Not governance claims. Governance artifacts. Open Policy Agent enforcement, structured decision traces, runtime sandboxing, and semantic data protection, verifiable, auditable, and built into every decision.
Discovery identifies agents. Enforcement applies to actions that pass through Operon's runtime or a configured interception point.
Imported agents. Agents admitted into the Operon runtime use its policy checks and decision traces. Review the imported tools and bound policies before promotion to production.
Existing executors. The governance wrapper intercepts configured outbound model calls. Tool calls and other execution paths need their own governed routing; wrapping a model call does not establish control over every action the agent can take.
Your wider governance program. Operon's execution records can support control reviews and audit evidence alongside your existing GRC tools. Agree evidence mappings and transfer requirements during the architecture review; a packaged connector is not implied.
Three illustrative artifacts show the intended enforcement path: a policy, an approved action trace, and a denied action trace. Use them to frame an architecture review against your own workflow.
Policies are declared in OPA/Rego. The runtime evaluates each agent action against the bound policy before dispatch. The same policy runs at compile time (binding to artifacts) and at runtime (verifying current context). One source of truth.
# policy.rego: Clinical agent: PHI write controls package operon.clinical.phi default allow = false # Allow PHI writes only when: # - Agent is on the approved list AND # - Action is escalated to a clinician on the care team AND # - The classification of the data matches the agent's clearance allow { input.agent.id == data.approved_clinical_agents[_] input.action.kind == "phi_write" input.escalation.reviewer.role == "clinician" input.escalation.reviewer.member_of == input.patient.care_team input.data.classification <= input.agent.clearance } # Always escalate when the agent is uncertain escalate { input.confidence < 0.85 }
The Evidence Data Trace is the immutable record of every governed action: the agent, the input, the policies fired, the model version, the human reviewer if any. Open-schema, queryable in SQL, exportable to OpenTelemetry.
// EDT record: single agent action { "trace_id": "edt_01HXY8ZMQF3K...", "agent": { "id": "clinical-summarizer-v3", "sha": "4b2..." }, "input": { "data_class": "PHI", "redactions": 12 }, "policy_evals": [ { "policy": "phi_write", "result": "escalate", "latency_ms": 4 }, { "policy": "residency", "result": "allow", "latency_ms": 1 } ], "model": { "provider": "anthropic", "name": "claude-opus-4-6" }, "human_review": { "reviewer": "dr_chen@hospital.org", "decision": "approve" }, "signature": "sha256:e9c..." }
An agent attempts to write outside its clearance. Policy denies. The action never reaches the model. The denial is logged. The reviewer is notified. The agent's authority ceiling is reduced for review. No surprise outputs reach production. No partial state in the system of record.
// Denied action: full incident trace { "event": "action_denied", "trace_id": "edt_01J2...", "reason": "data_classification > agent_clearance", "agent": "finance-summarizer-v1", "data": { "class": "MNPI", "clearance": "INTERNAL" }, "action": "never_dispatched", "escalation": { "workspace": "sec-incidents", "sev": "S2" }, "agent_state": { "authority_ceiling": "reduced_pending_review" } }
A literal kill switch in a regulated workflow is an anti-feature: it leaves records mid-write and financial transactions with orphaned compensating actions. Regulated operations require predictable transactional boundaries, not abrupt termination.
Before an agent reaches production, three questions have to be answered with evidence, not intent: is it safe to run, is it fair to the people it affects, and can you prove what it did. These are the gates Operon is built to enforce and record.
Operon replaces the raw kill switch with a fails-safe scoped pause, so halting a problem never leaves a record half-written or a transaction with orphaned compensating actions. Every item on this list produces an artifact in the Evidence Data Trace, not a line in a slide.
Agents can act on their own. Accountability never should. As autonomy rises, the question is not whether a human is in every loop, it is whether a named human owns every boundary the agent operates inside.
Operon binds each of these boundaries to policy, records who holds them in the audit trail, and routes every escalation to the human who owns it.
Fleets in different legal entities, regions, or classification levels can exchange signed results through the Control Plane without exposing prompts, weights, or private memory. Federation flows through audit, not around it.
Because EDT is one open-schema record, evidence packs for SOX, HIPAA, GDPR, EU AI Act, and ISO 27001 generate from the same source, no hand-assembly across five systems.
PHI access, agent identity, reviewer attribution. Evidence packs map to 45 CFR Part 164.
Material control evidence with deterministic compile artifacts and signed runtime decisions.
Decision traces include the human-in-the-loop attribution required for automated-decision-making controls.
Article-by-article alignment for high-risk AI systems; conformity-assessment-ready evidence.
Private-cloud and air-gapped deployments inherit your existing ISMS controls. Certification status for Operon Cloud is available on request.
Schedule a 45-minute architecture review. We'll map Operon's governance artifacts to your current evidence model, and show you the gaps either way.