five ways a hijacked agent does damage: prompt injection, data exfiltration, memory poisoning, audit tampering and runaway cost.

Can an agent run code safely?

Code an agent writes runs in a sandbox with no path to your filesystem, your network or the host machine, under a hard time limit. It can compute, but it cannot reach out.

Give your AI the task, not your company.

See an agent checked before it acts, in a 20-minute walkthrough on your own stack.