Governance

One Control Layer for Data, Workflows and Agents

Registry, permissions, vaults, memory, approvals, evidence and model choice, defined once for data, workflows and agents alike. We do not govern to constrain. We govern so we can deploy more with confidence.

Control layer

What the Estate Is Governed By

Seven things, each set once at workspace level and inherited by every block you add afterwards: data, workflows, connectors and agents.

Registry

Every agent in the estate, who owns it, what it is for, when it last ran. No shadow agents.

Permissions

Which data an agent sees, which NGT Tools and NGT Skills it can reach, which systems it can write to.

Vaults

Credentials issued centrally, scoped per role, rotated centrally, never sitting in a prompt or a script. Revoke the agent and you revoke its access everywhere.

Memory

What agents retain across runs and share with each other. Scoped, inspectable, isolated where it has to be.

Approvals

Which actions wait for a human signature, set once rather than agent by agent.

Evidence

Every run logged, traceable, replayable. The answer to what an agent was allowed to do, who decided that, and what it did.

Model

You choose the model: NGT Auto or any AI lab's LLM. Swap it without rebuilding the estate.

Why

The Harness Is What Makes an Agent Deployable

As models get easier to build with, the constraint moves from capability to control. An agent that cannot show what it was allowed to do, who decided that, and what it did, stays a pilot. One that can goes into production. The control layer is defined once and every agent inherits it, so the hundredth agent is as governed as the first.
Security and compliance

The Foundation the Control Layer Stands On

The certifications, the deployment model and the regulatory alignment that apply to every agent because they apply to the platform.

ISO 27001

Certified information security management, audited every year.

NIST 800-53

Security controls aligned to the NIST framework across the platform.

DORA

Operational resilience obligations for financial entities, built into how the platform is run.

GDPR

Personal data handled under the regulation, with data processing agreements for every client.

Single tenant

Every client runs in its own isolated environment. Methodology carries across deployments; data does not.

Sovereign

Data stays in the region you choose, under your keys, with full lineage of where it came from and where it went.

See the control layer on your estate

A demo walks through registry, vaults, approvals and evidence on a real agent.