The Pillar

What is GaaS?

Governance as a Service, in plain language: the problem it solves, the move it makes, and how it works — no pipeline diagram required.

GaaS — Governance as a Service — is an external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

org_demo · all agents
Simulated
TimeAgentActionVerdictLatency
09:41:02cx-agent-7send_email → customer_4421APPROVE19ms
09:41:00trading-bot-3execute_trade → AAPL × 500APPROVE34ms
09:40:56content-agentpost_to_social → instagram_brandMODIFY33ms
09:40:54hr-assistantaccess_record → employee #4421ESCALATE52.6s
09:40:50cx-agent-7read_cc_number → customer_callBLOCK40ms
09:40:48billing-agentprocess_refund → $2,340.00ESCALATE32ms
09:40:44fleet-mgrreroute_vehicle → truck_17 → depot_BAPPROVE33ms
09:40:42support-agentissue_credit → $500 creditAPPROVE36ms
GOVERNING
48,293 decisions

Simulated feed. Actual decisions include full audit records with hash-chain verification.

The Problem

Agents act. Prompts hope.

AI agents don't just answer questions anymore — they act. They send the email, place the order, publish the post, move the money. And for most operators, the only thing standing between an agent and a mistake is the prompt they wrote: a paragraph of instructions the agent is trusted to follow.

Every other consequential actor in the economy — an employee, a contractor, a bank transfer — passes through checks that exist outside the actor. Agents mostly don't. That gap between what agents can do and what actually checks them is the problem GaaS exists to close. Hope is not a control.

The Move

Put the check outside the agent.

The core principle: the agent is not the governor. The system proposing an action and the system evaluating it are architecturally separate. Before any consequential action executes, GaaS checks it against your rules and does one of four things:

Allows it

Lets it through

Clearly fine actions clear in well under a tenth of a second — fast enough that the agent never notices governance happened.

Fixes it

Fixes it, then sends it

When a small change — like adding a required disclosure — is enough to make it safe, GaaS approves it with that modification. No waiting needed.

Holds it

Holds it for a human

Actions that need judgment wait for a yes from the person who owns the risk — on their schedule, with the context in front of them.

Blocks it

Stops it cold

Actions that cross a line never execute. And because the rule lives outside the model, the agent can't argue its way past it.

Every verdict — allow, modify, hold, or block — is written to a tamper-evident, hash-chained audit record: a receipt you can show a client, an auditor, or a regulator.

The How

Declare, check, decide — in milliseconds.

Under the hood, GaaS runs a five-stage pipeline. The agent declares its intent ("pay invoice INV-2026-0044 to vendor 9912"); GaaS enriches that intent with real-world context the agent doesn't have (from your own systems through a context endpoint; 29 vendor integrations are built, none switched on yet; missing context is treated as risk); the enriched intent is evaluated against your policies and 12 regulatory frameworks; genuinely high-stakes calls get a multi-agent deliberation; and the verdict plus a tamper-evident audit record comes back — in under 100 milliseconds for routine actions.

You don't write the rules in code. The dashboard is conversational, powered by Claude: describe the policy the way you'd brief an employee — "hold any order over $500 for my approval" — and it exists, enforced, from then on.

And you don't have to trust any of this on faith. Shadow Mode runs the whole pipeline on your real agent actions while enforcing nothing — you see exactly what would have been held or blocked before you ever turn enforcement on.

Who It's For

Anyone whose agents act.

GaaS is not just for regulated enterprises. If agents send, post, order, answer, or move money on your behalf, you're an AI operator — an agency whose agents publish for clients, a shop whose agent orders parts, a clinic whose agent messages patients, a store whose agent handles refunds. Regulated teams get the framework mappings; everyone gets control.

The Dividend

It costs less than the prompt you're using now.

Governance an agent carries itself costs about 14,700 tokens of context per routine governed action. GaaS costs it 0 through a framework plugin, or about 2,470 through MCP: 83–100% less.

FAQ

Every objection, answered.

What does GaaS stand for?

Governance as a Service. The same way software, infrastructure, and payments became services you plug into rather than systems you build, GaaS makes governance — the checking, gating, and recording of AI agent actions — a service any operator can wire in.

What is GaaS, in one sentence?

An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

Do I have to be a regulated business?

No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.

Is it hard to set up?

No. Start in Shadow Mode with just an email; it runs the full pipeline on real actions without enforcing anything, so there is zero operational risk. A developer wires the SDK in an afternoon, and you author policies in plain language.

What does it cost?

Start free in Shadow Mode, no card. There is a free tier, then plans from $99 a month, and under a cent per governed action at scale. Nonprofits, NGOs, and veteran-owned businesses govern free for life. See pricing.

Will it slow my agents down?

Routine actions clear in well under a tenth of a second. Only high-stakes decisions take longer, and only because you asked them to.

Do I have to change my agent or my model?

No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.

Doesn't governance cost me tokens?

The opposite. A self-governing agent spends about 14,700 tokens of context on every routine governed action; with GaaS it spends 0 through a framework plugin (74 when an action is blocked), or about 2,470 through MCP. On a 200K-token model, self-governance fills 30% of the window after about 14 governed actions and 60% after about 28. See The Context Dividend.

I already have prompt guardrails. Why GaaS?

Prompt guardrails live inside the model, get re-read on every call, and can be argued away. GaaS is external and enforced; the agent cannot talk it out of a block.

See what GaaS would have caught.

Start free in Shadow Mode — the full pipeline runs on your real agent actions, enforcing nothing, so you can watch governance work before you turn it on. No credit card.