Platform

Give every agent an Authority Envelope.

Tegrix turns the authority layer into product: discover the agent, bind reusable controls, evaluate decisions, enforce at runtime, and keep the Evidence Ledger.

How it attaches

Envelope lifecycle

Discover

Find agents across platforms, business systems, and custom runtimes.

Bind

Give each agent an Authority Envelope built from reusable controls.

Evaluate

Run policies read-only first so teams can see decisions before enforcement.

Enforce

Return ALLOW, DENY, REQUIRE APPROVAL, or STOP at the runtime boundary.

Prove

Write the decision, facts, approval, and execution result to the Evidence Ledger.

Tegrix Agent Inventory showing cross-platform agents, owners, ecosystems, risk, shadow agents, and missing owners

Connectors and context

Use facts from the systems you already run.

Connectors bring in platform evidence, ownership, identity, workflow, finance, ITSM, and security facts. Tegrix turns those signals into context an Envelope can use.

Discovery does not make an agent governed by itself. The agent still needs an enforceable boundary where consequential actions pass.

Tegrix Agent Overview showing owner, provider, runtime status, data classification, trust posture, and attention items

Authority Envelope

Write controls in business vocabulary.

Controls define what an agent may do, against which systems and resources, under what conditions, and when a human must approve.

Change freezesMaintenance windowsValue thresholdsSpend velocityNamed approversSeparation of dutiesBreak-glassFact freshnessFail-closed postureResource scopeDelegation lineageConsequence tier
Tegrix Policies and Controls showing governance coverage and active controls protecting an agent

Approval anatomy

Named approver

The approval names the human authorized to decide.

Fact-locked scope

The approval is bound to the action, amount, system, time, and facts evaluated.

Replay refused

A prior approval cannot be reused for a different action or changed context.

Agent excluded

Agents never approve themselves, and requesters cannot approve their own action.

Evidence Ledger

Record evidence when the decision happens.

Because Tegrix makes the decision, the Ledger records evidence at the moment of decision, not after someone reconstructs logs.

Decision
ALLOW, DENY, REQUIRE APPROVAL, or STOP
Facts used
The enterprise facts evaluated at the time of decision
Control matched
The reusable control that applied to the agent action
Approver
Who approved, denied, or owned the exception
Execution result
Whether the business action actually ran
Tegrix Audit History showing decision history, evidence coverage, evidence gaps, and audit readiness

Exact platform support

Current support is stated directly.

Current platform support uses public product names and precise status.

Amazon Bedrock Agents

Live runtime boundary

Agent actions governed before execution.

Amazon Bedrock AgentCore

Live gateway boundary

Gateway tool calls governed through the same authority model.

Google Vertex AI

Live runtime boundary

Google-hosted agent actions governed through the shared model.

Google Agent Gateway

Live gateway boundary

Gateway interception uses the same Envelope and Ledger.

Microsoft Copilot

Designed path

Provider integration expands through the same authority model.

Azure AI Foundry

Designed path

Provider integration expands through the same authority model.

Custom / MCP runtimes

Supported boundary pattern

Actions pass through an enforceable MCP, gateway, or interceptor boundary.

Adoption

Start read-only. Enforce when ready.

Begin with one consequential workflow. See what Tegrix would allow, deny, require approval, or stop before enforcement changes operations.

Step 1

Connect one environment read-only

Step 2

Build inventory and enterprise context

Step 3

Choose one consequential workflow

Step 4

Evaluate policies without enforcement

Step 5

Enable runtime control when ready

Step 6

Expand by reusable controls