HomePlatform
Prove7 Control Vector™ · Platform

One platform that prepares, governs, and proves.

Prove7 Control Vector™ is the Agentic Trust Infrastructure for AI agents — a governed execution layer, four named engines, and a hash-chained record. Every action passes the Seven Gates, ships with its proof, and earns the autonomy it gets. Accountable Autonomy™ — answers as it acts.

Architecture

The whole platform, one view

Three planes: your systems on the left, the trust plane in the middle, the outside world on the right. Every arrow is governed — and everything that crosses the middle lands on the sealed record. Click any ⊕ component to look inside it.

YOUR SYSTEMS PROVE7 CONTROL VECTOR™ THIRD-PARTY & MODELS Business apps & APIs ERP · CRM · custom services Identity & access Okta · AD · SailPoint · Saviynt Data & records databases · files · knowledge Endpoints & branch sites desktops · disconnected estates Your coded agents LangChain · CrewAI · any code Your API clients scripts · portals · partners Surfaces Workspace · Endpoint Container · Governed Workflow AutoX · App Packs · Governed Agents · Governed APIs Governed Execution Layer™ envelope → resolve → pre-check → execute → post-check → seal inline · <50 ms · fail-closed · human-in-the-loop Cognitive Runtime executes the CEG · 3 modes · caps Policy Engine 6 PEPs · Rego/OPA Rules Engine docs & controls → rules Trust Engine & Ontology trust graph · 0–100 score Platform services Identity CA (SPIFFE) · Approvals · Discovery · DPG · Intelligence Sealed record hash-chained · tamper-evident · replayable Model providers OpenAI · Anthropic · Vertex · Bedrock Security stack CrowdStrike · Splunk · Chronicle ITSM & ops ServiceNow · PagerDuty · Jira MCP servers & A2A agents tools · partner agents 50+ connectors IAM · vaults · vector stores · intel governedactions evidence back SDK / gateway scopedAPI calls inference governedcalls results,scanned MCP · A2A,gated Deploy anywhere: Prove7 Cloud (managed) or self-hosted in your GCP / AWS / Azure — Helm · mTLS · signed images · air-gap friendly + + + + +
The platform in one view: every surface routes through the Governed Execution Layer; the four engines decide; every action lands on the sealed record. Nothing reaches your systems — or a model — ungoverned.
Inside the runtime

Governed Execution Layer™

Every governed call — from any surface, SDK, or API — runs one six-phase pipeline inline, sub-50 ms, fail-closed. The pre-check fires at the exact gate the agent’s Canonical Execution Graph declares.

One sealed transaction per action — six phases, inline
PHASE 1

Create Envelope

Immutable governance envelope opened; correlation id assigned

PHASE 2

Resolve Agent

Identity (SPIFFE/SVID), intent profile, entitlements, scope

PHASE 3

Pre-Check

Trust threshold · deterministic policy at the CEG-declared gate · DPG-in

PHASE 4

Execute

Agent / skill / tool runs — ours or yours (SDK mode)

PHASE 5

Post-Check

DPG-out · refusal detection · trust score update

PHASE 6

Seal

Hash-chained to the audit substrate; events emitted

Web App WorkspaceEndpoint Multi-Agent ContainerGoverned WorkflowAutoX™Agentic App PacksGoverned AgentsGoverned API GatewayMCP GatewaySDK Decorator (Py · Java · JS · C#)
1
Discovered
no shadow AI
2
Identity
per-agent SVID
3
Intent
approved purpose
4
Access
least privilege
5
Trust
earned autonomy
6
Enforcement
inline, fail-closed
7
Audit
chained, replayable
Read the full runtime deep-dive ↓
Engine 01

Cognitive Runtime Engine

Runs the agent by executing its Canonical Execution Graph. The LLM picks tools at runtime inside governance: every tool decision is policy-gated before and after, every step is a durable, replayable activity, and the whole loop is bounded by hard caps.

Execution model — hybrid layout shown (deterministic head / cognitive body / deterministic tail)
Deterministic heade.g. authenticate, load context — sequential, gated
A first-class node on the Canonical Execution Graph
Cognitive Loop
reason → pick tool → PRE-GATE → invoke → POST-GATE → return ⟲
connector skillavailability edge: always
workflow skillavailability edge: guarded
agent-as-toolchild workflow
maxIterations capcost cap (USD)per-skill retry/timeoutrate limitsidempotency cachehuman-approval pause/resumekill switch
Deterministic taile.g. seal evidence, notify — sequential, gated
Deterministic

Pre-authored graph. Entry posture for converted processes — the source replays faithfully.

Hybrid

Guard rails around LLM freedom: fixed head/tail, cognitive middle.

