For compliance & risk
Agent actions have to be reviewable, interceptable and signed off - not reconstructed from logs after the fact. Below is what every product and every path on this site says for compliance and risk, each linking back to its page.
By product
- AULO
Approvals and HITL capture human actions in AULO, while audit records and policies remain in OwlAudit
- HarnessServer
Managerial memory is disabled by default and strictly isolated to authorized Agents
- HeronSentry
OwlAudit pulls operational telemetry exports from this service
- LarkScout
Fully traceable knowledge sources; MCP can be enabled over mTLS to governed NodalOS Agents, not as an unauthenticated public endpoint
- OwlAudit
Provides a complete loop across reviews, escalations, and audit trails rather than mere pre-call blocking; tracks review veto frequency for governance
- PathPilot
Program budget adjustments record approved outcomes only; critical milestones link to OwlAudit writeback
- PrismCouncil
Structured provenance for decision rationale; connects with OwlAudit to feed sign-off events into audit chains
By governance path
- Comparison with Alternatives
Complementary relationship with AI GRC: ReadyForAI governs Agent runtime behaviors, while GRC governs model risk
- Agent Governance Diagnosis
Emphasizes approval audits, policy enforcement, and end-to-end auditability
- Existing Architecture Integration Assessment
Fully traceable integration process; HITL approval checkpoints activate during the pilot phase
- Private Deployment & Security Boundaries
Hook-level blocking + Hash Chain records + local verifiable audit ledgers satisfy regulatory audits
- Complete Product Governance Loop
OwlAudit anchors compliance with local audit chains; on connected NodalOS hooks, HITL policies reject synchronously