Prove7 Control Vector™ is the Agentic Trust Infrastructure for AI agents — a governed execution layer, four named engines, and a hash-chained record. Every action passes the Seven Gates, ships with its proof, and earns the autonomy it gets. Accountable Autonomy™ — answers as it acts.
Three planes: your systems on the left, the trust plane in the middle, the outside world on the right. Every arrow is governed — and everything that crosses the middle lands on the sealed record. Click any ⊕ component to look inside it.
Every governed call — from any surface, SDK, or API — runs one six-phase pipeline inline, sub-50 ms, fail-closed. The pre-check fires at the exact gate the agent’s Canonical Execution Graph declares.
Immutable governance envelope opened; correlation id assigned
Identity (SPIFFE/SVID), intent profile, entitlements, scope
Trust threshold · deterministic policy at the CEG-declared gate · DPG-in
Agent / skill / tool runs — ours or yours (SDK mode)
DPG-out · refusal detection · trust score update
Hash-chained to the audit substrate; events emitted
Runs the agent by executing its Canonical Execution Graph. The LLM picks tools at runtime inside governance: every tool decision is policy-gated before and after, every step is a durable, replayable activity, and the whole loop is bounded by hard caps.
Pre-authored graph. Entry posture for converted processes — the source replays faithfully.
Guard rails around LLM freedom: fixed head/tail, cognitive middle.
LLM-driven tool selection, earned through the Trust ladder — and revocable.
Adaptive Policy Enforcement Points are positions on the agent’s Canonical Execution Graph — computed from the capabilities the graph actually declares, not one gate for everything. Verdicts are reproducible: same input, same policy version, same answer. That is what a regulator can attest.
Turns what the enterprise already owns — policy documents, pattern libraries, compliance framework controls — into typed, versioned, enforceable rules with provenance back to their source. Malformed rules are quarantined, never silently over-blocked.
Policy documents (RAG) · pattern templates · framework controls · direct authoring
Uniform envelope: type, evaluation, severity, confidence, source ref
Rules + manual-control attestations, side by side
Inheritance preview · CEG enforcement-point picker · framework coverage projection
Rules + bindings + attestation tasks, audit event fired, coverage live
Every prove domain emits one signed assertion shape (W3C VC / in-toto model) keyed on the agent’s verifiable identity; the sealed audit chain is the substrate; the trust graph is a projection. Two queries answer everything: subject view (“fold everything we know about agent X as of time T”) and action replay (“walk one governed call end-to-end”).
Subject spine: agent UUID + spiffe:// identity + delegation chain. One envelope shape for every domain.
Hash-chained, tamper-evident, ~70 event types. Chain-integrity verify on demand. Replay = re-fold the stream.
0–100, recomputed per run against a ground-truth baseline. Zero evaluations reads Unrated — never a fabricated score. What trust promotes is the agent’s execution posture on its Canonical Execution Graph — demotion snaps it back in seconds.
Every governed call — from any product or SDK — runs one six-phase pipeline inline, in under 50 ms, fail-closed. Policy lives in the path of the action, not on a page beside it. And every call executes against the agent’s Canonical Execution Graph: the pre-check fires at the exact gate the graph declares, whether the step was authored by a person or chosen by the model.
An immutable governance envelope opens; a correlation id binds the whole call.
Identity (SPIFFE/SVID), intent profile, entitlements, and scope resolve.
Trust threshold, deterministic policy at the declared gate, data protection in.
The agent, skill, or tool runs — ours, or yours via the SDK.
Data protection out, refusal detection, trust score update.
The envelope is hash-chained to the audit record. Queryable, replayable.
No black boxes. Each engine’s behaviour is versioned, deterministic where it must be, and reconstructable everywhere.
Runs the agent itself — by executing its Canonical Execution Graph (CEG). Three declared execution modes on the same graph: Cognitive (the LLM reasoning loop picks tools at runtime — the loop is a first-class node, and every tool the model may reach is an availability edge), Deterministic (an agentic workflow invocation, node by node), and Hybrid (a deterministic head and tail around a cognitive body). Every tool decision is policy-gated before and after, every step is a durable, replayable activity, and the loop is bounded by hard caps — iterations, cost (USD), per-skill retry, timeout and rate limits. Approvals pause the conversation mid-reasoning and resume on decision.
Adaptive Policy Enforcement Points are positions on the agent’s Canonical Execution Graph — agent entry, each inference call, each MCP tool dispatch, workflow entry, inter-step, and outbound connector calls — computed from the capabilities the graph actually declares. Verdicts are deterministic Rego/OPA: same input, same policy version, same answer — the property a regulator can attest. Scope cascades Org → Tenant → Agent → Skill with inheritance previewed before activation.
Turns what the enterprise already owns — policy documents, pattern libraries, compliance framework controls — into typed, versioned, enforceable rules with provenance back to their source. Five stages: Source → Extract → Review → Configure → Activate. Activated rules bind to scopes and to enforcement points on each agent’s Canonical Execution Graph. Automatable controls become rules; manual controls become attestation tasks; the framework coverage percentage is live, not estimated. Malformed rules are quarantined, never silently over-blocked.
