Enterprise

Be able to answer for your agents

Customer security reviews now ask about AI governance posture. Regulators ask for records of automated actions. The board asks what the agents cost. Deixic is where those answers come from.

The customer questionnaire

Somewhere in this quarter’s security review: “Describe your AI governance posture.” The answer needs an inventory of agents, the controls in front of them, and evidence that both exist. Deixic’s fleet list, gated approvals, and activity trail are that answer — screens you can show, records you can point to.

Governance posture
Inventoryagents registered, with owners
Controlsgated actions wait for sign-off
Evidenceevery gated decision recorded

The regulator’s records

EU AI Act obligations for high-risk systems begin August 2, 2026. Article 12 asks for automatic event recording; Article 14 asks for human oversight that can intervene. The activity trail and the approval gate are the runtime-side artifacts those articles describe — our Article-by-Article read maps the rest. US security reviews cite NIST AI RMF instead, and procurement teams that ask for ISO 27001 have started asking for ISO/IEC 42001 — the framework mapping shows which runtime records answer each.

EU AI Act · runtime side
Art. 12record-keeping → activity trail
Art. 14human oversight → gated approvals
Aug 2, 2026Annex III obligations in effect

The board’s number

What the agents cost, by agent, month to date — with a flagged gap wherever a run produced no usable cost evidence. Platform, security, and finance read the same view, so the number in the board deck is the number in the product.

Spend · July — example workspace
$12,4005 agents · 2 gaps flagged
projection to month end included

One system of record, whatever built the agent

One team builds on LangGraph, another on CrewAI, a third writes its own loop against the model API. Guardrails inside each framework produce records that don’t agree — and a compliance review that has to read all three. Deixic sits outside the frameworks: registration, gates, and the trail work the same way regardless of what produced the agent.

The test that separates a gate from an instruction: whether the control still holds when the agent pursues a wrong objective with total conviction. A held action waits for a named person, and the agent cannot skip the wait. A system prompt only binds an agent that still agrees to be bound. Why enforcement has to live outside the agent walks the failure cases, starting with the coding agent that deleted a production database past a system-prompt instruction not to touch it.

When the process only exists in people’s heads

Some production paths were never written down — who must approve a customer send, what happens on a stale CRM row, which systems are in scope. Before you widen agent autonomy over those paths, we sit with business, platform, and security owners and write them down.

You leave with

  • Connected tools and agents you can cost and monitor.
  • Spend and activity for work that ran through Deixic.
  • A process map and approval matrix your security and platform reviewers can read — the evidence pack for the next audit.

The security review, short version

Model keysbring your own
Your datanever used for training
SOC 2 Type IIaudit underway
Security contactsecurity@deixic.com answers

The full trust page →