agnt8x

Govern agents where they run.
Build the ones you need.

The agnt8x Capability Map
Select a line
Gd Guardrails Av Approvals Ks Keystone Ve Veritas Ev Evidence Cr Crucible Au ASIC Us SEC Uk FCA Eu EU Act Sg MAS Ae ADGM Hk HKMA Jp JFSA Pa Passport Cd Conductor Lp Loops Pm Prism Sn Sentinel Mn Manage Br Broker Em Embassy Md Mandate Xc EXC Py Payments Vc Cards Li Limits Fn Find Fo Forge Bd Builder St Studio Ea EAM By BYOK Tm Templates Ec Echo Px Praxis Cx Context Ig Ingest Kb Knowledge Bg Budgets Co Cost Tr Traces Si Signal Al Alerts

Start with either mode. Most institutions end up using both, under one Passport, one set of data tiers and one record.

01

See every agent

Copilot, Claude, ChatGPT and in-house agents registered where they already run, each with a Passport, a named owner, a posture and a data tier. Observed takes hours, not a rebuild.

02

Control what they touch

Sensitive actions become tools served by the agnt8x governed broker. Identity and grant are re-checked on every call, and a tool revoked in agnt8x is refused mid-conversation.

03

Keep one record

VERITAS writes every governed action, on every platform, to one exportable record in your own database, and SIGNAL streams it to your SIEM.

04

Move only what needs moving

Most agents stay on their own platform. An agent comes onto agnt8x only when it needs a certified model, a jurisdiction lock or output a supervisor must be able to verify.

Proven on Microsoft Copilot Studio Proven on Claude Managed Agents Proven on ChatGPT agents Agentforce and Workday designed
01

Compose

Build agents without code in STUDIO and onboard them like a new hire: role, scope and business context. Or import a Copilot or Claude agent with its instructions, memory and files.

02

Teach

PRAXIS puts a person between the agent and anything it learns. ECHO keeps its memory, with provenance, in your own database rather than in the model.

03

Certify

CRUCIBLE tests every task. KEYSTONE certifies each model against your own task battery before it is allowed to run anything regulated.

04

Deploy

PRISM runs each task on a certified model within its data tier, hosted or in your own cloud. CONDUCTOR turns a procedure document into a governed, multi-agent workflow loop.

In production today, a client's compliance reviewer turned a new document format into a certified workflow loop, with no help from us.

EMBASSY
Cloud agnostic. The whole control plane, inside whichever cloud you run.
We do not sell a cloud, so we have no reason to prefer one. EMBASSY runs agnt8x inside your own AWS or Azure account, in your own region, on your own keys, with no route to the internet and no runtime data access for us. The same image and the same code run on either cloud: the difference between two client deployments is signed profile data, never a code branch.
01

Residency you can prove

The compute identity allows in-country model profiles and denies cross-border ones, so residency holds even if the application above it is misconfigured.

02

The record stays inside

VERITAS lives in your database with the retention you set. Agent memory runs as embedded open source against it, with no third-party memory service in the path.

03

Credentials stay inside

Long-lived secrets never leave the perimeter, and agent platforms receive only short-lived tokens. From outside we see health, version and volume, nothing else.

AWS: installed in a regulated client's account Azure: built and demonstrated SOC 2 Type I held SOC 2 Type II in progress

Learn the platform on a self-serve plan before you bring it into your institution. Identity, enforcement and evidence ship at every level, including the smallest plan. There is no governance tier, because a control you can decline to buy is not a control.

01

Two governed agents

One seat and one workspace, with a Passport and an audit record on every agent, built in Studio on any certified model.

02

Free for 30 days

Starter credits included. Carry on for a monthly fee, or close the account. Talk to us when you want more agents.

3
Frontier agent platforms governed in production
Any
Certified model, on AWS or Azure: cloud agnostic
SOC 2
Type I held, Type II in progress

The argument

Two populations of agents.
One control plane.

The same institution runs both kinds, often on the same data. No supervisor has ever accepted that the second kind is out of scope because a human never touched it.

Agents that work like staff

Conversational. They sit in an org chart, hold an email address, work a queue and escalate to a person, reached by email, Slack, chat, API and on calls. Increasingly built in Copilot Studio, Claude and ChatGPT by the business itself.

They need a named owner, a scope, a review point and a way to remove them.