Cognitive

LLM-driven tool selection, earned through the Trust ladder — and revocable.

Audit emits decision-level events — even the model’s choices are on the chain. Read the full engine detail ↓
Engine 02

Policy Engine

Adaptive Policy Enforcement Points are positions on the agent’s Canonical Execution Graph — computed from the capabilities the graph actually declares, not one gate for everything. Verdicts are reproducible: same input, same policy version, same answer. That is what a regulator can attest.

Adaptive PEP taxonomy — gates placed along the execution path
P0
Agent Entryfires once at boot of every execution
LLM
Inference Callbefore every model invocation
MCP
Tool Callbefore every MCP tool dispatch
P1
Workflow Entrywhen a workflow run starts
P2
Inter-Stepbetween workflow nodes
P3
Connector Outbefore outbound system calls
Scope cascade:OrgTenantAgentSkill·most specific wins · inheritance previewed before activation · Data Protection Guards (in/out) honour per-node overrides
Deterministic Rego/OPA at every gate — plus pause-for-approval mid-reasoning, demote autonomy, kill. Read the full engine detail ↓
Engine 03

Rules Engine

Turns what the enterprise already owns — policy documents, pattern libraries, compliance framework controls — into typed, versioned, enforceable rules with provenance back to their source. Malformed rules are quarantined, never silently over-blocked.

Unified rule lifecycle — every path converges on one pipeline
1 · SOURCE

Pick sources

Policy documents (RAG) · pattern templates · framework controls · direct authoring

2 · EXTRACT

Candidate rules

Uniform envelope: type, evaluation, severity, confidence, source ref

3 · REVIEW

Human selects

Rules + manual-control attestations, side by side

4 · CONFIGURE

Bind scope + PEPs

Inheritance preview · CEG enforcement-point picker · framework coverage projection

5 · ACTIVATE

Atomic commit

Rules + bindings + attestation tasks, audit event fired, coverage live

evaluation: ENUM · REGEX · EXPRESSION BLOCKWARNAUDIT data-classification rules → DPG redaction config validator + engine quarantine framework mapping: SOC 2 · ISO 27001 · ISO 42001 · HIPAA · PCI · EU AI Act · NIST AI RMF · SR 11-7 · SOX
Automatable controls become rules; manual controls become attestation tasks. Read the full engine detail ↓
Engine 04

Trust Engine & Ontology

Every prove domain emits one signed assertion shape (W3C VC / in-toto model) keyed on the agent’s verifiable identity; the sealed audit chain is the substrate; the trust graph is a projection. Two queries answer everything: subject view (“fold everything we know about agent X as of time T”) and action replay (“walk one governed call end-to-end”).

Trust ontology — assertions in, chain as substrate, autonomy out
Seven prove domains emit signed TrustAssertions
Discovery & RegistrationIdentity (SPIFFE/WIMSE) Intent ProfilesAccess / RBAC Trust AssessmentEnforcement verdicts Audit eventsOutcome conformance

Subject spine: agent UUID + spiffe:// identity + delegation chain. One envelope shape for every domain.

Sealed audit chain

Hash-chained, tamper-evident, ~70 event types. Chain-integrity verify on demand. Replay = re-fold the stream.

Agent Trust Score → autonomy ladder
Shadow — observes only, everything scored
Assisted — suggests; humans act
Supervised — acts through approval gates
Autonomous — acts alone, proof sealed per action

0–100, recomputed per run against a ground-truth baseline. Zero evaluations reads Unrated — never a fabricated score. What trust promotes is the agent’s execution posture on its Canonical Execution Graph — demotion snaps it back in seconds.

An accountability ontology: signed evidence, earned autonomy, replayable provenance. Read the full engine detail ↓
The runtime

Governed Execution Layer™

Every governed call — from any product or SDK — runs one six-phase pipeline inline, in under 50 ms, fail-closed. Policy lives in the path of the action, not on a page beside it. And every call executes against the agent’s Canonical Execution Graph: the pre-check fires at the exact gate the graph declares, whether the step was authored by a person or chosen by the model.

PHASE 1

Create Envelope

An immutable governance envelope opens; a correlation id binds the whole call.

PHASE 2

Resolve Agent

Identity (SPIFFE/SVID), intent profile, entitlements, and scope resolve.

PHASE 3

Pre-Check

Trust threshold, deterministic policy at the declared gate, data protection in.

PHASE 4

Execute

The agent, skill, or tool runs — ours, or yours via the SDK.

PHASE 5

Post-Check

Data protection out, refusal detection, trust score update.

PHASE 6

Seal

The envelope is hash-chained to the audit record. Queryable, replayable.

