For teams running AI agents in production

GaaS: Governance as a Service for AI agents.

Every agent action is checked against your policies before it executes: approved, modified, escalated, or blocked. Every decision leaves verifiable evidence, a hash-chained record kept outside the agent's reach.

$0 free tier · 1K actions/mo · No credit card, no contract

GaaS — Governance as a Service — is an external layer for AI agent governance: it checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

decision record · dec_7f3a…c291
Simulated example
intent · irrigation-ctl · declared risk: low
activate_valve → irrigation_zone_4
BLOCK
Evidence gathered
claimed
soil_moisture: 38%
weather_api
rain_active
live_sensor
soil_moisture: 82% (contradiction)
Policy and deliberation
policy
water_conservation_v2
rule
block during precipitation
risk score
0.0 → 0.87
panel
risk, domain, compliance
consensus
BLOCK, 3/3 unanimous
Audit record
4e19…a07b→7f3a…c291
integrity
hash-chained (SHA-256), signed
proof
signed proof token issued
timestamp
daily, in Bitcoin
Stale sensor data. Contradiction. Action blocked before execution.47.2 s
12
Regulatory frameworks built in
59
Policies built in and enforced
29
Connector integrations built
<100 ms
Routine decision, end to end
Pending
Provisional patent, filed March 2026

Your agents are acting. Who's governing?

Autonomous AI agents are sending emails, executing transactions, accessing records, posting content, and controlling physical systems. Right now, the governance model for most of these agents is: hope the prompt was good enough.

GaaS provides the institutional checks that every hospital, bank, and trading floor requires of human employees — but for AI agents. Cognitive offloading that's structured, fast, transparent, and auditable.

48,293
DECISIONS
87.3%
APPROVAL RATE
24ms
AVG LATENCY
12
BLOCKED TODAY
TIMEAGENTACTIONVERDICTMS
SYSTEM OVERVIEW● ONLINE
VERDICT DISTRIBUTION
74.2% APPROVE 12.8% MODIFY 8.6% ESCALATE 4.4% BLOCK
PIPELINE HEALTH
Intent Declaration2ms
Context Enrichment18ms
Policy Evaluation6ms
Deliberation48.2s
Decision + Audit9ms
RECENT BLOCKS
irrigation-ctl2m ago
Stale sensor data — contradiction detected
cx-agent-74m ago
PCI-DSS violation — speakerphone active
data-export-311m ago
GDPR scope exceeded — 340K records

Simulated feed. Actual decisions include full audit records with hash-chain verification.

How it works

Five stages between intent and action.

Most decisions never leave the deterministic control plane. The ones that need judgment get a multi-agent deliberation, bounded in time and fully recorded. Watch a block happen, stage by stage.

  1. Intent declaration

    The agent declares what it intends to do. If it can't declare it, it can't do it.

    Every action

  2. Context enrichment

    GaaS discovers what the agent doesn't know. Missing context is itself a finding.

    Every action

  3. Policy evaluation

    Four-tier policy hierarchy: universal, regulatory, organizational, agent-specific.

    Every action

  4. Deliberation

    High-risk actions are debated by a multi-agent panel. Deliberation is the product, not overhead.

    High-risk actions only · about 40–60 s

  5. Decision + audit

    A tamper-evident, hash-chained, signed record for every decision, carrying its reason and timestamped daily in Bitcoin; every live decision gets a proof token anyone can check.

    Routine decisions: 24 ms median end to end

pipeline trace · dec_7f3a…c291
Simulated PROCESSING
1. INTENT DECLARED2ms
action:activate_valve
target:irrigation_zone_4
risk_declared:low
context:{ soil_moisture: 38% }
2. CONTEXT ENRICHED23ms
weather_api:rain_active⚡
live_sensor:soil_moisture: 82%⚡ CONTRADICTION
confidence:0.94
3. POLICY EVALUATED6ms
triggered:water_conservation_v2
rule:block during precipitation
risk_score:0.0 → 0.87▲
4. DELIBERATION47.1s
panel:[risk, domain, compliance]
consensus:BLOCK — 3/3 unanimous
5. DECISION + AUDIT12ms
verdict:BLOCK
audit_hash:7f3a...c291
reason:Stale sensor data. Contradiction.
total latency47.2s

Integration

Govern your first agent action this afternoon.

Install the SDK, declare an intent, act on the verdict. SDKs for Python, TypeScript and Java, with plugins for LangChain, OpenAI Agents, CrewAI, Pydantic AI, Vercel AI, Microsoft Agent Framework, and MCP.

