ProvenantAI Get in touch
Control and evidence for AI agents

Your agents can only do what you decided.

You decide exactly what an agent is allowed to see and exactly what it is allowed to do. Provenant holds those limits every time it runs, and produces the evidence.

Limits have to sit outside the model
“There will always be ways to prompt the AI that can make it disregard these rules.”
NIST, announcing a peer-reviewed proof that no finite set of guardrails is universally robust — Vassilev, IEEE Security & Privacy, May/June 2026. Source
Existing frameworks “were architected [for systems] whose behavior can, in principle, be characterized at deployment time” — and autonomous agents “routinely violate” this. Organizations “lack mechanisms to enforce access policies dynamically as agent tasks evolve,” and “no enforceable, agent-specific security controls exist today.”
Cloud Security Alliance, AI agent governance gap, April 2026. Source

You set the limits. Nothing your agent reads can change them.

Every

MCP server you already run. No fork, no wrapper, no rewrite.

15 min

from importing an existing tool to a live agent with its controls documented and enforced.

Zero

changes to the tools you already run. No SDK, no code, nothing to rewrite.

Standards register

Built to satisfy the bar, no matter who sets it.

Agent governance is arriving from several directions. We handle all of them.

CSA Agentic Trust Framework
Agent trust framework · 25 requirements
25of 25
22 enforced2 contained1 evidencedControl by control →
AIUC-1
Agent certification · 51 controls in six domains
44of 51
20 enforced7 contained17 evidencedControl by control →
EU AI Act binding
Law · Articles 8–27 · enforcement from August 2026
17of 20
6 enforced1 contained10 evidencedControl by control →
OWASP Top 10 for Agentic Applications
Risk taxonomy · 10 risks · 2026
10of 10
6 enforced4 containedControl by control →
Colorado AI Act binding
State law · SB 24-205 · 11 duties · from 30 June 2026
10of 11
2 enforced8 evidencedControl by control →
NIST AI RMF
Risk-management framework · 19 categories
16of 19
3 enforced3 contained10 evidencedControl by control →
ISO/IEC 42001
Certifiable management standard · 10 sections
9of 10
2 enforced7 evidencedControl by control →
EnforcedProvenant does it. You can show it before your agent runs.
ContainedWhere the standard asks you to prevent something the model might do, Provenant limits how far it gets.
EvidencedWhere the standard asks you for a plan, a policy or a test, Provenant hands you what it needs.
What an assessment looks like

Your evidence is already written.

Hand an assessor the whole picture — what your agent can do, what it sees, and where every value came from. Nothing to reconstruct.

schedule_appointment Processing activity · Scheduling · Live

Purpose — book an appointment slot for the patient in this session.

Agent providesyours
slotIdscheduling
reasonCodescheduling
Record returnsthe record's own
confirmationIdscheduling
patientNamepersonal data
diagnosisCodehealth data
Agent seesyours
confirmationIdscheduling
Withheld from the agent: patientName, diagnosisCode
Schedule I — assembly of the request every value is given a source complete
slotIdagentslotId
patientRefsessionpatientRef
Technical and organisational measures

diagnosisCode is not disclosed to the agent and is not retained in session state. patientRef is supplied from session state; the agent does not choose its value. The agent receives confirmationId.

Produced from the same decisions that hold the agent.

A live document is produced for each agent.

Get in touch

We’re taking on design partners.

If you have an agent doing something you cannot afford to get wrong, we would like to hear about it — including the parts that are still messy.

hello@useprovenant.ai