Seven Gates: Discovered · Identity · Intent · Access · Trust · Enforcement · Audit<50 ms inlinefail-closedhuman-in-the-loop
The engines

Four engines. All named, all attestable.

No black boxes. Each engine’s behaviour is versioned, deterministic where it must be, and reconstructable everywhere.

Engine 01 · Temporal-backed durable execution

Cognitive Runtime Engine

Runs the agent itself — by executing its Canonical Execution Graph (CEG). Three declared execution modes on the same graph: Cognitive (the LLM reasoning loop picks tools at runtime — the loop is a first-class node, and every tool the model may reach is an availability edge), Deterministic (an agentic workflow invocation, node by node), and Hybrid (a deterministic head and tail around a cognitive body). Every tool decision is policy-gated before and after, every step is a durable, replayable activity, and the loop is bounded by hard caps — iterations, cost (USD), per-skill retry, timeout and rate limits. Approvals pause the conversation mid-reasoning and resume on decision.

executes the CEG3 modes, one graphcost & iteration capsidempotency cachemid-reasoning approval pausekill switchdecision-level audit events
Engine 02 · Deterministic · fail-closed

Policy Engine

Adaptive Policy Enforcement Points are positions on the agent’s Canonical Execution Graph — agent entry, each inference call, each MCP tool dispatch, workflow entry, inter-step, and outbound connector calls — computed from the capabilities the graph actually declares. Verdicts are deterministic Rego/OPA: same input, same policy version, same answer — the property a regulator can attest. Scope cascades Org → Tenant → Agent → Skill with inheritance previewed before activation.

6 enforcement points on the CEGRego / OPAscope cascadeversioned verdictsData Protection Guards in/out
Engine 03 · Policy-as-data · five-stage lifecycle

Rules Engine

Turns what the enterprise already owns — policy documents, pattern libraries, compliance framework controls — into typed, versioned, enforceable rules with provenance back to their source. Five stages: Source → Extract → Review → Configure → Activate. Activated rules bind to scopes and to enforcement points on each agent’s Canonical Execution Graph. Automatable controls become rules; manual controls become attestation tasks; the framework coverage percentage is live, not estimated. Malformed rules are quarantined, never silently over-blocked.

docs · patterns · frameworks · directBLOCK / WARN / AUDITcoverage projectionattestation tasksvalidator + quarantine
Engine 04 · The trust graph · earned autonomy

Trust Engine & Ontology

Every prove domain — discovery, identity, intent, access, trust, enforcement, audit — emits one signed assertion shape keyed on the agent’s verifiable identity. The sealed audit chain is the substrate; the trust graph is a projection over it. Two queries answer everything: the subject view (everything known about agent X as of time T) and action replay (one governed call walked end-to-end). On top sits the Agent Trust Score™ — a live 0–100 measure that grants autonomy stage by stage and withdraws it automatically on drift. What trust promotes is the agent’s execution posture on its Canonical Execution Graph: steps climb deterministic → hybrid → cognitive as evidence accrues, and demotion snaps the graph back to its proven baseline in seconds. Zero evaluations reads Unrated — never a fabricated number.

signed TrustAssertionshash-chained substratesubject viewaction replayShadow → Assisted → Supervised → AutonomousCEG posture follows trustauto-demotion
The Agentlet™ model

Four archetypes. One lifecycle. One record.

Every governed agent on Prove7 is an Agentlet™ — and every Agentlet is one of four archetypes. Different births, same gates: each carries a cryptographic identity, a declared intent, a Canonical Execution Graph, a trust score, and a sealed record, and each moves through the same Build · Decide · Act lifecycle with autonomy that is earned, ceilinged, and revocable.

Archetype 01 · hand-built native

Let™

An agent your team authors on the platform — skills selected from the Skill Center, orchestration drawn as a Governed Workflow, execution mode declared (deterministic, cognitive, or hybrid). Born inside the gates: governance is its native habitat, never a wrapper.

authored on-platform3 execution modesBuild · Decide · Act
Archetype 02 · compiled from your process

AutoLet™

An agent compiled from a versioned source you already trust — a runbook, an SOP document, a spreadsheet process, an approved URL, or a governed workflow — created in one click through AutoX™. The source is fixed at creation and registered as the agent’s ground-truth baseline and judge; the AutoLet starts by replaying it faithfully and earns cognitive autonomy stage by stage, reversibly.

runbook / doc / workflow sourcebaseline as judgeshadow → autonomousauto-demotion
Archetype 03 · external, adopted

ExteLet™

An agent you built elsewhere — LangChain, CrewAI, AutoGen, OpenAI, Bedrock, ServiceNow, UiPath, or plain code — registered and governed through the MCP Gateway or SDK decorator. No rebuild: it keeps its runtime and gains identity, policy, trust, and a sealed record. Verified on its first successful governed call.