Bought by a line of business, with risk looking over its shoulder.

Agents that work like systems

Invoked over an API by another system, at volume, with no person in the loop. Built by platform and infrastructure teams, and increasingly called by one another.

They need identity, authority limits, residency enforcement and a record every bit as much.

Bought by platform engineering, architecture and the CIO.

Most of the market has picked one of these and built for it. Sell to the business and you build an org chart and forget the API surface. Sell to the platform team and you build a gateway and forget accountability. agnt8x governs both, through the same Passport, the same data tiers and the same record, and lets one agent call another under that same control.

How the Agent Passport works Who we are

Built for sectors where someone answers for the agent.

The controls are the same in every sector: an identity, a scope, a data tier, a certified model and a record you hold. What changes is the regulator asking, and the work the agents do.

Financial services

Live engagements in Australia, New Zealand and the UK

Operational resilience and information security rules such as APRA CPS 230 and CPS 234, DORA and the FCA Consumer Duty already reach the systems your agents act through. agnt8x gives each agent an accountable owner, enforces what data it may touch, and keeps evidence an examiner will accept, across every vendor in the estate.

Retail banking

Responsible lending assessment, hardship triage and customer servicing, with personal data held to in-jurisdiction certified models and every decision recorded.

Wealth

Advice file review, fee disclosure checks and member communications for advice firms and pension funds, with a person approving what the agent learns.

Insurance

Claims triage, policy and underwriting file checks and complaints handling, with each check certified against your own cases before it runs.

Energy and utilities

Agents handling billing disputes, hardship and vulnerable-customer cases, outage communications and field work orders, in organisations that critical-infrastructure rules such as the SOCI Act and NIS2 already cover.

What matters: anything that acts on operational systems is Brokered, so a tool can be revoked in the middle of a task.

Government

Agents triaging correspondence, summarising cases and drafting responses for departments and agencies that must keep public records and keep data in the country.

What matters: EMBASSY inside the agency's own cloud account, on its own keys, with a record that survives any vendor.

Telecommunications

Agents handling service activations, fault and outage enquiries, billing disputes, porting and complaints, under consumer protection and financial hardship codes and the rules covering networks as critical infrastructure.

What matters: customer identity and personal data held to their tier, and anything touching the network or provisioning stack is Brokered.

Consumer sectors

Retail, travel, hospitality and other consumer businesses running agents for customer service, complaints and returns at volume, under privacy and consumer protection law.

What matters: personal data held to its tier, cross-border routing denied, and each task on the cheapest certified model.

An agent does not have to move to be governed.

Posture is chosen agent by agent, according to what the agent does. Every change is recorded on its Passport with the preconditions that justified it, and moving back down keeps its identity and history. It is a reversibility ladder, not a migration ladder.

Observed
See what is already running
Adopted in hours
Registered with a Passport, a named owner, a data tier and an audit record, while it keeps running exactly where it runs. Drift is detected when its published definition changes. No work for platform teams. Most agents start here.
What you gain: a complete, independent list of every agent, who owns it and what it touches.
Brokered
Govern the boundary, not the agent
Hours per agent
The agent stays on its platform and draws its sensitive tools, a payment gate or a certified compliance check from the agnt8x broker over MCP. Identity, posture and grant are re-checked on every call, and a revoked tool is refused mid-conversation with an audit reference.
What you gain: the ability to empower an agent, and to stop its action, without asking the vendor.
Resident
Run on the control plane
Per agent
Built in agnt8x, or imported with its instructions, memory and files. It starts on probation with tools proposed rather than granted, and where guardrails differ the stricter one wins. The original keeps running, and a fidelity report states what came across.
What you gain: the choice of which model it uses, where it runs and on whose infrastructure.

Running on three frontier agent platforms today.

Proven means running in agnt8x production and demonstrated end to end against a live platform tenant. Built means implemented and tested. We mark every claim, so you do not have to guess which is which.

