Agentic AI · Governance & Trust

AI Agent Governance — Discover, Observe, and Control Every Agent in Production

Agents are being spun up faster than any team can track — by developers, by other agents, and by tools nobody registered with IT. This directory covers the platforms built to find those agents, watch what they do, and enforce policy before something goes wrong.

12Platforms & tools
3Core pillars
2026Curated for

Three Pillars of Agent Governance

Every platform below solves for one or more of these — the same shape as governance for any autonomous system, applied to AI agents.

01 · Discover

Find every agent

Inventory agents wherever they run — instrumented via OpenTelemetry, exposed through an MCP server, called via a cloud AI API, or running locally on someone's laptop.

02 · Observe

Trace what they do

Step-by-step execution traces of tool calls, cost, latency, and output quality — plus continuous evaluation for drift, hallucination, and groundedness.

03 · Govern

Enforce policy

Non-human identity and access control, restricted tool permissions, budget limits, PII and prompt-injection checks, and an audit trail for every action an agent takes.

AI Agent Governance Platforms & Tools

Twelve platforms spanning agent discovery, runtime observability, and non-human identity and policy enforcement.

1

Arthur AI

Discovers agents across an enterprise via telemetry, MCP servers, network traffic, and cloud AI APIs, then applies runtime policies — restricted tools, budget caps, PII checks, prompt-injection protection — with a full audit trail.

DiscoveryPolicy enforcement
Visit site
2

Galileo

Converts offline agent evaluations into low-latency production guardrails, using distilled evaluator models to monitor 100% of traffic for hallucination, drift, and policy violations without the cost of a full LLM judge.

EvaluationRuntime guardrails
Visit site
3

WitnessAI

A unified visibility and control layer for how employees, models, applications, and agents use AI — flagging data leakage, prompt injection, and compliance violations while tracking AI spend across the organization.

VisibilityCompliance
Visit site
4

Vijil

An AI agent trust platform spanning the full lifecycle — pre-production testing, production defense, continuous evaluation, and hardened components — aimed at cutting the time it takes an agent to earn enterprise trust.

TestingTrust scoring
Visit site
5

SGNL

A continuous identity platform that replaces standing access with dynamic, context-aware authorization — granting and revoking an agent's access to critical systems automatically as conditions change.

IdentityNon-human access
Visit site
6

Cerbos

An authorization management platform that centralizes fine-grained permissions as human-readable policy, enforced through stateless decision points — built to secure non-human identities like AI agents at scale.

AuthorizationPolicy engine
Visit site
7

P0 Security

Runtime access control that governs what agents, users, and machines can actually do across systems — preserving identity context through an entire action chain and eliminating standing privileges.

Runtime accessLeast privilege
Visit site
8

Enkrypt AI

Protects agents and LLMs across their lifecycle with runtime guardrails, adversarial red teaming, and automated compliance checks — detecting prompt injection, jailbreaking, and data leakage in real time.

Red teamingRuntime guardrails
Visit site
9

Guardrails AI

An open-source framework for validating agent and LLM inputs and outputs — simulating test data, catching failure modes through dynamic evaluation, and deploying runtime checks for policy violations and hallucinations.

Open sourceI/O validation
Visit site
10

Aporia

Real-time guardrails that sit between an agent and its tools or outputs, blocking hallucinations, prompt injection, and off-policy responses before they reach a user or a downstream system.

GuardrailsPolicy enforcement
Visit site
11

Zenity

Governs enterprise copilots and AI agents from build through runtime, comparing each agent's actual behavior against its intended instructions and permissions to catch drift, misuse, and policy violations.

Copilot governanceLifecycle security
Visit site
12

EgisAI

Drops into an existing agent framework with one line of code to automatically discover every agent, mask sensitive data and block risky tool calls at runtime, and generate an audit trail of every action for compliance.

Runtime enforcementAudit trail
Visit site