any frameworkgateway or SDKkill switchsame trust ladder
Archetype 04 · the platform’s own

SysLet™

System agents that run the platform’s own automated work — discovery sweeps, compliance evidence collection, scheduled governance jobs. Prove7 practices what it enforces: SysLets pass the same gates, carry the same identities, and seal to the same record as every other Agentlet. No privileged shadows.

platform-operatedsame seven gatesno ungoverned automation
Platform services

Everything around the engines

Prepare · Discovery

Find every agent — including the ones nobody told you about

Continuously walk your runtimes, clouds, and tools and surface every agent that touches your systems, then classify and attribute them. You can’t govern an agent you can’t see.

passive discoveryMCP scanruntime telemetryattribution graph
Prepare · Registry & Identity

Every agent gets a cryptographic name and a declared purpose

Each agent bound to a cryptographic identity (SPIFFE · mTLS · OIDC · JWT-SVID), an owner who can be paged, a declared scope, and an authorized intent — so drift is detectable instantly.

SPIFFE / mTLSowner attributionintent templatesscope
Prepare · Trust Transfer

Move from deterministic to agentic, stage by stage

Register a proven workflow as the ground-truth judge, then advance a candidate agent through shadow → assisted → supervised → autonomous — only as fast as its sealed conformance allows.

deterministic baselineshadow modereversible trust
Govern · Adaptive Protection

Protection that adapts to earned trust, on every call

Trust-weighted enforcement at 100% of calls, inline. Allowed autonomy adapts to a live trust score; drift auto-demotes in under a minute and resumes the deterministic path.

continuous enforcementdrift auto-demotekill-cascade
Prove · Provenance & Audit

A record that survives a year, a rewrite, and a cross-examination

Every sealed action becomes a content-addressed, hash-chained, append-only record, captured before execution. Pull any output and the whole lineage comes back — to origin and forward to blast radius.

capture-before-executehash-chainlineagetamper-evident
Prove · Compliance & Intelligence

Audit prep becomes audit access — and the fleet gets smarter

Every action continuously mapped to SOC 2, ISO 27001/42001, EU AI Act, NIST AI RMF, SR 11-7, and SOX ITGC. Workflow Intelligence reads your runs — cost, latency, override rates, drift — and surfaces what to tune and what’s ready for its next autonomy level.

framework mappingcontinuous attestationrun analytics

Deploy anywhere. Govern everything.

Prove7 Cloud — fully managed, zero ops — or self-hosted in your own GCP / AWS / Azure estate: Helm-deployed, mTLS everywhere, cosign-signed images. Air-gap-friendly for regulated estates. A global and scoped Kill Switch, Inference Control, Secrets Manager, and multi-tenancy with a promote-to-production gate come standard.

Prove7 CloudSelf-hosted (GCP · AWS · Azure)Helm + signed images50+ connectors — CrowdStrike, Splunk, Okta, SailPoint, ServiceNow, PagerDuty, Tenable, HashiCorp…

Frequently asked

What is an AI agent governance platform?

An AI agent governance platform is the runtime layer that controls what AI agents are allowed to do and proves what they did. Prove7 Control Vector governs every agent action inline — identity, intent, policy, trust, and human approval — and seals each action to a tamper-evident, hash-chained audit record that can be replayed end-to-end.

How is Prove7 different from AI usage or prompt security tools?

AI usage security tools inspect what people type into chatbots. Prove7 governs what AI agents actually do — the actions they take on enterprise systems. It runs agents inside governance with cryptographic identity, deterministic policy, earned autonomy, and replayable provenance, rather than filtering prompts in transit.

What are the four engines of the Prove7 platform?

The Cognitive Runtime Engine runs agents with governed LLM tool selection; the Policy Engine enforces deterministic Rego/OPA verdicts at six enforcement points; the Rules Engine compiles policy documents and framework controls into typed enforceable rules; and the Trust Engine & Ontology maintains a signed trust graph and the 0–100 Agent Trust Score that grants and revokes autonomy.

Can Prove7 run self-hosted or air-gapped?

Yes. Prove7 deploys as a fully managed cloud or self-hosted in your own GCP, AWS, or Azure estate via Helm with mTLS and signed images — a fit for banks, insurers, healthcare, and government estates that cannot route agent traffic through a third-party cloud.

RELATED:Products →Agent Trust Score™ →Framework mapping →Agentic AI Governance →
Accountable Autonomy™ — answers as it acts.

See it govern an agent end-to-end in 30 minutes.

If you’re the one who answers when the machine acts — a CISO, a CFO, a COO — watch Prove7 Control Vector™ take an agent from discovered to governed to proven, live.

Schedule a Demo →