CapabilityMicrosoft Copilot StudioClaude Managed AgentsOpenAI ChatGPT agents
Observed: registered with a Passport, posture and audit recordProvenProvenProven
Brokered: tools drawn from the governed broker, revocable mid-conversationProvenProvenProven
Invoked by agnt8x on its own platform, exchange recordedProvenDirect LineProvenSessions APIWaiting on OpenAITrigger error reported to OpenAI
Resident: copied into agnt8x with a fidelity reportProvenRead from DataverseProvenInstructions, memory, filesBuiltDeclared instructions
Orchestrated by an agnt8x agent across platformsProvenProvenWaiting on OpenAI

The demonstration that matters. An agnt8x agent put one question to a Copilot Studio agent running in Microsoft and to a Claude agent running at Anthropic on agnt8x-governed tools, then returned one answer attributing each part to its source. Every call carried the requester's identity into the audit trail.

Next, on the same adapter. Salesforce Agentforce through its Agent API and session tracing, and Workday through its Agent System of Record and Agent Gateway. Both are designed, not built.

Certified checks any agent can call.

Because the broker serves tools to agents on every platform, it can serve regulated judgement too. The calling agent stays where it runs. The certified result, and the evidence behind it, come from agnt8x.

Pn
Pensions
Member communication checks, transfer scam indicators, and the boundary between guidance and advice.
Wa
Wealth and advice
Advice file review, in use with a wealth and advice firm today, and fee disclosure checks.
Bl
Banking and lending
Responsible lending assessment, available today as an agnt8x agent, and hardship triage.
Or
Operational risk
Information security control review against APRA CPS 234, available today.
Ks
The governed envelope
Returned on every call, from any platform
Certified
ResultThe business answer
ReasonsPlain-language basis, citing the rule applied
Rule set and versionWhich version of the standard was used
CertificateThe certified model and procedure behind it
Review flagWhether a person must check it first
Evidence referenceThe record, in your own database
A regulated check owned by the platform whose agents call it could never be neutral.

The five questions risk committees put to us.

The first four come up in every pilot conversation, in roughly this order. The fifth is the one that decides it, and it is a risk question rather than a procurement one.

QuestionWhat they askWhat agnt8x produces
InventoryHow many agents are running here, including the ones other systems call over an API, and who owns each?A live register across Copilot, Claude, ChatGPT and agnt8x agents, each with a Passport, a named owner, a posture and a data tier. Observed takes hours, not a rebuild.
AuthorityUnder whose authority does each one act, and which class of data may it touch?Passport scope and an operating tier. Classification enforced as a floor on every workflow step. Tools granted agent by agent through the governed broker, revocable mid-conversation.
EvidenceWhat did each one actually do, and can we prove it to an examiner afterwards?VERITAS: one vendor-neutral record across every platform, held in your own database, exportable, and streamed to your SIEM through SIGNAL.
ContinuityIf a model is withdrawn, repriced or fails certification, what happens to the work?KEYSTONE certificates per task. PRISM reselects from the certified set within the data tier, and records what else was eligible and why it was not chosen.
ExitIf we leave you, what do we keep?An open agent manifest, a portable Passport, full export, and a fidelity report that prices any move in advance, including a move out of agnt8x.

Where we can, the evidence is the other party's own output, not a screenshot of our dashboard.

Revocation inside three vendors' agents
A tool revoked in agnt8x was refused inside a live Copilot conversation, a live ChatGPT agent and a live Claude agent, each with an audit reference, while the agent's other tools kept working.
Residency refused at the identity layer
A cross-border model profile returned an explicit deny from the same compute identity that had succeeded in-country seconds earlier. Recorded in the cloud provider's audit log, not ours.
Failures recorded as failures
Copilot returns its errors as ordinary chat text. agnt8x detects them and records a failure with its error code, so an audit trail never counts a broken exchange as an answer.

Neutrality is a precondition, not a feature.

Every platform now has its own agent control plane, and each governs its own ecosystem well. The question is who governs across them, and on whose behalf.

A model vendor

cannot certify a competitor's model against your tasks, and cannot fail over to one when its own is unavailable or withdrawn. That decision is never disinterested.

A hyperscaler

governs its own ecosystem well and everything else by exception. Identity, perimeter and commercial centre of gravity stay inside its environment: the concentration you were trying to avoid.

An agent builder

that grades its own agents from a record it keeps is marking its own homework. The test is whether the evidence belongs to you and whether someone else can check it.

A system of record

can hold the register, and several now do it well. The assurance model, the evidence format and the escalation path stay anchored to that vendor's platform.

