What needed solving
AI agents now call real tools: they push code, run shell commands, query databases and read files. Most teams have no single place that decides which of those calls an agent may make, stops a dangerous one before it runs, or keeps a record they could show an auditor afterwards.
How we're building it
Every agent tool call passes through one pipeline: an emergency kill switch, a per-agent tool allow-list, policy rules, governed operations, budget limits and, where needed, human approval. Governed operations are dangerous actions such as force-push, DROP TABLE, rm -rf and reading secrets, each mapped to the OWASP LLM Top 10, OWASP Agentic and MITRE ATLAS. Every decision, whether allowed, held for approval or blocked, is written to a tamper-evident evidence ledger with downloadable receipts. An MCP proxy brings any MCP server under the same rules, alongside local posture scanning, compliance-style reports and role-based console access.
What we learned
Built test-first with AI-assisted engineering: 369 backend tests and about 90 frontend tests. Governance only earns trust when every decision can be replayed: the ledger and its receipts matter as much as the block itself.
What we are testing next
Can the harness govern a coding agent live, checking every Bash, Write and Read that Claude Code attempts before it runs, without slowing the developer down?
Where it is
- Sep 2026Gateway pipeline, governed operations and evidence ledger built test-first
- Oct 2026Live beta with an invite-only console, MCP proxy and public demo instance
- NextGovern Claude Code itself live, checking each tool call before it runs
Live beta. The console is invite-only, and the screenshot shows sample data from a demo instance.

- R-039Vantage: Health Operations Twin
A geospatial digital twin for hospital operations, from a national 3D map of hospital estates down to room-level floor plans, queried in natural language.
- R-025Connected Highways
AI planning and risk copilots for major highways programmes.
- R-026CivilMap - Construction Command Center
Real-time visibility across complex infrastructure programmes.
