Fleet posture
Govern the AI on your devices.
Governance is the endlayer module where you set the rules for AI. Which AI tools and coding agents are approved, what an agent may do on its own, which MCP servers it may reach, and what may leave in a prompt. Publish a rule, and every device is checked against it within fifteen minutes. It grades, assigns an owner and keeps the record. Guardrails in the agent warn, redact or block in real time; removing an installed app waits for an administrator.
Policy library
Recent versions
the Governance overview · example devices, not live data
Your AI policy needs checking.
Most AI governance starts as a document: an approved-tools list, an acceptable-use policy, a framework spreadsheet. It is true the day it is written. It cannot tell you which of two hundred laptops broke it this morning, which shadow AI nobody has ruled on yet, or who changed the rule last month.
AI arrives through people, not procurement.
Someone installs a coding agent, points it at a repository and gives it a credential. Your approved-tools list never finds out.
- Nothing checks the laptops against the policy
- Agents run in modes nobody approved
- EU AI Act, ISO/IEC 42001 and SOC 2 want a record
It answers from the device, and grades honestly.
A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.
- The device reports. Your policy decides
- Unknown is never counted as a pass
- Every publish is a version you can export
Nothing was looking where the AI runs.
Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.
- We are an AI governance company
- Customers could not say what AI ran on their machines
- So we built a control plane for the device
Rules that check every device.
Governance reads the same device reports Surfaces and Monitoring already use, so there is nothing to integrate. Turn one rule on and the fleet is graded against it on the next report. The record starts with the first version.
A rule that grades the fleet
Approve or disallow a tool and every device carrying it passes or fails within fifteen minutes.
A version on every decision
Each publish is v+1, with a name and a time. The old version stays readable.
Removal only with approval
A blocked app raises a request. Nothing leaves a machine until an administrator says so.
Evidence you can hand over
Every verdict cites the version that made it. Packs and a nightly export keep it outside the product.
One rule, checked on every device.
Nothing new is installed. The rules give meaning to the reports the agent already sends every fifteen minutes.
Each has a collector in the agent and a grader in the backend.
Graded, verified, applied, removed, installed, scheduled.
A fresh organisation grades ungraded until someone decides.
Every device rechecks on its next report.
You decide
Turn a rule on in the Library, or decide a tool from its row in Monitoring.
Library · sanction drawerIt publishes as a version
A new version is inserted, based on the one you started from. A stale editor is refused by name.
v+1 · immutableEvery device regrades
On its next report, within fifteen minutes. A missing measurement stays unknown.
every 15 minutes · never a false passFailures surface
Failures reach Events. Anything blocked waits in Requests for an administrator.
Events · Requests · approval firstThe record keeps it
History holds every version. Packs and the nightly export cite the version behind each verdict.
versioned · attributed · exportedGrade one rule against your fleet and keep the verdict.
Start with the policy you already have, on three devices free. Every verdict stays linked to the version of the rule that made it.
One console for rules, versions and requests.
Governance is a left rail and a table, like the rest of the console. The Library holds the rules, Packages maps them to frameworks, History keeps every version, and Events and Requests are the queues that need a person. Pick a view to see what it holds.
Every rule, with its switch
One table of the nineteen rules and the five collection switches. It is the only place in the console that publishes a policy.
| Rule | Effect | Status | Fleet |
|---|---|---|---|
| Approved AI tools | graded | on · 6 listed | pass 188 |
| Disallowed AI tools | graded | on · 2 listed | fail 24 |
| Blocked apps | removed | on · 1 listed | 2 requests |
| Permitted agent modes | graded | on · 2 listed | pass 33 · fail 5 |
| Guardian plugin | installed | on · 4 hosts | 31 of 38 |
| Sensitive data in prompts | applied | on · 2 hosts | 142 caught |
| Minimum OS versions | graded | off | ungraded |
Six effects, on the row. Graded checks and reports. Removed and installed change a machine, after approval. Verified checks that your MDM already does it.
Frameworks, as rules in force
Six packages ship, all off until an administrator adopts one. Active means the mapped rules are on. It never means compliant.
| Package | Authority | Rules in force | Standing |
|---|---|---|---|
| SOC 2 | AICPA Trust Services Criteria | 14 of 23 | adopted |
| EU AI Act | Regulation (EU) 2024/1689 | 9 of 13 | adopted |
| ISO/IEC 42001 | AI management systems | 19 mapped | not adopted |
| NIST AI RMF | NIST AI 100-1 | 12 mapped | not adopted |
| GDPR | Regulation (EU) 2016/679 | 11 mapped | not adopted |
Mappings, not certifications. The citations are a reading of the framework. Certification still needs evidence and review.