We do not train models and we do not sell a cloud, which is why agnt8x is model agnostic and cloud agnostic by design. We do build agents, and ours meet the same test as everyone else's: certified against your own tasks, recorded in your own database, and open to any other tool to assess. Neutrality is a property of what we do not sell and what we do not keep.

Alongside Agent 365, not instead of it. If you have invested in Agent 365 and Copilot Studio, keep Microsoft as the identity and security layer for the Microsoft estate. agnt8x links each Passport one-to-one to its Entra Agent ID, governs what non-Microsoft agents do at runtime, and keeps the record across vendors neutral and in your hands. That separation is the concentration risk the UK Critical Third Parties regime, DORA and APRA CPS 230 now address directly.

We publish the route out.

Almost all of the durable value in a deployed agent sits in its configuration, business context, memory and earned record, not in the model weights. So the route out is open, including out of agnt8x. A control plane that sells itself as neutral while charging for the exit is not neutral.

EAM
The agent manifest
An open, Apache 2.0 description of what an agent is, independent of any runtime. Publicly committed for donation to a neutral foundation. It will never appear on an invoice.
Passport
The portable identity
A cryptographic, KYC-bound credential carrying scope, verification status and earned record, linked to Entra Agent ID where one exists. Designed to move, including out of agnt8x.
Fidelity report
The exit is priced
Every move between postures and between platforms reports what transferred and what did not, so the cost of leaving is visible before anyone commits, in either direction.
Read the EAM spec View on GitHub

// Frequently asked

Common questions

What is agnt8x?

agnt8x is a neutral control plane for regulated organisations running AI agents on Microsoft Copilot, Claude, ChatGPT and their own platforms. It governs those agents where they already run, and gives you a platform to build, certify and deploy new ones, under one identity, one policy and one record you hold yourself. It is model agnostic and cloud agnostic: hosted by us, or inside your own AWS or Azure account.

See how it works

Who is agnt8x for?

Regulated organisations where a named person has to answer for what an agent did: financial services (retail banking, wealth and insurance), energy and utilities, telecommunications, government, and consumer businesses handling personal data at scale. Risk, compliance and platform teams use it to govern the agents already in flight. Business teams use it to build agents for regulated work without waiting for engineering.

See the sectors we support

How is agnt8x different from ChatGPT or Claude?

ChatGPT and Claude are where agents run. agnt8x is where they are governed. It registers Copilot, Claude and ChatGPT agents with a Passport and a named owner, serves and revokes their sensitive tools mid-conversation, and keeps one record across all of them in your own database. Agents built on agnt8x run each task on a model certified against your own tasks. We do not train models or sell a cloud, so we have no reason to prefer one.

Does an agent have to move onto agnt8x to be governed?

No. Agents are governed in one of three postures. Observed agents are registered and monitored where they run. Brokered agents stay on their platform and draw their sensitive tools from agnt8x. Resident agents run on the agnt8x control plane. Posture is chosen agent by agent, and moving back down keeps the agent's identity and history.

Is agnt8x cloud agnostic?

Yes. We do not sell a cloud, so we have no reason to prefer one. agnt8x runs as a hosted service, or as EMBASSY inside your own AWS or Azure account, in your own region, on your own keys, with no route to the internet and no runtime data access for us. The same image and code run on either cloud.

Discuss an EMBASSY deployment

Does agnt8x replace Microsoft Agent 365?

No. We recommend co-existence. Microsoft stays the identity and security layer for the Microsoft estate, agnt8x links each Passport one-to-one to its Entra Agent ID, and the record across vendors stays neutral and in your hands.

Can I try agnt8x without paying?

Yes. The self-serve plan is free for 30 days, with one seat, up to two governed agents and starter credits included. For organisations, we start with a live demonstration on real platform tenants, then a scoped pilot on your own agents.

Book a demo

What is the difference between an AI agent and an AI chatbot?

A chatbot answers questions. An agent takes actions: it reads documents, calls tools, updates systems and hands work to other agents, sometimes with no person in the loop. That is why an agent needs what a chatbot does not: an identity, limits on what it may touch, a certified model for regulated tasks, and a record an examiner can check afterwards.

See it live

Watch a tool revoked inside Copilot, Claude and ChatGPT.

A live demonstration on real platform tenants, then a conversation about which of your agents to govern first and which, if any, to build.

Book a demonstration enterprise@agnt8x.ai