Govern the AI Workers you build, buy, or deploy — with customer-controlled identity, authority, human oversight, and evidence.

Current Capability Status

See what Scaled Agents can govern today.

Evaluate the current control-plane capabilities for governing AI Workers—from identity and authority through human review, runtime decisions, evidence, and lifecycle.

Available Today

One governed path from AI Worker intent to accountable action.

Scaled Agents connects the records, decisions, and evidence needed to govern AI Workers without turning a registration record into blanket authority.

Shape and register AI Workers

Create a Scaled Agent turns an idea into a structured Blueprint. Passport Studio carries the approved identity, owner, purpose, scope, risk, permissions, and lifecycle record forward.

Govern decisions and actions

Toll Gates evaluate policy and evidence. Human Review captures accountable decisions. Runtime Permits provide short-lived authority for the exact action under review.

Reconstruct the evidence trail

Stamps, workflow events, action decisions, and audit exports preserve what was requested, what evidence was considered, who decided, and what happened next.

Scaled Agents does not turn a Blueprint, Passport, Toll Gate, Stamp, readiness review, or evidence package into legal advice, compliance approval, security authorization, audit opinion, certification, or blanket production authority.

Review detailed capability evidence and operating boundaries

How To Read This Page

Status labels describe evidence posture, not formal approval.

The page separates public materials from four evidence states. A higher state for one component never promotes the complete platform, and a status label does not create legal, compliance, security, audit, production, or operating approval.

Available now

Public website content, templates, guided intake, draft Blueprint paths, and readiness materials that can support planning, evaluation, and owner review.

Repository-validated implementation

Identified source or artifacts with reproducible validation of the stated behavior. This does not establish deployment or customer operation.

Production-hosted Version 1 evidence

The exact version is deployed to production infrastructure with verified production routes, successful production canaries, and an identified rollback boundary. Customer activation and action authority remain separately gated.

Production-capable component

A deployable component with validated server-side operating and control responsibilities. This does not assert customer deployment or activation.

Customer-production operational

The exact authorized customer-managed deployment and scope, supported by current operating evidence and accountable owner authorization.

Review evidence

Readiness packets, source-backed records, validation outputs, and implementation notes that help accountable owners decide what remains open before customer operation.

Customer-controlled path

Capabilities a customer may automate or operate inside its own controlled environment, including file intake, registry exports, APIs, repositories, usage records, or environment-local scanning.

Gated readiness

Connector, MCP, identity, storage, support, and runtime paths that require defined scope, security and privacy review, testing, rollback or pause controls, and accountable owner decision.

Customer implementation required

Production-adjacent operation, runtime enforcement, customer IAM, system-of-record actions, and live connectors that require customer-owned implementation and approval before use.

Read status labels as planning posture. They do not certify compliance, validate security posture, approve production use, authorize AI workers, create audit opinions, or replace customer owner decisions.

Capability Status

Separate public evaluation materials, implementation maturity, customer-controlled paths, and live-operation gates.

The public website, Create a Scaled Agent flow, Passport planning records, Control Plane proof path, and readiness packets are suitable for readiness conversations and guided enterprise evaluation. Customer-specific operation requires approved scope, access controls, contracts, privacy/security review, implementation evidence, and customer owner authorization.

