AI is outrunning governance. Catch up.

Identity, scoped access, human approval and a full audit trail for every AI agent.

Book a governance demo.

Takes a minute. Then pick a time that suits you.

We use these details to arrange your demo and follow up about Tilde. See our privacy policy.

13%

of organizations think they have the right AI agent governance

Gartner, April 2026
97%

of organizations with an AI-related breach lacked proper AI access controls

IBM, 2025
0

credentials in model context. Tilde brokers every secret.

What changed in 2026.

  1. Evaluation agents escaped a test sandbox into Hugging Face

    During a cyber-capability evaluation, frontier-lab agents running with reduced safeguards spent about two and a half days inside Hugging Face’s infrastructure, taking roughly 17,600 actions and collecting cloud credentials.

    Source: Hugging Face
  2. “We Must Pace the Frontier”

    Anthropic’s CEO argued the industry should deliberately slow capability gains so safety work can catch up, with independent evaluators and shared standards.

    Source: Dario Amodei
  3. New York’s financial regulator warned about frontier AI risk

    NYDFS told regulated firms to consider the heightened cybersecurity risks that frontier AI models bring, from faster attacks to agent access.

    Source: NYDFS

The questions every audit now asks.

Who is the agent acting as?

Shared service accounts and pasted API keys make it impossible to say which agent did what, on whose behalf.

What can it reach?

An agent with broad access can read, change or send far more than its task needs. One bad instruction goes a long way.

Who approved it, and where’s the record?

Risky actions happen without a named reviewer, and the evidence is scattered across tools, if it exists at all.

Controls on the path of every action.

An identity for every agent
Each agent gets its own identity, separate from the person who built it. Access is granted explicitly to people, groups and agents.
Fine-grained permissions
Scope agents to workspaces and the exact tools and data they need. Private by default, shared on purpose.
Secrets stay out of prompts
OAuth, API keys and custom credentials are encrypted, brokered and rotated by the platform. Agents never see them.
Approval for risky actions
Your policy decides which tool calls run and which pause for a named reviewer with the context to decide.
An audit trail your auditor can use
Follow each request from identity to policy, approval and outcome. Traces stay in your own Langfuse. Audit data exports cleanly.
One inventory, one off switch
The registry shows every agent, its owner, access and health. Disable one in a single place.
Resolve identityresearch-agent
Check policyApproval required
Human decisionApproved
Write audit eventevt_01K4…9J

From shadow AI to governed AI.

  1. 01

    Find what’s running

    Register existing agents, whatever framework they use, and give each an owner.

  2. 02

    Set the policy

    Grant access, move credentials into the platform and mark the actions that need approval.

  3. 03

    Prove it

    Review decisions and export the record whenever an auditor, regulator or board asks.

Questions we hear.

Does Tilde make us compliant?

No platform makes you compliant on its own. Tilde gives you the controls and evidence regulators ask about, such as identity, access, approvals and audit, across NYDFS, model risk management and similar expectations.

Do we have to rebuild our agents?

No. Register agent endpoints built with the frameworks you already use. Tilde governs their access, credentials and actions through its gateway.

Can we require a human to approve certain actions?

Yes. Define which actions pause for review and route them to an authorized person. Everything else runs within its permissions.

Where does the audit data live?

In your environment. Self-host Tilde in AWS, Azure, Google Cloud or on-prem. Traces go to your self-hosted Langfuse under your retention rules.

Say yes to AI. Keep your auditor happy.

Book a governance demo