Every version, newest first
Who published it and what the fleet looked like under it. Nothing is edited in place, so the table can always say what the rule said on a given day.
| Version | In effect from | Published by | Sanctioned | Unsanctioned |
|---|---|---|---|---|
| v14 in effect | 2 Sep 2026, 09:12 | R. Patel | 6 | 2 |
| v13 | 29 Aug 2026, 16:40 | J. Okafor | 6 | 1 |
| v12 | 26 Aug 2026, 11:05 | R. Patel | 6 | 1 |
| v11 | 19 Aug 2026, 14:22 | J. Okafor | 5 | 1 |
Deleting is disabling. Removing an entry publishes a version in which it is not enforced. The old version stays readable here.
What needs attention now
A control transition, an unsanctioned tool, a device silent for a day, a snapshot quarantined. Fixing the problem removes the row.
| Event | Device | Since |
|---|---|---|
| Unsanctioned tool · Codex CLI | blr-imac-587 | 2 days |
| Permitted MCP hosts · pass → fail | lon-mbp-218 | 6 hours |
| Device silent · no pause recorded | nyc-win-377 | 31 hours |
Archiving records who ignored an issue, and when. Recent detections is the thirty-day feed.
The one page that removes software
One row per blocked thing, not per device. An app on two hundred machines is one decision.
| Blocked | Found on | Blocked by | Standing |
|---|---|---|---|
| Windsurf | 13 devices | Library, v14 | awaiting approval |
| mcp.internal-crm.example | 21 devices | Library, v13 | removing · 17 done |
Nothing is removed until you approve it. Stopping a removal prevents it spreading to machines that have not checked in.
Regulations became Packages. Remediations and Data collection folded into the Library. Every old path still resolves.
Rules, versions, removals and evidence.
The parts a policy document does not have: rules that grade, versions that cannot be edited, removal that waits for approval, runtime controls inside the coding agent, and evidence an auditor can check. Each is a row or a control in the console.
Nineteen rules, each with a switch
Turn one on and fill the list. Every default is off, so the fleet has no position until you give it one.
Every change is a new version
Publishing inserts v+1. The old version stays readable, and a stale editor is refused by name.
The fleet regrades within fifteen minutes
Every device rechecks on its next report. A device that could not be checked is never counted as passing.
Frameworks counted as rules in force
Adopt a package and its rules switch on together. The figure is rules in force, never compliance.
Removal waits for a person
A blocked app raises one request for the whole fleet. Nothing is uninstalled until an administrator approves it.
Prompts scored before they run
A plugin in Claude Code, Cursor, Codex CLI and Antigravity, with your thresholds. It reports the score, never the text.
Secrets and personal data caught on the way out
Warned on, redacted or blocked inside the agent. Matched text never leaves the machine.
A record that outlives the deployment
Evidence packs on request, one export file a day. Every read is logged against the person who made it.
Every change is saved as a version.
There is no update operation. That absence is what lets History answer what the rule said on any given day.
Every check gets a clear result.
Every rule is graded as a pure function of the measurement and the published policy, so the same inputs always give the same verdict. A pass rate that quietly includes unknowns will not survive an auditor. Governance keeps unknown, ungraded and not applicable apart from pass, always.
Checked, and holds. Drawn in the neutral fill, never green.
Checked, does not hold, where the policy chose the softer verdict.
Checked, does not hold. Reaches Events.
Could not be checked. A stale list, a machine gone quiet.
No decision yet. The rule is off.
Does not apply to this device. Never folded into unknown.
Your data stays in your own platform.
Audit evidence in endlayer is the versions, the verdicts, the access log and a nightly export, kept short in the product and as long as you like in storage you own. Everything lives in your own endlayer platform.
Metadata by default. Titles and messages only after an administrator types a lawful basis.
Snapshot bodies for 14 days, derived rows for 30. Read only by roles your admins grant.
One NDJSON file per organisation per day, over HTTPS only. Never the prose.
Evidence packs, from a safe projection. Every read is logged against the person.
