Shape and register AI Workers
Create a Scaled Agent turns an idea into a structured Blueprint. Passport Studio carries the approved identity, owner, purpose, scope, risk, permissions, and lifecycle record forward.
Current Capability Status
Evaluate the current control-plane capabilities for governing AI Workers—from identity and authority through human review, runtime decisions, evidence, and lifecycle.
Available Today
Scaled Agents connects the records, decisions, and evidence needed to govern AI Workers without turning a registration record into blanket authority.
Create a Scaled Agent turns an idea into a structured Blueprint. Passport Studio carries the approved identity, owner, purpose, scope, risk, permissions, and lifecycle record forward.
Toll Gates evaluate policy and evidence. Human Review captures accountable decisions. Runtime Permits provide short-lived authority for the exact action under review.
Stamps, workflow events, action decisions, and audit exports preserve what was requested, what evidence was considered, who decided, and what happened next.
Scaled Agents does not turn a Blueprint, Passport, Toll Gate, Stamp, readiness review, or evidence package into legal advice, compliance approval, security authorization, audit opinion, certification, or blanket production authority.
How To Read This Page
The page separates public materials from four evidence states. A higher state for one component never promotes the complete platform, and a status label does not create legal, compliance, security, audit, production, or operating approval.
Public website content, templates, guided intake, draft Blueprint paths, and readiness materials that can support planning, evaluation, and owner review.
Identified source or artifacts with reproducible validation of the stated behavior. This does not establish deployment or customer operation.
The exact version is deployed to production infrastructure with verified production routes, successful production canaries, and an identified rollback boundary. Customer activation and action authority remain separately gated.
A deployable component with validated server-side operating and control responsibilities. This does not assert customer deployment or activation.
The exact authorized customer-managed deployment and scope, supported by current operating evidence and accountable owner authorization.
Readiness packets, source-backed records, validation outputs, and implementation notes that help accountable owners decide what remains open before customer operation.
Capabilities a customer may automate or operate inside its own controlled environment, including file intake, registry exports, APIs, repositories, usage records, or environment-local scanning.
Connector, MCP, identity, storage, support, and runtime paths that require defined scope, security and privacy review, testing, rollback or pause controls, and accountable owner decision.
Production-adjacent operation, runtime enforcement, customer IAM, system-of-record actions, and live connectors that require customer-owned implementation and approval before use.
Read status labels as planning posture. They do not certify compliance, validate security posture, approve production use, authorize AI workers, create audit opinions, or replace customer owner decisions.
Capability Status
The public website, Create a Scaled Agent flow, Passport planning records, Control Plane proof path, and readiness packets are suitable for readiness conversations and guided enterprise evaluation. Customer-specific operation requires approved scope, access controls, contracts, privacy/security review, implementation evidence, and customer owner authorization.
| Capability | Status | What it means | Boundary |
|---|---|---|---|
| Public website and resources | Available now | Public pages, resources, use cases, Advisor paths, training catalog, and readiness content. | Informational only; no customer-specific approval. |
| Create a Scaled Agent | Available now | Draft Blueprint path for shaping a worker idea, classifying risk, and preparing next steps. | Blueprints are recommendations, not approval records. |
| Passport planning record | Available now | Public draft planning record showing owner, purpose, scope, risk, evidence posture, Toll Gates, and lifecycle context. | Draft only; not an approval, authorization, or live customer record until customer-specific review, approval, and implementation gates are complete. |
| Control Plane and Passport Studio governed workflow | Repository-validated implementation | Validated path for Worker and Passport lifecycle, Human Review, Runtime Permit evaluation, mock Action Broker receipt, Evidence Records, Stamps, Audit Export reconstruction, and Passport Studio kernel-run visibility. | Repository validation only; no customer deployment, live connectors, external execution, production authorization, legal conclusion, compliance conclusion, security authorization, or audit opinion. |
| Public Control Plane and Passport Studio product surfaces | Repository-validated implementation | The Version 1 public surfaces have reproducible source validation. They qualify as production-hosted Version 1 evidence only after the exact deployed revision has verified production routes, successful production canaries, and an identified rollback boundary. | Repository validation does not establish deployment, customer identity, tenant persistence, customer evidence custody, connector execution, customer activation, or runtime action authority. |
| Authenticated Passport Studio Worker adapter | Production-capable component | A separately validated server-side component intended for controlled customer-managed deployment. | Component capability does not establish installation, activation, customer authorization, operating effectiveness, or customer-production operational status. |
| Durable governance contracts | Repository-validated implementation | Tenant-scoped record lookup, role and separation-of-duties checks, append-only evidence behavior, secret-like value rejection, local record persistence, and backup/export shapes for review. | Synthetic implementation evidence; not a customer evidence store, production database, or customer-hosted runtime by itself. |
| Customer-managed readiness packets | Review evidence | Owner-acceptance, install readiness, identity/session handoff, persistence/storage, evidence custody, backup/restore, support/update boundary, release-management, and customer delivery package readiness evidence. | Supports review only; customer operation requires written agreement, customer owner approval, security/privacy/legal/commercial review, configured deployment, and acceptance evidence. |
| Existing or unregistered AI worker intake | Customer-controlled path | Passport Studio can support manual intake of existing AI worker details through uploaded or pasted files and draft records. In a customer-managed environment, customers can extend intake through approved file libraries, registry exports, APIs, repositories, usage exports, or environment-local scanning to create draft Passport candidates. | Automation must run under the customer's authorization, security controls, privacy rules, and data boundaries. The public Version 1 does not scan, monitor, enforce, or approve unregistered AI use in a customer environment. |
| Connector and MCP readiness path | Gated readiness | Connector promotion records, MCP boundary packets, local harness evidence, and customer-live authorization gates prepare Jira, Slack, local MCP, API, and system-action paths for owner/security/privacy review. | No live customer connectors, live MCP, customer environment connection, secret store, customer data, or external tool calls until separately implemented, tested, authorized, and controlled. |
| Runtime enforcement and production connectors | Customer implementation required | Customer IAM, model runtime, tools, APIs, MCP-compatible transports, logs, Runtime Permit checks, Action Broker mediation, and system-of-record actions. | Requires implementation, testing, customer authorization, evidence capture, controlled rollout, and customer operation approval. |
Evaluation Context
Review the homepage, Passport preview, Governed Workflow, Create a Scaled Agent, and Passport Studio product view to understand the control-plane loop.
