Is the agent allowed to act?
Access controls answer who can use which tool—and within what limits.
Every agent-governance platform answers whether the agent was allowed to act. Company Brain answers whether it should have.
THE GAP
WHAT ACCESS CONTROL CANNOT SEE
An agent can pass every identity, tool-access and action-scope check an access-control platform runs—and still act on a policy that changed six weeks ago. Company Brain is the check built for that gap.
Access controls answer who can use which tool—and within what limits.
Knowledge controls answer whether the guidance is current, owned and released for use.
Execution controls answer whether the model and provider are approved for this workload, inside its cost and quality boundary.
The agent has permission, current knowledge and an approved execution path.
✓Access-control platforms answer who may act and on which tool. None of them answer whether what the agent just said is still true. Five factors an access-control review will not surface.
| Decision factor | Company BrainKnowledge governance | Access-control platformsIdentity & permissions |
|---|---|---|
| Answer withdrawal on source changeWhat happens to an agent's answer when the policy behind it changes. | In progress: a drift alert opens immediately; automatic pausing of the affected skill is on the roadmap | Not addressed — permissions unchanged when policy changes |
| Named human approval before publicationWhether a person must approve knowledge before an agent can use it. | Required by design | Optional workflow, not a publication gate |
| Version attribution on every answerWhether an answer is tied to the exact source version it came from. | Source + version + owner attached | Citations to documents, not to versions |
| Detecting contradiction between two approved sourcesWhat happens when two policies that are both technically approved disagree. | In progress: conflict detection runs while new skills are synthesised; continuous review across the published corpus is on the roadmap | Not addressed |
| Evidence export for a single answerWhat you can hand an auditor for one specific agent decision. | Evidence Pack | Activity logs |
"Access-control platforms" describes identity, tool-access and agent-permission systems generally; it is not a claim about any single named vendor. Rows marked "in progress" describe engineering work under way, not a shipped capability—see the assurance roadmap for status definitions. Reviewed August 2026.
A tool-access policy update should reach every agent immediately—not after a review backlog. Compare the source, approval and agent outcome in one control view.
Auto-approval limit for purchase orders
$2,000Procurement Operations / approvedAuto-approval limit for purchase orders
$500Prepared for named owner review
Bring the policies and rules an agent's decisions depend on into one governed layer.
A named reviewer approves the rule before any agent can act on it.
When the rule changes, every affected agent answer is flagged for review until a correction is approved.
An Evidence Pack keeps the source, the accountable owner, the change event and the affected agent answer in one reviewable record—the record an activity log was never designed to produce, because it does not track whether the underlying policy is still true.
Updated 14 May 2026 · Finance Operations
Approved for agent use · 14:42
Approval limit revised in source policy.
Stays in charge of who an agent is. Company Brain does not touch authentication or SSO.
Stays in charge of what an agent may touch, and within what limits. That job does not move.
Governs whether the knowledge behind an already-authorised action is still current, owned and approved.
Identity, authentication and single sign-on remain your identity provider's job.
What an agent is technically capable of executing is controlled by your agent runtime, not by Company Brain.
No product can certify EU AI Act, SOC 2 or ISO 27001 compliance on its own. Company Brain supports the evidence and record-keeping those obligations require.
The current launch scope does not promise agent write-actions in external systems; that is gated separately.
"If the policy behind an agent's answer changed yesterday, would the answer already reflect it—or would it take a person noticing?" If the honest answer is "a person noticing," permission was never the whole story.
No. Access-control platforms decide whether an agent is allowed to act. Company Brain decides whether the knowledge behind that action is still current and approved. Most customers run both, side by side.
No. It guarantees the agent was authorised and the answer traces to a current, named-owner-approved source—not that the source itself is free of human error.
A drift alert opens immediately and the affected skill is flagged in the review queue. A named reviewer can correct it with one click—including rewriting the source document itself where write-back is connected. Automatically pausing the skill while it is under review is on our roadmap, not shipped today.
No product can make an organisation compliant on its own. Company Brain supports the record-keeping and traceability work Articles 11–13 require, as part of a wider compliance-readiness programme.
A scoped engagement around one high-risk agent decision: connect its governing source, name a reviewer, and watch one policy change reach the agent.
Tell us which agent decisions carry the most risk. We will map the access checks you already run against the knowledge checks you do not.
Start a scope →