Expiry is the window closing. Erasure is a decision: one person, one device, or everything.
Governance completes Surfaces and Monitoring.
Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.
Surfaces
One row per device. Finds the AI tools, agents, models and keys on each one.
Read about Surfaces →Monitoring
One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.
Read about Monitoring →Governance
The rules every device is graded against, with a version on every decision.
Common questions.
- AI governance
- The rules, records and evidence a company keeps about the AI it uses.
- AI policy
- A rule an organisation defines centrally about which AI tools may run, what they may do and what they may reach. In endlayer every policy is versioned and graded against devices.
- Shadow AI
- AI tools people install and use for work without anyone approving them. The AI case of shadow IT.
- AI agent
- Software that can take actions on its own to reach a goal. A coding agent that edits files and runs commands without a person approving each step is the case endlayer governs.
- Model Context Protocol (MCP)
- An open standard for connecting AI assistants to tools and data. An MCP server declared on a device can carry a credential to a system outside the company.
- Data loss prevention (DLP)
- Controls that detect and stop sensitive data leaving. endlayer's sensitive-data rule runs inside the coding agent before a prompt is sent.
- SOC 2
- An assurance report on a service organisation's controls, against the AICPA Trust Services Criteria.
- EU AI Act
- Regulation (EU) 2024/1689, the European Union's law on artificial intelligence, including duties on organisations deploying AI.
- ISO/IEC 42001
- The international standard for an AI management system.
- NIST AI RMF
- The US NIST AI Risk Management Framework: govern, map, measure, manage. Voluntary.
- GDPR
- Regulation (EU) 2016/679, the European Union's data protection law.
- Audit evidence
- The retained record an auditor can check a claim against. In endlayer: versions, verdicts, access logs and a nightly export.
What is endlayer Governance?
It is the endlayer module where you set the rules for AI on your devices. It holds the rules your fleet is graded against and publishes every change as a version. Devices are regraded on their next report, removals wait for an administrator, and History keeps the record.
Can we write our own rules?
You turn on, configure and package the nineteen that ship. You cannot invent a rule kind, because each needs a collector in the agent and a grader in the backend. A rule without a measurement would be a checkbox.
If we adopt the SOC 2 package, are we SOC 2 compliant?
No, and the product will not say you are. A package is a named selection of rules mapped to a reading of the framework. The figure is always rules in force, never compliance.
What is the difference between disallowed and blocked?
A disallowed tool fails its check and stays installed. A blocked app fails and raises a removal request. Nothing is removed until an administrator approves it.
Does the Guardian plugin read our developers' prompts?
It scores them inside the agent host, against the thresholds you published. What comes back is the vertical, the action and the score. Never the text.
What happens to a device that could not be checked?
It is unknown. Unknown is drawn as its own segment and kept out of the pass rate. A control that could not be evaluated has not passed.
Does endlayer help with EU AI Act, ISO/IEC 42001, NIST AI RMF or SOC 2 compliance?
It gives you the device-side evidence those frameworks ask for: which AI tools run, what agents may do, what left in a prompt, and who decided what, with a version on each decision. Packages map rules to the framework clauses. The product reports rules in force and leaves the compliance judgement to you and your auditor.
Can it block AI tools on employee laptops?
Yes, in two ways. Real-time guardrails inside the agent act on the device as it happens: a prompt is scored before it runs, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app waits for a person: the Blocked apps rule raises a removal request, and the uninstall happens only after an administrator approves it. Disallowed is the softer option: the tool fails its check and stays installed. Every rule is graded on every device within fifteen minutes of publishing.
Does it block violations automatically, in real time?
The guardrails do. They run inside the agent on the device, so a blocked prompt or a redacted secret happens at the moment it would have left the machine, and the matched text never leaves it. Grading runs on every report: a device is checked against your policy version, a failure gets an owner, a state and a date it closed, and the evidence is kept and exported. The one action that is never automatic is uninstalling an app. That waits for an administrator. Cloud connectors and SDK ingestion are the planned layers, and the same rules and the same enforcement apply to them the day they ship.
Who can change the policy, and can we tell who did?
Publishing is a capability you grant. Every publish is a new version with a name and a time on it, and a stale editor is refused with both version numbers named. Nothing is ever edited in place.
Take control of the AI already in your company.
It is already installed on the laptops. You can see all of it by this afternoon.