Your agents act.
You answer for it.
Autonomous agents already touch customer data, spend money and call systems on your behalf — and almost nobody can say precisely what they did, or stop them mid-run. Daevix is the governance layer: observe every action, keep a record you can hand to an auditor, and contain an agent in one move.
Alpha · AGPLv3 · runs inside your own boundaryAn agent gets out of the box, and you find out later.
Agents improvise. Given a tool, a budget and a goal, they will reach for things nobody wrote a ticket for. The public escapes so far have all had the same shape: the action was possible, nothing was watching the boundary, and the record of what happened was reconstructed from application logs days afterwards.
Observe. Audit. Contain.
Three things you need before you can let an agent near anything that matters. Daevix does them at the boundary of the agent, so they hold even when the agent misbehaves.
Every action an agent takes, as it happens.
Agents are not services: they improvise, and the interesting behaviour is the call you did not anticipate. Daevix watches the boundary of every agent — what it reached for, what it read, what it spent — so the fleet is legible while it is still running, not after an incident.
nothing runs unobservedA record built to be handed to someone else.
The trail is a first-class, tamper-evident stream with its own schema — not application logs that a later release can reword or drop. When risk, legal or a regulator asks what the agent did on the 14th, the answer is a query, not an archaeology project.
records may not be droppedStop one agent without stopping the business.
Policy is default-deny at the edge of the agent, so an agent reaches only what you allowed. When something goes wrong you contain that agent alone — reach cut, run frozen mid-step, record sealed — while the rest of the fleet keeps working.
one agent, one moveWhat the agent did, in one line each.
Actor, action, target, outcome. Readable by the engineer on call and by the reviewer who has never seen your stack — which is the point of an audit record. Filter it, tail it live, or query the same stream from the API.
Four questions most teams cannot answer yet.
An agent is untrusted code acting in your name. Governance cannot live inside it, and it cannot be a prompt — it has to sit outside the agent, where the agent cannot argue with it.
Your boundary. Your keys. Your record.
- Runs inside your own infrastructure — agent data never transits us
- Every action attributed to an agent, a run and a human owner
- The audit trail is yours, exportable, and outlives the vendor
- Containment is an operator action with a record, not a support ticket