# Python 3.11+
$ pip install gaas-sdk
SDKs
Python, TypeScript, Java
Framework plugins
LangChain, OpenAI Agents, CrewAI, Pydantic AI, Vercel AI, Microsoft Agent Framework, MCP
Protocol
REST/HTTPS, JSON payloads, X-API-Key header
Routine verdict
Under 100 ms, end to end
First governed action
An afternoon, typically
governed_action.py
from gaas_sdk import (
    GaaSClient, build_intent, ActionType, TargetType,
)

async with GaaSClient(
    "https://api.gaas.is",
    headers={"X-API-Key": "gsk_..."},
) as client:
    intent = build_intent(
        agent_id="my-agent",
        action_type=ActionType.COMMUNICATE,
        verb="send",
        target_type=TargetType.ENDPOINT,
        target_identifier="email-service",
        summary="Send welcome email to new user",
        content={"template": "welcome_series"},
    )
    response = await client.submit_intent(intent)
    # approve | approve_modified | escalate | block
    print(response.data.verdict)

Observe first. Enforce when you're ready.

Shadow Mode runs the full pipeline on your agents' real actions for 14 days without blocking anything, so you see every verdict before you enforce one.

Context connectors

Rules applied to reality, not just claims.

Context Connectors are pluggable data sources that enrich AI agent intent declarations with real-world context during Stage 2 of the governance pipeline. They transform governance from "rules applied to agent claims" to "rules applied to reality." GaaS's code includes 29 connector integrations across enterprise, IoT, smart home, agriculture, and energy platforms; none is switched on in the hosted service yet, and a category no system answers is reported as missing context and treated as risk. Since 29 September 2026 you can connect your own systems through a context endpoint, which answers the facts your policies check during every decision.

Browse the 27 listed connectors and what each one enriches

  • Twilio
  • Salesforce
  • Stripe
  • GitHub
  • Okta
  • Datadog
  • Slack
  • Workday
  • Zendesk
  • Microsoft Teams
  • Google Workspace
  • Jira
  • Asana
  • Vanta
  • PagerDuty
  • Alexa Smart Home
  • SmartThings
  • Google Nest
  • Honeywell Home
  • Philips Hue
  • Canvas LMS
  • Clever
  • ShipStation
  • AEMP 2.0
  • Leaf Agriculture
  • Tesla Fleet
  • SolarEdge

Compliance

12 frameworks. 59 policies. Built in.

Every governance decision is evaluated against the regulatory frameworks that apply to your industry, jurisdiction, and action type.

  • EU AI Act5 policies

    Articles 9, 10, 13, 14 and 15. Risk classification, transparency obligations, human oversight requirements.

  • GDPR4 policies

    Erasure, portability, automated decision explanation, sub-processor management.

  • HIPAAEnforced

    PHI detection and blocking. Minimum necessary standard enforcement. BAA-ready audit trail.

  • PCI DSSEnforced

    Cardholder data detection and blocking. Agent payment compliance.

  • CCPAEnforced

    California consumer privacy rules, evaluated on agent actions that touch personal information.

  • NIST 800-53Mapped

    AC, AU, IA, SC control families with agent-specific interpretations.

  • FedRAMPMapped

    FedRAMP Moderate baseline alignment. Control inheritance documentation.

  • CMMCMapped

    Level 2 practice mapping for defense contractor agent governance. CUI handling.

  • NIST CSFMapped

    Identify, Protect, Detect, Respond, Recover mapped to governance pipeline stages.

  • SOXEnforced

    Sarbanes-Oxley controls, evaluated on agent actions that touch financial records and reporting.

  • FERPAEnforced

    Education record protection. Role-based access enforcement for student PII.

  • TCPA + Florida FTSAEnforced

    Consent and contact rules for agent-initiated calls and texts: 6 TCPA policies plus Florida's Telephone Solicitation Act.

Trust tiers

Governance earns trust. Trust unlocks access.

  1. Registered

    SDK integrated, basic policies configured.

    → GaaS token issued

  2. Verified

    30-day compliant operation demonstrated.

    → Elevated trust tokens

  3. Certified

    Independent audit, full deliberation enabled.

    → H2Om GaaS Certified

GaaS Governance Shield

Bidirectional governance

Outbound: control what your AI agents do in the world, with every action evaluated before execution. Inbound: control what visiting AI agents do on your digital property: identify, gate, monitor, and audit. Organizations that govern their outbound agents earn trust tokens recognized across the GaaS network.

FAQ

Frequently asked questions about GaaS.

What is GaaS (Governance as a Service)?

GaaS is a governance pipeline that sits between an AI agent's intent and its execution. It enriches context, evaluates policy, deliberates risk via multi-agent panels, and produces a tamper-evident audit trail. Sub-100ms for routine actions, full multi-agent deliberation for high-stakes decisions.

How much latency does GaaS add to AI agent actions?

Routine actions complete the full governance pipeline in under 100ms (median 24 ms, p95 36 ms, measured in production). High-risk actions that trigger multi-agent deliberation take about 40–60 seconds end to end. The governance tax is proportional to the governance need.

