This is the tenant your agents, envelopes and audit history will belong to.
Aegis Runtime
Choose your access level
You can change this later — it controls how much of the console is unlocked.
PILOT
For validating the concept
Individuals, developers, design partners
Up to 3 registered agents
Guided Action Envelope builder
Sandbox / simulated execution
Basic approvals & audit history
Limited integrations
BUSINESS
For teams running agents in production
Multiple teams, larger agent estate
Custom Action Envelopes
Agent roles & permissions
Approval workflows & policy templates
Risk ratings, searchable audit
Suspension & revocation
ENTERPRISE
For large, distributed agent estates
Advanced tenant & policy controls
Custom policy hierarchies
Enterprise identity, segregation of duties
Signed & versioned envelopes
Centralised audit & reporting
Dedicated deployment support
Organisation▾
Welcome to Aegis Runtime
Everything Aegis is currently governing, at a glance.
3
registered agents
1
pending approvals
8,421
actions evaluated
Agent health
Agent
Status
Risk
Recent governance activity
Agent Registry
Every agent registered under this organisation, and the authority it currently has.
Agent
Owner
Status
Risk
01 · Identity
02 · Purpose
03 · Risk profile
Agent identity
Registering an agent establishes which autonomous system is being given authority — not just a username.
Agent purpose
This becomes part of the agent's governance record, and helps identify actions outside its intended role.
Risk profile
Aegis uses these answers to suggest a preliminary risk rating, which you can review before it's set.
Aegis suggests: —
Action Envelopes
Define exactly what each agent is allowed to do — and what happens when it asks for more.
First Agent OnboardingAUTHORITY: NONE
Agent registered successfully.
The agent now has an Aegis identity and authentication credential,
but it has zero AI action authority.
Authentication does not grant permission to perform governed actions.
CURRENT AUTHORITY STATE
ZERO ACTION AUTHORITY
Create an AI Action Envelope to explicitly define what this
agent is permitted to do.
Existing envelopes
Agent
Version
Status
Allowed actions
Approval required
AI Action Envelope™ Builder
Define the bounded authority granted to this agent. Anything not explicitly authorised is denied.
Enter one action per line. These are the only actions this envelope grants the agent authority to request.
Enter allowed actions that must receive human approval before execution.
Optionally restrict an action to specific resources.
Enter one resource per line. Leave blank to allow the action against any resource.
Example: allowing customer.lookup
only for customer:C1001 means the
same action against another customer is denied.
DENY — any action not explicitly authorised above is denied.
Resource restrictions are available in this guided builder. Context constraints, amount limits and role controls are supported by the Runtime and will be exposed through the guided builder in a later preview.
Decision Simulator
Test what an envelope would decide before an agent ever acts on it.
Run a test
Optional arguments supplied with the proposed action. Aegis Runtime evaluates the request against the agent's active AI Action Envelope™ and organisation policy.
decision—
reasonSelect an agent and governed action.
request_id—
Policies
Organisation-wide governance controls applied alongside each agent's Action Envelope.
Governance flowRuntime enforcement
Action request
↓
Agent Action Envelope
Is this specific agent authorised to perform the action?
↓
Organisation Policy
Does organisation-wide policy permit the action?
↓
Governance decision
ALLOW · REQUIRE APPROVAL · DENY
↓
Execution / Hold / Block
Organisation policy
Loading organisation policy…
Approvals
Actions waiting on a human decision before they can execute.
Action
Agent
Resource
Status
Review
Audit & evidence
A searchable record of every registration, decision, approval and denial.
Time
Event
Detail
Integrations
Connect AI agents and applications to the Aegis Runtime governance layer.
Runtime API
Submit agent actions to POST /runtime/evaluate
for authority, policy and approval enforcement before execution.
Available
Agent API keys
Manage credentials used by registered agents to authenticate with the
Aegis Runtime API.
Available
Python integration
Python applications can call the Runtime API directly.
A packaged Aegis SDK is not yet published.
SDK not yet published
MCP gateway
Govern MCP-connected agent tool calls through the Aegis authority layer.
Planned
Runtime API integration
Connect your AI agent or application to Aegis before it performs governed actions.
Aegis evaluates the requested action and returns an authority decision.
Endpoint
POST /runtime/evaluate
Authentication
Agent API key
Response
ALLOW · REQUIRE_APPROVAL · DENY
How it works
1. Register the agent
Create the AI agent identity in Aegis.
↓
2. Define its Action Envelope
Specify the actions, resources and authority limits available to the agent.
↓
3. Issue an Agent API key
The application uses this credential to authenticate the agent to Aegis Runtime.
↓
4. Send the action to Aegis
Call the Runtime API before performing the governed action.
↓
5. Enforce the decision
Execute only when Aegis returns ALLOW. Hold actions requiring approval and block denied actions.
Send an action for evaluation
Your application submits the proposed action to Aegis Runtime for governance and controlled execution.
Example response
Handle the Aegis decision
Your application should use the returned decision and status to determine what happens next.
When the status is EXECUTED, the governed action has already been executed through Aegis Runtime. Do not execute the same action again in the calling application.
ALLOWAction executed
Status: EXECUTED. Aegis permitted the action and returns the execution result.
REQUIRE APPROVALAction held
Status: PENDING_APPROVAL. The action is not executed and requires human approval.
DENYAction blocked
Status: DENIED. The action is not executed.
Python example
Call Aegis Runtime from your Python application before allowing the AI agent to perform a governed action.
import os
import requests
AEGIS_RUNTIME_URL = "http://127.0.0.1:8000/runtime/evaluate"
AEGIS_AGENT_API_KEY = os.environ["AEGIS_AGENT_API_KEY"]
response = requests.post(
AEGIS_RUNTIME_URL,
headers={
"Authorization": f"Bearer {AEGIS_AGENT_API_KEY}",
"Content-Type": "application/json",
},
json={
"action": "design.read",
"arguments": {
"design_id": "DESIGN-001"
},
},
timeout=30,
)
response.raise_for_status()
result = response.json()
status = result["status"]
if status == "EXECUTED":
print("Action executed by Aegis")
print(result["result"])
elif status == "PENDING_APPROVAL":
print("Action requires human approval")
elif status == "DENIED":
print("Action denied by Aegis")
Agent credentials
Select a registered agent to manage its Aegis Runtime API credential.
Team
Who has access to this organisation's console.
Name
Role
Add team member
The team member can use this password to sign in to Aegis.