Governed routing
Every agent request routes through the same path: context load → policy evaluation → approval gate → execution → evidence record. No ungoverned back doors.
ATC is the control tower for your AI fleet: agents request, the platform evaluates, people approve what matters, work executes, and the evidence writes itself. Watch it run live below.
One button, five steps, about six seconds: an agent asks to do work, policy blocks the risky part, a human approves, the work runs, and a tamper-evident receipt seals it. Every step explains itself as it happens.
One governed mission
“Draft a customer escalation summary from safe demo data, block external send, require approval, and seal the receipt.”
The agent asks to draft a customer escalation summary. Nothing runs yet — the request itself is logged first.
Safe drafting is allowed to proceed. Risky actions — emailing the customer, touching secrets, spending money — are blocked before they can happen.
Because this task is risk tier 3, a named person must approve before results leave the platform. Everyday low-risk work skips this gate.
The runner drafts the summary inside the boundary the policy set. It cannot exceed the approved scope.
Every event is hashed into a chain — each hash includes the one before it, so any tampering breaks the chain. The receipt is yours to download.
Every agent request routes through the same path: context load → policy evaluation → approval gate → execution → evidence record. No ungoverned back doors.
Sensitive classes — external sends, spend, credentials, production changes — pause for a named approver. Everyday work keeps moving.
Claude, ChatGPT, Gemini, Grok, custom agents, and MCP apps work from the same current state via GRIFF Brain — handoffs preserve decisions and evidence.
Request, context, approvals, actions, outputs, and outcome recorded as work happens — replayable and exportable for reviews, customers, and auditors.
Model calls attributed per workspace with budget posture visible in the Control Center — spend is a governed input, not a surprise.
The same ATC model runs cloud-connected, hybrid, or self-hosted — the operating model stays constant while the data boundary moves.
A full 76-minute governed agent session is published with hash-backed replays and the complete written audit — inspect exactly what ATC recorded.