Every prove domain — discovery, identity, intent, access, trust, enforcement, audit — emits one signed assertion shape keyed on the agent’s verifiable identity. The sealed audit chain is the substrate; the trust graph is a projection over it. Two queries answer everything: the subject view (everything known about agent X as of time T) and action replay (one governed call walked end-to-end). On top sits the Agent Trust Score™ — a live 0–100 measure that grants autonomy stage by stage and withdraws it automatically on drift. What trust promotes is the agent’s execution posture on its Canonical Execution Graph: steps climb deterministic → hybrid → cognitive as evidence accrues, and demotion snaps the graph back to its proven baseline in seconds. Zero evaluations reads Unrated — never a fabricated number.
Every governed agent on Prove7 is an Agentlet™ — and every Agentlet is one of four archetypes. Different births, same gates: each carries a cryptographic identity, a declared intent, a Canonical Execution Graph, a trust score, and a sealed record, and each moves through the same Build · Decide · Act lifecycle with autonomy that is earned, ceilinged, and revocable.
An agent your team authors on the platform — skills selected from the Skill Center, orchestration drawn as a Governed Workflow, execution mode declared (deterministic, cognitive, or hybrid). Born inside the gates: governance is its native habitat, never a wrapper.
An agent compiled from a versioned source you already trust — a runbook, an SOP document, a spreadsheet process, an approved URL, or a governed workflow — created in one click through AutoX™. The source is fixed at creation and registered as the agent’s ground-truth baseline and judge; the AutoLet starts by replaying it faithfully and earns cognitive autonomy stage by stage, reversibly.
An agent you built elsewhere — LangChain, CrewAI, AutoGen, OpenAI, Bedrock, ServiceNow, UiPath, or plain code — registered and governed through the MCP Gateway or SDK decorator. No rebuild: it keeps its runtime and gains identity, policy, trust, and a sealed record. Verified on its first successful governed call.
System agents that run the platform’s own automated work — discovery sweeps, compliance evidence collection, scheduled governance jobs. Prove7 practices what it enforces: SysLets pass the same gates, carry the same identities, and seal to the same record as every other Agentlet. No privileged shadows.
Continuously walk your runtimes, clouds, and tools and surface every agent that touches your systems, then classify and attribute them. You can’t govern an agent you can’t see.
Each agent bound to a cryptographic identity (SPIFFE · mTLS · OIDC · JWT-SVID), an owner who can be paged, a declared scope, and an authorized intent — so drift is detectable instantly.
Register a proven workflow as the ground-truth judge, then advance a candidate agent through shadow → assisted → supervised → autonomous — only as fast as its sealed conformance allows.
Trust-weighted enforcement at 100% of calls, inline. Allowed autonomy adapts to a live trust score; drift auto-demotes in under a minute and resumes the deterministic path.
Every sealed action becomes a content-addressed, hash-chained, append-only record, captured before execution. Pull any output and the whole lineage comes back — to origin and forward to blast radius.
Every action continuously mapped to SOC 2, ISO 27001/42001, EU AI Act, NIST AI RMF, SR 11-7, and SOX ITGC. Workflow Intelligence reads your runs — cost, latency, override rates, drift — and surfaces what to tune and what’s ready for its next autonomy level.
Prove7 Cloud — fully managed, zero ops — or self-hosted in your own GCP / AWS / Azure estate: Helm-deployed, mTLS everywhere, cosign-signed images. Air-gap-friendly for regulated estates. A global and scoped Kill Switch, Inference Control, Secrets Manager, and multi-tenancy with a promote-to-production gate come standard.
An AI agent governance platform is the runtime layer that controls what AI agents are allowed to do and proves what they did. Prove7 Control Vector governs every agent action inline — identity, intent, policy, trust, and human approval — and seals each action to a tamper-evident, hash-chained audit record that can be replayed end-to-end.
AI usage security tools inspect what people type into chatbots. Prove7 governs what AI agents actually do — the actions they take on enterprise systems. It runs agents inside governance with cryptographic identity, deterministic policy, earned autonomy, and replayable provenance, rather than filtering prompts in transit.
The Cognitive Runtime Engine runs agents with governed LLM tool selection; the Policy Engine enforces deterministic Rego/OPA verdicts at six enforcement points; the Rules Engine compiles policy documents and framework controls into typed enforceable rules; and the Trust Engine & Ontology maintains a signed trust graph and the 0–100 Agent Trust Score that grants and revokes autonomy.
Yes. Prove7 deploys as a fully managed cloud or self-hosted in your own GCP, AWS, or Azure estate via Helm with mTLS and signed images — a fit for banks, insurers, healthcare, and government estates that cannot route agent traffic through a third-party cloud.
If you’re the one who answers when the machine acts — a CISO, a CFO, a COO — watch Prove7 Control Vector™ take an agent from discovered to governed to proven, live.
Schedule a Demo →