CapabilityStatusWhat it meansBoundary
Public website and resourcesAvailable nowPublic pages, resources, use cases, Advisor paths, training catalog, and readiness content.Informational only; no customer-specific approval.
Create a Scaled AgentAvailable nowDraft Blueprint path for shaping a worker idea, classifying risk, and preparing next steps.Blueprints are recommendations, not approval records.
Passport planning recordAvailable nowPublic draft planning record showing owner, purpose, scope, risk, evidence posture, Toll Gates, and lifecycle context.Draft only; not an approval, authorization, or live customer record until customer-specific review, approval, and implementation gates are complete.
Control Plane and Passport Studio governed workflowRepository-validated implementationValidated path for Worker and Passport lifecycle, Human Review, Runtime Permit evaluation, mock Action Broker receipt, Evidence Records, Stamps, Audit Export reconstruction, and Passport Studio kernel-run visibility.Repository validation only; no customer deployment, live connectors, external execution, production authorization, legal conclusion, compliance conclusion, security authorization, or audit opinion.
Public Control Plane and Passport Studio product surfacesRepository-validated implementationThe Version 1 public surfaces have reproducible source validation. They qualify as production-hosted Version 1 evidence only after the exact deployed revision has verified production routes, successful production canaries, and an identified rollback boundary.Repository validation does not establish deployment, customer identity, tenant persistence, customer evidence custody, connector execution, customer activation, or runtime action authority.
Authenticated Passport Studio Worker adapterProduction-capable componentA separately validated server-side component intended for controlled customer-managed deployment.Component capability does not establish installation, activation, customer authorization, operating effectiveness, or customer-production operational status.
Durable governance contractsRepository-validated implementationTenant-scoped record lookup, role and separation-of-duties checks, append-only evidence behavior, secret-like value rejection, local record persistence, and backup/export shapes for review.Synthetic implementation evidence; not a customer evidence store, production database, or customer-hosted runtime by itself.
Customer-managed readiness packetsReview evidenceOwner-acceptance, install readiness, identity/session handoff, persistence/storage, evidence custody, backup/restore, support/update boundary, release-management, and customer delivery package readiness evidence.Supports review only; customer operation requires written agreement, customer owner approval, security/privacy/legal/commercial review, configured deployment, and acceptance evidence.
Existing or unregistered AI worker intakeCustomer-controlled pathPassport Studio can support manual intake of existing AI worker details through uploaded or pasted files and draft records. In a customer-managed environment, customers can extend intake through approved file libraries, registry exports, APIs, repositories, usage exports, or environment-local scanning to create draft Passport candidates.Automation must run under the customer's authorization, security controls, privacy rules, and data boundaries. The public Version 1 does not scan, monitor, enforce, or approve unregistered AI use in a customer environment.
Connector and MCP readiness pathGated readinessConnector promotion records, MCP boundary packets, local harness evidence, and customer-live authorization gates prepare Jira, Slack, local MCP, API, and system-action paths for owner/security/privacy review.No live customer connectors, live MCP, customer environment connection, secret store, customer data, or external tool calls until separately implemented, tested, authorized, and controlled.
Runtime enforcement and production connectorsCustomer implementation requiredCustomer IAM, model runtime, tools, APIs, MCP-compatible transports, logs, Runtime Permit checks, Action Broker mediation, and system-of-record actions.Requires implementation, testing, customer authorization, evidence capture, controlled rollout, and customer operation approval.

Evaluation Context

What an enterprise evaluator should review first.

Product proof

Review the homepage, Passport preview, Governed Workflow, Create a Scaled Agent, and Passport Studio product view to understand the control-plane loop.

Trust proof

Review Security, Privacy, Terms, Shared Responsibility, Governance Assurance, CMMC evidence-readiness, and framework readiness pages for boundaries and evidence posture.

Delivery proof

Review the Public Resources, Defense & Government solution, Forward-Deployed AI, Procurement Accelerator, and first-30-day path to understand guided evaluation and implementation support.

Model Route Governance

Evaluate model routes by task, evidence, cost, and rollback path.

Scaled Agents can represent model-route choices as Passport, Toll Gate, Human Review, Runtime Permit, and Stamp Ledger records. The route framework supports right-sizing requests, evaluating on representative workload data, enforcing guardrails, testing before promotion, and tracking total task cost, not just token price.

Route Decision Path

Sensitive or regulated data uses approved enterprise routes; low-complexity, high-volume work can start low-cost; routine business reasoning can use mid-tier; complex, high-risk, agentic, or deeply analytical work may require frontier-tier review.

