Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Platform · Controls

Every action was permitted. The sequence was not.

A permission check asks "may this caller do this?" one call at a time. An agent can do harm with calls that each pass that check.

Built into the Swiftward service you run.

Who is calling

The user, the agent, or both. Each identity is either stated by your own system, in a header, or proven with a credential the gateway checks. Who is calling matters far more on a tool call than on a model call, because a tool call takes a real action in a real system.

Three levels of what they may do

LevelQuestion
Roles and grantsmay this identity act at all
Endpoint levelmay it call this specific tool
Policy levelis this call, with these arguments, in this sequence, permitted

An agent reads a customer record, looks up an external address, and sends a document to that address. Each call is allowed on its own. Together, on one customer, they are data exfiltration, and a check that looks at one call at a time never sees it.

MITRE ATLAS lists this as AML.T0086, Exfiltration via AI Agent Tool Invocation.

To catch it, the engine keeps state across calls and a rule tests the sequence. This is the same mechanism as business rules, applied to permissions instead of money.

When the agent belongs to another company

Everything above assumes you can look the caller up, and here you cannot. For agents that work across companies on a blockchain, the emerging answer is a public standard, ERC-8004, instead of any one company's registry.

Related: who administers the system · an agent behind three gateways
Book a demo