What exists
Every agent across OpenAI, Anthropic, Bedrock, Entra and homegrown frameworks — with a named owner and a sponsor.
Calvari is a control plane for AI agents — a system of record that answers what exists, what it can reach, what it did, what it cost, and what it was worth. Across every vendor and framework. Provable to an auditor.
Read-only to start. No migration, no rewriting your agents, no runtime to adopt.
Your observability stack sees traces. Your IdP sees identities. Your finance tools see a single line item from one vendor. None of them can tell you who owns the agent that spent it, or what it was allowed to touch.
Every agent across OpenAI, Anthropic, Bedrock, Entra and homegrown frameworks — with a named owner and a sponsor.
Declared tool scopes and standing credentials, versioned as policy, with drift from the declaration surfaced.
A per-tenant hash chain of actions, anchored to write-once storage, verifiable by an open-source CLI.
Spend attributed per agent against versioned price sheets, with budgets and projected-overrun alerts.
Outcomes counted, then netted against cost — with every assumption printed beside the number.
These are the three findings that make a security team stop the meeting. They are not hypothetical failure modes — they are what an unmanaged agent estate looks like from the inside.
The engineer who built it changed teams. The agent still runs, still holds its keys, and no name on the org chart is accountable for it.
A long-lived provider key pasted into an environment variable two quarters ago, scoped to everything, rotated never.
A five-figure monthly invoice that finance cannot break down by team, by agent, or by anything a budget holder could act on.
You do not have to take all of it. Read-only inventory is a complete product on its own — enforcement is opt-in, per agent, and always after you have seen what it would have blocked.
Connect read-only admin APIs and the registry populates itself. Mandatory owner and sponsor, risk tiers, and a lifecycle that moves draft to approved to retired.
Policy as code in Cedar, versioned and reviewable. Every policy runs in shadow mode first, so promotion to enforcement is a decision made against real evidence.
A per-tenant hash chain over every recorded action, with Merkle roots anchored to write-once storage. The verifier is open source, so nobody has to take our word for it.
Cost is measured. Value is modelled — and Calvari never blurs the two. No value figure renders without the model, the version, the assumptions and the person who approved them.
Point Calvari at your provider admin APIs with read-only credentials. Nothing is installed in the path of your agents, and nothing changes about how they run.
The registry fills in: agents, identities, keys, tools and spend. Unowned agents and unattributed cost surface on the attention dashboard, and you assign owners.
A gateway can sit inline and apply policy — but only per agent, only after shadow mode has shown you the diff, and only once a second admin has approved.
Calvari sells evidence, so it would be strange to ask you to take our own status on faith. Here is the honest position, including the parts that are not finished.
We are taking a small number of design partners — regulated enterprises with real agent estates and a security team that will push back. Read-only connection, and a written findings report you can take to your board.
Tell us what you are running and roughly how many agents. We will reply with whether we can help.