Eval & Feedback Loop

New models enter an eval queue before production use, failed quality thresholds escalate one tier or route to human review, and Stamp Ledger entries record scorecard, reviewer, rollback, and route-change evidence.

Cost Governance

Model-route cost review should include input, output, retrieved context, tool calls, retries, caching, latency impact, and human review so teams can evaluate total task cost, not just token price.

This is a governance and routing framework. It helps align model choices to workload, policy, evidence, and owner review; it does not certify compliance, approve production use, endorse providers, or replace customer validation.

First 30 Days

A practical first-month evaluation path.

WeekFocusExpected output
1Define buyer goals, AI worker candidates, data boundaries, owners, and review constraints.Evaluation scope and initial AI worker shortlist.
2Create draft Blueprints and map each worker to owner, scope, risk tier, review path, and evidence needs.Draft Blueprint set and Passport readiness gaps.
3Review Passport, Toll Gate, Human Review, Runtime Permit, and Action Broker fit against one mock workflow.Control-plane walkthrough with blockers and assumptions.
4Decide whether to continue with advisory support, licensed customer-hosted or customer-managed deployment planning, partner-led implementation guidance, or backlog deferment.Owner decision record and next-slice plan.

Customer Operation Criteria

What must be true before broader customer operation.

Access and workspace

Customer-hosted or customer-managed deployment, authentication, workspace separation, least-privilege roles, account recovery, and customer-owner administration must be approved and tested.

Evidence and export

Passport, Registry, Toll Gate, Human Review, Runtime Permit, Action Broker, Evidence Record, and Audit Export packages need customer-controlled storage and retrieval rules.

Support and incident path

Support tiers, security intake, incident routing, notification expectations, and escalation contacts must be governed by written agreement.

Security, Privacy, And Regulated Data

Use public forms for planning context only.

Security or incident intake

Use the readiness intake for non-sensitive security concerns and state that the request is security-related. Do not submit secrets, credentials, regulated records, customer evidence, source code, or sensitive architecture in public forms.

Regulated data FAQ

Public paths are not a HIPAA, GDPR, CCPA, employee-record, payment-card, or regulated-data intake channel. Customer-specific regulated data requires a reviewed private path and written terms.

Data handling boundary

Customer workspace data, Passport records, evidence records, retention, deletion, subprocessors, cross-border transfers, and audit access must be controlled by the applicable agreement.

Evidence Standard

Evidence should reconstruct why an AI worker action was allowed, blocked, escalated, or deferred.

Minimum evidence set

Worker, Passport, owner, purpose, risk tier, scope, tool/data boundary, policy version, review state, requested action, decision, missing inputs, and lifecycle outcome.

Human review

Material or unclear actions should link to a Human Review item with reviewer role, decision, evidence considered, conditions, and next review date.

Export boundary

Exports should use redacted summaries, non-secret identifiers, related record IDs, hashes where appropriate, and explicit limitations. They are readiness support, not audit opinions.

Delivery Model

Choose the engagement path that matches the buyer's maturity.

Guided evaluation

Best for teams validating AI worker governance needs before platform commitment.

Forward-deployed support

Best for workflow discovery, operating-model design, implementation planning, and governed rollout support.

Partner-led enablement

Best for advisory firms, GRC consultants, security advisors, and implementation partners supporting multiple clients.

Portability And Accessibility

Customer records and accessible review paths must remain practical.

Data portability

Customer-specific Passport records, evidence summaries, decisions, and exports should be available in reviewable formats defined by the applicable agreement.

Exit plan

Customer exit should define export format, retention, deletion, archival evidence, revocation state, and final owner acknowledgement.

Accessibility statement

The public site targets keyboard-operable navigation, readable contrast, descriptive alt text, labeled forms, and accessible tabs. Accessibility gaps should be routed through readiness intake with page, device, browser, and assistive-technology context.

Next Step

Evaluate one governed AI Worker outcome.

Start with a specific Worker, accountable owner, business outcome, and consequential decision or action. Then trace the controls and evidence required to govern it.