COMPANY BRAIN
COMPANY BRAIN / AGENT GOVERNANCE

Permission is not
truth.

Every agent-governance platform answers whether the agent was allowed to act. Company Brain answers whether it should have.

01

THE GAP

WHAT ACCESS CONTROL CANNOT SEE

Allowed to act.
Not allowed to be wrong.

An agent can pass every identity, tool-access and action-scope check an access-control platform runs—and still act on a policy that changed six weeks ago. Company Brain is the check built for that gap.

ONE AGENT / ONE DECISION“Can I approve this refund?”REQUEST: $750
CHECK 01 / ACCESSYOUR EXISTING CONTROLS

Is the agent allowed to act?

Access controls answer who can use which tool—and within what limits.

Identity verifiedTool access allowedAction scope in bounds
CHECK 02 / KNOWLEDGECOMPANY BRAIN

Is the knowledge safe to use?

Knowledge controls answer whether the guidance is current, owned and released for use.

Source v18.2 currentOwner approvedAnswer impact released
CHECK 03 / EXECUTIONCOMPANY BRAIN

Is the intelligence allowed to run this workload?

Execution controls answer whether the model and provider are approved for this workload, inside its cost and quality boundary.

Model approvedProvider in policyCost / quality in bounds
ONLY WHEN ALL ARE TRUEAccountable AI.

The agent has permission, current knowledge and an approved execution path.

01B / THE LANDSCAPE

Access-shaped.
Not truth-shaped.

Access-control platforms answer who may act and on which tool. None of them answer whether what the agent just said is still true. Five factors an access-control review will not surface.

Decision factorCompany BrainKnowledge governanceAccess-control platformsIdentity & permissions
Answer withdrawal on source changeWhat happens to an agent's answer when the policy behind it changes.In progress: a drift alert opens immediately; automatic pausing of the affected skill is on the roadmapNot addressed — permissions unchanged when policy changes
Named human approval before publicationWhether a person must approve knowledge before an agent can use it.Required by designOptional workflow, not a publication gate
Version attribution on every answerWhether an answer is tied to the exact source version it came from.Source + version + owner attachedCitations to documents, not to versions
Detecting contradiction between two approved sourcesWhat happens when two policies that are both technically approved disagree.In progress: conflict detection runs while new skills are synthesised; continuous review across the published corpus is on the roadmapNot addressed
Evidence export for a single answerWhat you can hand an auditor for one specific agent decision.Evidence PackActivity logs

"Access-control platforms" describes identity, tool-access and agent-permission systems generally; it is not a claim about any single named vendor. Rows marked "in progress" describe engineering work under way, not a shipped capability—see the assurance roadmap for status definitions. Reviewed August 2026.

02 / LIVE CONTROL

See the moment an agent
loses its authority.

A tool-access policy update should reach every agent immediately—not after a review backlog. Compare the source, approval and agent outcome in one control view.

INTERACTIVE DEMONSTRATION
CONTROL DELTA / PROCUREMENT AGENT SCOPEANSWER LIVE
PREVIOUS SOURCEv4.1

Auto-approval limit for purchase orders

$2,000Procurement Operations / approved
GOVERNED SOURCEv4.2

Auto-approval limit for purchase orders

$500Prepared for named owner review
AGENT ANSWERCan I auto-approve a $1,200 purchase order?
LIVEYes — within auto-approval limit
RECEIPTSOURCE → OWNER → ANSWER IMPACTVersion linked
03 / HOW IT WORKS

Three moves.
One accountable agent.

A physical flow from governed source documents, through human approval, to agent-ready knowledge
GOVERNED FLOWSOURCE HUMAN AGENT
01

Connect the policy source.

Bring the policies and rules an agent's decisions depend on into one governed layer.

02

Approve what is true.

A named reviewer approves the rule before any agent can act on it.

03

Stay current.

When the rule changes, every affected agent answer is flagged for review until a correction is approved.

04 / EVIDENCE

Every governed decision
has a receipt.

An Evidence Pack keeps the source, the accountable owner, the change event and the affected agent answer in one reviewable record—the record an activity log was never designed to produce, because it does not track whether the underlying policy is still true.

EVIDENCE PACK / CB-024 REVIEWABLE
GOVERNING SOURCEPOLICY / REFUNDS
v18.2

Updated 14 May 2026 · Finance Operations

HUMAN APPROVALPriya N. / Head of Claims

Approved for agent use · 14:42

CHANGE EVENT$300 $750

Approval limit revised in source policy.

AGENT IMPACT2 ANSWERS FLAGGED
ILLUSTRATIVE CONTROL RECORDORIGIN OWNER IMPACT
05 / WHERE IT FITS

Keep your stack.
Add the missing check.

Your identity provider

Stays in charge of who an agent is. Company Brain does not touch authentication or SSO.

Your access-control platform

Stays in charge of what an agent may touch, and within what limits. That job does not move.

Company Brain

Governs whether the knowledge behind an already-authorised action is still current, owned and approved.

WHAT THIS DOES NOT DO / 01

Does not replace IAM

Identity, authentication and single sign-on remain your identity provider's job.

WHAT THIS DOES NOT DO / 02

Does not replace runtime sandboxing

What an agent is technically capable of executing is controlled by your agent runtime, not by Company Brain.

WHAT THIS DOES NOT DO / 03

Does not certify compliance

No product can certify EU AI Act, SOC 2 or ISO 27001 compliance on its own. Company Brain supports the evidence and record-keeping those obligations require.

WHAT THIS DOES NOT DO / 04

Does not execute write actions in the launch package

The current launch scope does not promise agent write-actions in external systems; that is gated separately.

06 / THE BUYER TEST

One question
settles it.

Ask your platform this.

"If the policy behind an agent's answer changed yesterday, would the answer already reflect it—or would it take a person noticing?" If the honest answer is "a person noticing," permission was never the whole story.

AGENT GOVERNANCE / FAQ

Questions a risk
officer will actually ask.

AGENT GOVERNANCE / FAQ ANSWERED DIRECTLY
01Is this the same as an access-control or IAM platform?

No. Access-control platforms decide whether an agent is allowed to act. Company Brain decides whether the knowledge behind that action is still current and approved. Most customers run both, side by side.

02Does passing both checks guarantee the answer is correct?

No. It guarantees the agent was authorised and the answer traces to a current, named-owner-approved source—not that the source itself is free of human error.

03What happens when a policy the agent relies on changes?

A drift alert opens immediately and the affected skill is flagged in the review queue. A named reviewer can correct it with one click—including rewriting the source document itself where write-back is connected. Automatically pausing the skill while it is under review is on our roadmap, not shipped today.

04Does this make agent behaviour EU AI Act compliant?

No product can make an organisation compliant on its own. Company Brain supports the record-keeping and traceability work Articles 11–13 require, as part of a wider compliance-readiness programme.

05What does a first engagement look like?

A scoped engagement around one high-risk agent decision: connect its governing source, name a reviewer, and watch one policy change reach the agent.

SCOPE THE CONTROL

Scope the control
around your organisation.

Tell us which agent decisions carry the most risk. We will map the access checks you already run against the knowledge checks you do not.

Start a scope