Onboarding design partners

Every AI agent in your enterprise. Accounted for.

Calvari is a control plane for AI agents — a system of record that answers what exists, what it can reach, what it did, what it cost, and what it was worth. Across every vendor and framework. Provable to an auditor.

Read-only to start. No migration, no rewriting your agents, no runtime to adopt.

The five questions

Five questions no single tool answers today

Your observability stack sees traces. Your IdP sees identities. Your finance tools see a single line item from one vendor. None of them can tell you who owns the agent that spent it, or what it was allowed to touch.

01

What exists

Every agent across OpenAI, Anthropic, Bedrock, Entra and homegrown frameworks — with a named owner and a sponsor.

02

What it can reach

Declared tool scopes and standing credentials, versioned as policy, with drift from the declaration surfaced.

03

What it did

A per-tenant hash chain of actions, anchored to write-once storage, verifiable by an open-source CLI.

04

What it cost

Spend attributed per agent against versioned price sheets, with budgets and projected-overrun alerts.

05

What it was worth

Outcomes counted, then netted against cost — with every assumption printed beside the number.

Day one

What the first scan usually finds

These are the three findings that make a security team stop the meeting. They are not hypothetical failure modes — they are what an unmanaged agent estate looks like from the inside.

Unowned

Agents nobody owns

The engineer who built it changed teams. The agent still runs, still holds its keys, and no name on the org chart is accountable for it.

Standing access

Credentials that never expire

A long-lived provider key pasted into an environment variable two quarters ago, scoped to everything, rotated never.

Unattributed

Spend with no owner

A five-figure monthly invoice that finance cannot break down by team, by agent, or by anything a budget holder could act on.

Platform

Four pillars, adopted in order

You do not have to take all of it. Read-only inventory is a complete product on its own — enforcement is opt-in, per agent, and always after you have seen what it would have blocked.

Inventory

Connect read-only admin APIs and the registry populates itself. Mandatory owner and sponsor, risk tiers, and a lifecycle that moves draft to approved to retired.

  • Cross-vendor discovery, credentials stored write-only
  • Orphan and shadow-agent detection
  • Day-zero baseline snapshot
  • Branded audit report export

Identity & permissions

Policy as code in Cedar, versioned and reviewable. Every policy runs in shadow mode first, so promotion to enforcement is a decision made against real evidence.

  • Shadow mode before enforce, always
  • Two-person rule on high and critical tiers
  • Credential broker: Vault, AWS STS, short-lived and scoped
  • Quarantine kill-switch that revokes on the way out

Activity & audit

A per-tenant hash chain over every recorded action, with Merkle roots anchored to write-once storage. The verifier is open source, so nobody has to take our word for it.

  • Detects mutation, reordering and tail truncation
  • Anchors written to object-lock storage, undeletable
  • Durable spool: zero event loss under hard kill
  • Verifier names the exact point of divergence

Value

Cost is measured. Value is modelled — and Calvari never blurs the two. No value figure renders without the model, the version, the assumptions and the person who approved them.

  • Outcome ingestion by SDK, signed webhook or connector
  • Versioned, approved value models with an audit trail
  • Per-agent P&L, cost netted exactly once
  • Board report where every number can be challenged
How it works

Observe first. Enforce only when you choose to.

STEP 01

Connect

Point Calvari at your provider admin APIs with read-only credentials. Nothing is installed in the path of your agents, and nothing changes about how they run.

STEP 02

Discover

The registry fills in: agents, identities, keys, tools and spend. Unowned agents and unattributed cost surface on the attention dashboard, and you assign owners.

STEP 03

Enforce, if you want to

A gateway can sit inline and apply policy — but only per agent, only after shadow mode has shown you the diff, and only once a second admin has approved.

Turning enforcement off requires nobody. A control plane that can take a customer's agents offline has to be safer to disable than to enable. Every agent starts in shadow, and the console will not let you enforce until you have looked at the seven-day preview of what would have been blocked.
In scope

What Calvari does

  • Govern agents wherever they already run, across vendors and frameworks
  • Produce evidence an auditor will accept, not a dashboard screenshot
  • Map controls to EU AI Act, ISO 42001, NIST AI RMF and Indian regulators
  • Broker short-lived credentials so standing secrets can be retired
Out of scope

What Calvari will never be

  • An agent framework, a runtime, or anywhere you host agents
  • A prompt-injection or content guardrail vendor
  • A model evaluation, routing or failover product
  • A data classification or DLP tool — we consume your labels
Trust

Where we actually are

Calvari sells evidence, so it would be strange to ask you to take our own status on faith. Here is the honest position, including the parts that are not finished.

Stage Pre-launch, onboarding design partners. The platform is built and tested end to end. We are working with a small number of enterprises before general availability.
Security audit An independent audit was commissioned against the codebase. Every Critical and High finding is closed; remaining Medium and Low findings are tracked publicly as issues rather than quietly carried.
Penetration test Not yet performed. An external test, with Critical and High findings remediated, is a hard gate before any customer traffic passes through the gateway.
SOC 2 Not compliant, and not claimed. An auditor cannot observe controls over a system that has no production history. It is sequenced after deployment, not before.
Data handling Calvari records metadata about agent activity — which tool, which agent, which outcome. It is not an LLM proxy and does not see your prompts or model responses.
Design partners

Find out what is running in your estate

We are taking a small number of design partners — regulated enterprises with real agent estates and a security team that will push back. Read-only connection, and a written findings report you can take to your board.

Tell us what you are running and roughly how many agents. We will reply with whether we can help.