Runtime guardrails for AI in production

Runtime controls and signed records for agents that act.

Glacis supervises agents that use tools, credentials, customer data and delegated authority. Routine work goes through untouched. The risky exceptions get held, narrowed or denied, and either way there’s a signed record someone outside your company can check, in their own browser, with no Glacis account.

The risk

Agents in production act with delegated authority.

An agent in production retrieves data, calls APIs, triggers workflows, writes files, updates tickets and acts inside customer environments. Prompt injection, tool misuse, exfiltration and unauthorized action become business risks rather than abstract AI safety concerns, and a buyer wants to know what the system did, not only what the model said.

Enterprise buyers will ask what the agent could do, what it was denied, and how you know. Glacis puts the control where the agent acts, and whichever way it decides there’s a signed record.

Founder-led sales

Through enterprise security review, with evidence a buyer can check.

When an agent uses tools, credentials, customer data, code or production systems, enterprise buyers ask for evidence. Glacis helps technical founders harden a named workflow and produce a customer-ready evidence pack before the security review stalls the deal.

Security-review pressure

Answer how prompt injection, tool misuse, data leakage, unauthorized actions and drift are controlled, in terms a reviewer can check.

No mature security team yet

Add runtime security depth to a fast-growing team before the organization has a full security function of its own.

Expanding attack surface

AI-assisted development and agent workflows widen the access an agent holds to tools, code, credentials and production data.

Hardening sprint

A named workflow mapped, its runtime controls prioritized, and an evidence pack customers can review.

Control surface

Agent permissions, decided at the moment of action.

Tool permission

A sensitive tool call is allowed, constrained, held or denied before the agent acts on it.

Credential boundary

Which credentials, scopes and systems the agent can reach, limited and recorded.

Data access

Risky data movement and suspicious use of context, redacted, held or denied.

Human review

The action is held for a person when impact, confidence or policy context crosses a threshold.

Operational evidence

What each agent was allowed to do, what it was denied, and why.

Records are signed at runtime, as the decision is made, and an evidence pack is assembled afterwards from those records.

A security reviewer reads a concrete record about a named workflow instead of a policy promise about the system in general. The record shows what the control reported for that action: the rule that ran, the decision and the signature. It doesn’t tell you whether the agent’s output was correct, whether every action was captured, or whether the system is safe or compliant.

Workflow
Control
Decision
Record
Evidence pack
Agent requests production data export
Tool permission and exfiltration rule
Held for a person
Signed policy hash, tool ID, model version
Security review and incident-response artifact

How it works

Supervision, made independently checkable.

Delegated authority, mapped

The credentials, tools, data, workflows and actions the agent can reach today.

Runtime controls, installed

The allow, constrain, hold and deny rules that apply at the agent boundary.

Signed records, preserved

Each decision leaves a signed record. An evidence pack for a particular customer review is assembled from those records afterwards.

Architecture

Operational evidence, alongside the stack you already use.

Glacis sits alongside the observability, governance and security tools you already run and adds a signed record of what each runtime control reported. Prompts, outputs, customer data, credentials and context can stay out of the portable record, which carries hashes rather than payloads. What the record does and doesn’t establish is set out beside the sample row above.

Runtime controls

The agent boundary, controlled before tools and data are touched.

Signed records

Each action that passes through the control leaves a signed record of what it reported.

Payloads stay local

Protected payloads can stay local; what leaves is the hashes, outcomes, signatures and metadata a reviewer needs.

Let’s look at what your agents can do.

We’ll show where delegated authority creates risk, which controls should run and what the signed records would give a customer’s security reviewer.

Talk to us