Review Security, Privacy, Terms, Shared Responsibility, Governance Assurance, CMMC evidence-readiness, and framework readiness pages for boundaries and evidence posture.
Review the Public Resources, Defense & Government solution, Forward-Deployed AI, Procurement Accelerator, and first-30-day path to understand guided evaluation and implementation support.
Model Route Governance
Scaled Agents can represent model-route choices as Passport, Toll Gate, Human Review, Runtime Permit, and Stamp Ledger records. The route framework supports right-sizing requests, evaluating on representative workload data, enforcing guardrails, testing before promotion, and tracking total task cost, not just token price.
Sensitive or regulated data uses approved enterprise routes; low-complexity, high-volume work can start low-cost; routine business reasoning can use mid-tier; complex, high-risk, agentic, or deeply analytical work may require frontier-tier review.
New models enter an eval queue before production use, failed quality thresholds escalate one tier or route to human review, and Stamp Ledger entries record scorecard, reviewer, rollback, and route-change evidence.
Model-route cost review should include input, output, retrieved context, tool calls, retries, caching, latency impact, and human review so teams can evaluate total task cost, not just token price.
This is a governance and routing framework. It helps align model choices to workload, policy, evidence, and owner review; it does not certify compliance, approve production use, endorse providers, or replace customer validation.
First 30 Days
| Week | Focus | Expected output |
|---|---|---|
| 1 | Define buyer goals, AI worker candidates, data boundaries, owners, and review constraints. | Evaluation scope and initial AI worker shortlist. |
| 2 | Create draft Blueprints and map each worker to owner, scope, risk tier, review path, and evidence needs. | Draft Blueprint set and Passport readiness gaps. |
| 3 | Review Passport, Toll Gate, Human Review, Runtime Permit, and Action Broker fit against one mock workflow. | Control-plane walkthrough with blockers and assumptions. |
| 4 | Decide whether to continue with advisory support, licensed customer-hosted or customer-managed deployment planning, partner-led implementation guidance, or backlog deferment. | Owner decision record and next-slice plan. |
Customer Operation Criteria
Customer-hosted or customer-managed deployment, authentication, workspace separation, least-privilege roles, account recovery, and customer-owner administration must be approved and tested.
Passport, Registry, Toll Gate, Human Review, Runtime Permit, Action Broker, Evidence Record, and Audit Export packages need customer-controlled storage and retrieval rules.
Support tiers, security intake, incident routing, notification expectations, and escalation contacts must be governed by written agreement.
Security, Privacy, And Regulated Data
Use the readiness intake for non-sensitive security concerns and state that the request is security-related. Do not submit secrets, credentials, regulated records, customer evidence, source code, or sensitive architecture in public forms.
Public paths are not a HIPAA, GDPR, CCPA, employee-record, payment-card, or regulated-data intake channel. Customer-specific regulated data requires a reviewed private path and written terms.
Customer workspace data, Passport records, evidence records, retention, deletion, subprocessors, cross-border transfers, and audit access must be controlled by the applicable agreement.
Evidence Standard
Worker, Passport, owner, purpose, risk tier, scope, tool/data boundary, policy version, review state, requested action, decision, missing inputs, and lifecycle outcome.
Material or unclear actions should link to a Human Review item with reviewer role, decision, evidence considered, conditions, and next review date.
Exports should use redacted summaries, non-secret identifiers, related record IDs, hashes where appropriate, and explicit limitations. They are readiness support, not audit opinions.
Delivery Model
Best for teams validating AI worker governance needs before platform commitment.
Best for workflow discovery, operating-model design, implementation planning, and governed rollout support.
Best for advisory firms, GRC consultants, security advisors, and implementation partners supporting multiple clients.
Portability And Accessibility
Customer-specific Passport records, evidence summaries, decisions, and exports should be available in reviewable formats defined by the applicable agreement.
Customer exit should define export format, retention, deletion, archival evidence, revocation state, and final owner acknowledgement.
The public site targets keyboard-operable navigation, readable contrast, descriptive alt text, labeled forms, and accessible tabs. Accessibility gaps should be routed through readiness intake with page, device, browser, and assistive-technology context.
Next Step
Start with a specific Worker, accountable owner, business outcome, and consequential decision or action. Then trace the controls and evidence required to govern it.