Run AI agents in production without losing the audit trail.

Every agent runs under a scoped identity, is checked against policy in real time, and leaves a signed record of what it did.

AccessNo standing access
ControlHumans keep the final say
ProofEvery action, signed
Why it matters

Accountable for the agent. Missing the controls.

Every function accountable for an autonomous agent is missing the one thing it needs at the point of action.

Security
No enforcement at the point of action.
Unanswered
Risk
No tamper-evident audit of agent decisions.
Unanswered
Finance
An agent can burn an unbounded budget.
Unanswered
Regulator
Nobody can reconstruct what happened.
Unanswered
Tovel is the runtime that closes the gap.
How Tovel works

Discover what is running. Govern how it runs. Put it to work.

One continuous path, from the agents already loose in your estate to a governed fleet you can put to work, with evidence at every step.

Live inventorywatching 24/7
billing-agent FOUND
mcp · github FOUND
svc-agent · prod SHADOW
support-copilot FOUND
01 Discover

Every agent, the moment it appears.

Tovel keeps a live inventory of every agent and MCP server across your cloud accounts, and flags shadow agents as soon as they spin up.

Explore the product
OWASP LLM OWASP Agentic NIST AI RMF
ISO 42001 MITRE ATLAS EU AI Act AU AI Safety
tool call
approved
02 Govern

Prove how every agent runs.

Score posture against the frameworks that matter, route high-consequence actions to a human, and sign every decision.

How governance works
Application · Storefront
Agent fleet · 3 active
SignedEvery action
GatedHigh-risk
SealedEvidence
03 Put to work

Put agents to work at scale.

Each application runs as one sealed enclave, with every action of its agent workforce governed and measured continuously.

See the enclave
The product

The governed runtime for the whole agent fleet.

Every enclave runs the same six-layer harness: inventory, posture, approvals and evidence, scoped and signed on every turn.

Fleet map/storefront
ap-southeast-2 live
Agent inventoryBedrock · AgentCore
All 46 Governed 45 Shadow 1
AgentModelToolsStatus
refunds-copilotstorefront · T2
claude-sonnet-46 MCPGoverned
payments-agentstorefront · T1
claude-opus-49 MCPGoverned
scraper.unmanagedoff-platform
model unknownShadow
46 agents · 45 governed1 shadow held at boundary
Security postureContinuous
92A
Residual risk Low · within board appetite
Posture · 12 wk+4 pts
Critical 0 High 2 Medium 5 Low 9
Control domainCoverage vs appetite
Identity & access96
Tool least-privilege92
Prompt-injection defence88
Data provenance & residency94
Human oversight97
Assessed continuously against your enabled framework packs1 domain below appetite
Approval queue3 waiting · Rule-of-Two
Export customer dataset8,412 recordsrisk · high
tool: data.export → analytics-workspace · via AgentCore Gateway · analytics-agent
Sensitive PII Cross-boundary Bulk export
d.okafordata protection officer waiting 2m 14s
Also in queue
Publish KB article externallycontent-agentwaiting 0m 40s
Merge PR · change access policydevops-agentwaiting 5m 02s
Requested by analytics-agent · export #DX-2291held · awaiting DPO sign-off
Evidence recordSealed7-yr retention
Record
EVR-DX-2291 · data export
Actor
analytics-agent claude-sonnet-4 · AgentCore
Accountable
R. Mehta · Head of Data
Data touched
8,412 records · PII / Confidential
Authorised by
d.okafor · DPO · 14:22:41 AEST
Residency
ap-southeast-2 · AU only
Controls
Guardrails · least-privilege · residency
Tamper-evident chain · 6 spans · SHA-256
Sealed to the evidence locker✓ replayable end to end
  • 01 Shadow agents, caught on sight

    Any agent running outside an enclave is flagged the moment it appears, and held before it touches production.

  • 02 Security posture, graded live

    Risk and control coverage scored from real runtime signals, mapped to the frameworks that apply to you.

  • 03 High-consequence actions wait for a human

    Anything above your risk threshold pauses for a named approver, with full context, before it runs.

  • 04 Audit-ready evidence, mapped to your regulator

    Every agent-involved action is sealed into a tamper-evident record, ready to show an auditor.

The harness

Enterprise controls, enforced on every agent action.

Every turn passes through the enclave's control layers before it acts: the plan is verified, tools and data are gated, high-consequence actions wait for a human, and the full trajectory is sealed to evidence.

Select a layer to see what it enforces
Data residency
Data and inference stay in Australia on AWS Bedrock and AgentCore.
Signed evidence locker
Append-only, hash-chained, exportable for board and auditor review.
HITL by default
High-consequence actions route to a named human before they run.
Read-only by default
Agents receive least-privilege scopes; every write is gated and attributed.
Framework packs shipped
OWASP LLM Top 10OWASP Agentic ASI01–10NIST AI RMFISO 42001MITRE ATLASEU AI ActAU AI Safety

Posture is scored against these packs only. Tovel does not claim coverage of frameworks it has not shipped.

See every agent, action, and decision in one place.

A 30-minute walkthrough on your own architecture: the harness, the maturity matrix and the evidence a board can read.