Aiveris Platform Design partners open

Every agent request meets policy before execution.

Aiveris sits between AI agents and company systems. It binds each request to an identity, limits visible tools, applies policy, collects approval when needed, and records the decision.

Control plane simulator

Run a sample request

Interactive simulation. Sample data. No network calls.

Choose request
Actor
Agent
Tool
Environment
Risk
  1. 01IdentityWaiting
  2. 02ToolsWaiting
  3. 03PolicyWaiting
  4. 04ApprovalWaiting
  5. 05DispatchWaiting
  6. 06AuditWaiting

Policy decision

Ready

Select a request and run it through the control plane.

Rule
Waiting
Dispatch
Waiting

Sample evidence

Audit record

Empty
request_id
waiting
identity
waiting
agent
waiting
tool
waiting
decision
waiting
rule
waiting
args
waiting
previous_hash
waiting
own_hash
waiting

Sample request ready.

Request lifecycle

Six control points. One decision path.

Agent sends intent. Gateway decides which authority the request earns before any company system receives it.

Run another request ↑
01

Bind identity

Validate the bearer JWT against configured JWKS. Production identity mode rejects anonymous requests and development identity headers.

02

Limit tool surface

Resolve the approved route or tool namespace. MCP preview surfaces strip unsafe description text and quarantine tools that fail sanitization.

03

Evaluate policy

Cedar or database rules return allow, deny, or require approval. A missing evaluator or policy error fails closed.

04

Collect approval

Queue sensitive requests for a named reviewer. Slack can deliver the notice. Pending requests expire after a configured time limit.

05

Dispatch with scope

Forward allowed requests with bounded authority. Exchange tokens carry audience, scope, and expiry. Raw upstream credentials stay inside the gateway.

06

Record evidence

Capture the decision, reason, timing, and configured argument record. SHA-256 links each event to the previous event for later integrity checks.

Security boundary

One governed route between agents and systems.

Teams control identity, policy, credentials, and evidence at one boundary. Each upstream keeps its existing API and permission model.

Requesters

Agents arrive with identity and intent.

  • Internal agents
  • Developer tools
  • Workflow automation

Aiveris boundary

Gateway control plane

JWKS identity Namespaces Cedar policy Approvals Rate limits Redaction

Upstreams

Approved systems receive bounded calls.

  • SaaS APIs
  • Code repositories
  • Data and internal services
Decision evidence JSONL / Postgres / S3 Argument capture mode: hash, redact, full, or omit

Agent receives

Enough access for the approved job.

  • Visible routes or tool namespaces allowed for its identity
  • Clear response when policy allows, denies, or requires approval
  • Approval status for requests placed on hold
  • Upstream response after policy permits dispatch

Gateway retains

The controls agents should never own.

  • Raw upstream credentials and token signing material
  • Policy bundles, admin authority, and reviewer decisions
  • Rate limits, redaction rules, and audit sink settings
  • Evidence showing why each request moved or stopped

Current product boundary

What teams can evaluate today.

Current claims follow the platform repository and launch evidence. Preview surfaces stay labeled until they reach the same control coverage.

Current path

HTTP reverse proxy

Control plane for design partners with policy before dispatch, approval handling, identity binding, durable state, and configured audit sinks.

Gate: machine checks plus a live environment smoke before customer use.

Local bridge

MCP stdio

Local protocol bridge with policy enforcement and an audit file required by default. HTTP remains the customer boundary.

Use: controlled local evaluation.

Experimental

MCP SSE

Inbound transport bound to loopback and guarded by an admin token. It does not yet match HTTP policy, audit, and inventory coverage.

Use: protocol testing only.

Human gate

Customer-specific readiness

Access review sign-off and customer evidence remain required. Software checks cannot close those decisions.

Owner: customer and designated reviewers.

Policy choices

Allow. Deny. Require approval.

Rules can use caller identity, groups, route or tool, environment, and request context. Policy errors stop execution.

Evidence controls

Choose the audit detail.

Argument capture supports hashed, redacted, full, or omitted modes. Exchange credentials are fingerprinted without storing raw token values.

Customer control

Run inside your environment.

Deploy the Go gateway with your identity provider, rules, databases, object storage, and upstream credentials.

Design partner path

Start with one agent workflow worth controlling.

Choose a risky tool call. Define identities and approval rules. Inspect the audit trail with your security team before adding another system.