How much does GaaS cost per action?

Plans include a monthly action allowance: Free $0 (1K actions), Developer $99 (10K), Starter $500 (50K), Growth $2,500 (500K), Enterprise $10,000+ (5M+). Beyond the allowance, each decision bills once in its highest class: routine $0.002, deliberation $0.05, escalation $0.25. Shadow and test decisions are never metered, a failed deliberation bills as routine, and the audit record is never metered. Overage billing is active as of 1 August 2026, following a full report-only cycle; your included allowance is netted out first and is never metered, and usage recorded during the report-only period was not charged retroactively.

What is Shadow Mode?

Shadow Mode runs the GaaS governance pipeline on your real agent actions without enforcement. Actions are validated, enriched, checked against your policies, and audited — but never blocked; deliberation is skipped in shadow mode. It lets you see what governance reveals about your agents before activating enforcement. Free for 14 days, no credit card required.

What SDKs and integrations does GaaS support?

GaaS provides SDKs for Python, TypeScript and Java. Framework plugins are available for LangChain, OpenAI Agents, CrewAI, Pydantic AI, Vercel AI, Microsoft Agent Framework, and MCP. The API uses REST/HTTPS with JSON payloads. A typical integration adds one governance call before each agent action.

What are GaaS Trust Tiers?

Trust Tiers are a progressive credentialing system. Registered: SDK integrated with basic policies (GaaS token issued). Verified: 30-day compliant operation demonstrated (elevated trust tokens). Certified: independent audit with full deliberation enabled (H2Om GaaS Certified).

What is Bidirectional Governance?

GaaS provides two governance directions. Outbound Governance controls what your AI agents do in the world — every action evaluated before execution. Inbound Governance controls what visiting AI agents do on your digital property — identify, gate, monitor, and audit incoming agent activity.

What exactly counts as a governance decision?

Every time an agent declares an intent and GaaS evaluates it through the full five-stage pipeline — intent declaration, context enrichment, policy evaluation, deliberation if needed, and verdict plus audit — returning a verdict in under 100ms, that is one governance decision. The free tier covers all of that at no cost.

What happens when GaaS blocks an action?

Every block includes a complete reasoning chain: which policy triggered, which condition failed, and what the agent would need to change to make the action compliant. Nothing is blocked silently. Your team can review every blocked action in the dashboard.

Do I need to code anything to get started with GaaS?

Shadow Mode requires a short SDK integration (Python, TypeScript or Java) that routes your agent's actions through the GaaS pipeline. It typically takes an afternoon for a developer using LangChain, OpenAI Agents, CrewAI, or Pydantic AI. Shadow Mode does not enforce decisions, so there is zero operational risk while you evaluate. Switching to live enforcement is a single flag change.

How is GaaS different from system-prompt guardrails?

Guardrails live inside your agent's context window: an agent that governs itself spends about 14,700 tokens of context on every routine governed action. They have no access to real-world context and produce no auditable record. GaaS is an external governance layer: 0 tokens in your agent's context through a framework plugin, or about 2,470 through MCP; it enriches decisions with context your agent doesn't have, and produces a tamper-evident audit trail for every decision.

What is GaaS, in one sentence?

An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

Do I have to be a regulated business to use GaaS?

No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.

Do I have to change my agent or my model to use GaaS?

No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.

What compliance frameworks does GaaS support?

GaaS evaluates every governance decision against 12 regulatory frameworks and 59 built-in policies — including EU AI Act, GDPR, HIPAA, PCI DSS, CCPA, SOX, TCPA and Florida's FTSA, NIST 800-53, FedRAMP, CMMC, NIST CSF, and FERPA. Coverage is automatic based on the action type, jurisdiction, and industry. Compliance status is queryable via API and exportable for auditor review.

How does GaaS handle prompt injection and security threats?

Every intent declaration is scanned against 17 prompt injection signatures at Stage 1 — before any context enrichment or policy evaluation occurs. Flagged payloads are rejected immediately. At Stage 3, enriched context is re-scanned for injection patterns that only emerge after enrichment. The injection checks are Tier 1 — non-disableable. Behavioral anomaly detection and session trust decay run and enforce, and security teams receive events through signed per-organization webhooks, with a guide for Splunk, Sentinel and QRadar.

Start today

Your agents are acting. Who's governing yours?

Start free with 1K actions a month and no credit card. For volume pricing, security review, or deployment questions, talk to sales.

White paper

The Context Dividend

Edition 5, measured against the live system: what self-governance costs an agent's context, and what GaaS hands back.

Intellectual property

Patent pending

Provisional patent filed March 2026 covering the multi-stage governance pipeline architecture for autonomous AI agents.

How GaaS records hold up to audit