Skip to content
the governance layer

Govern the AI on your devices.

Governance is the endlayer module where you set the rules for AI. Which AI tools and coding agents are approved, what an agent may do on its own, which MCP servers it may reach, and what may leave in a prompt. Publish a rule, and every device is checked against it within fifteen minutes. It grades, assigns an owner and keeps the record. Guardrails in the agent warn, redact or block in real time; removing an installed app waits for an administrator.

Get startedBook a demoSee the views ↓nineteen rules · every publish a version · maps to SOC 2, EU AI Act, ISO/IEC 42001, NIST AI RMF
endlayer|GovernanceOverview
Policy version
v14
since Sep 2, 2026
Rules on
9/ 19
checked across the fleet
Checks failing
6
somewhere in the fleet
Requests
2
waiting for approval

Fleet posture

1,412 pass178 warn6 fail118 unknown
All checks

Policy library

9of 19 rules on
AI tools4 on
Agent behaviour2 on
Connections1 on
Open the library

Recent versions

v14in effectr.patelSep 2
v13j.okaforAug 29
v12r.patelAug 26
Full history

the Governance overview · example devices, not live data

endlayer, in three
Surfaces finds what is on each machine.
Monitoring counts it across the fleet.
Governance decides what is allowed.you are here
why

Your AI policy needs checking.

Most AI governance starts as a document: an approved-tools list, an acceptable-use policy, a framework spreadsheet. It is true the day it is written. It cannot tell you which of two hundred laptops broke it this morning, which shadow AI nobody has ruled on yet, or who changed the rule last month.

why you need Governance

AI arrives through people, not procurement.

Someone installs a coding agent, points it at a repository and gives it a credential. Your approved-tools list never finds out.

  • Nothing checks the laptops against the policy
  • Agents run in modes nobody approved
  • EU AI Act, ISO/IEC 42001 and SOC 2 want a record
why the endlayer platform

It answers from the device, and grades honestly.

A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.

  • The device reports. Your policy decides
  • Unknown is never counted as a pass
  • Every publish is a version you can export
why we built it

Nothing was looking where the AI runs.

Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.

  • We are an AI governance company
  • Customers could not say what AI ran on their machines
  • So we built a control plane for the device
Your GRC toolTracks controls and owners. It never sees a laptop.no device evidence
Your MDMEnforces device settings. It has no idea what an AI agent may do on its own.autonomy is not a setting
Your AI gatewayGoverns traffic that goes through it. Local models and coding agents never do.nothing on the device
Your wikiHolds the policy. Nothing checks it, and nothing remembers the last version.no regrade, no history
what you get

Rules that check every device.

Governance reads the same device reports Surfaces and Monitoring already use, so there is nothing to integrate. Turn one rule on and the fleet is graded against it on the next report. The record starts with the first version.

01

A rule that grades the fleet

Approve or disallow a tool and every device carrying it passes or fails within fifteen minutes.

Library → rule on → next report
02

A version on every decision

Each publish is v+1, with a name and a time. The old version stays readable.

publish → v14 → History
03

Removal only with approval

A blocked app raises a request. Nothing leaves a machine until an administrator says so.

Blocked apps → Requests → approve
04

Evidence you can hand over

Every verdict cites the version that made it. Packs and a nightly export keep it outside the product.

History → evidence pack → export
how it works

One rule, checked on every device.

Nothing new is installed. The rules give meaning to the reports the agent already sends every fifteen minutes.

19rules ship with the product

Each has a collector in the agent and a grader in the backend.

6effects

Graded, verified, applied, removed, installed, scheduled.

0rules on by default

A fresh organisation grades ungraded until someone decides.

15minutes to regrade

Every device rechecks on its next report.

A rule is published as version 14, every device is regraded against it on its next report, and History, Events and the evidence pack record it.you decideLibraryDisallowed AI toolsonCodex CLIaddedbased onv13one click, one versionstale editors refused by namev14your platformregrade · never ourslon-mbp-218failnyc-win-377passblr-imac-587failsfo-mbp-102passber-lnx-044, quiet 31 hunknownv14 in effectthe recordHistoryv14 · R. Patel · 09:12Events24 devices fail Disallowed AI toolsRequestsnone, disallowed stays installedEvidencepack cites v14 for every verdictimmutable · attributed · exported nightly
01

You decide

Turn a rule on in the Library, or decide a tool from its row in Monitoring.

Library · sanction drawer
02

It publishes as a version

A new version is inserted, based on the one you started from. A stale editor is refused by name.

v+1 · immutable
03

Every device regrades

On its next report, within fifteen minutes. A missing measurement stays unknown.

every 15 minutes · never a false pass
04

Failures surface

Failures reach Events. Anything blocked waits in Requests for an administrator.

Events · Requests · approval first
05

The record keeps it

History holds every version. Packs and the nightly export cite the version behind each verdict.

versioned · attributed · exported
start with governance

Grade one rule against your fleet and keep the verdict.

Start with the policy you already have, on three devices free. Every verdict stays linked to the version of the rule that made it.

see it working

One console for rules, versions and requests.

Governance is a left rail and a table, like the rest of the console. The Library holds the rules, Packages maps them to frameworks, History keeps every version, and Events and Requests are the queues that need a person. Pick a view to see what it holds.

Governance · Library

Every rule, with its switch

One table of the nineteen rules and the five collection switches. It is the only place in the console that publishes a policy.

Policy rulesrule · effect · status · fleet
RuleEffectStatusFleet
Approved AI toolsgradedon · 6 listedpass 188
Disallowed AI toolsgradedon · 2 listedfail 24
Blocked appsremovedon · 1 listed2 requests
Permitted agent modesgradedon · 2 listedpass 33 · fail 5
Guardian plugininstalledon · 4 hosts31 of 38
Sensitive data in promptsappliedon · 2 hosts142 caught
Minimum OS versionsgradedoffungraded

Six effects, on the row. Graded checks and reports. Removed and installed change a machine, after approval. Verified checks that your MDM already does it.

Governance · Packages

Frameworks, as rules in force

Six packages ship, all off until an administrator adopts one. Active means the mapped rules are on. It never means compliant.

Packagesframework · rules in force
PackageAuthorityRules in forceStanding
SOC 2AICPA Trust Services Criteria14 of 23adopted
EU AI ActRegulation (EU) 2024/16899 of 13adopted
ISO/IEC 42001AI management systems19 mappednot adopted
NIST AI RMFNIST AI 100-112 mappednot adopted
GDPRRegulation (EU) 2016/67911 mappednot adopted

Mappings, not certifications. The citations are a reading of the framework. Certification still needs evidence and review.

Governance · History

Every version, newest first

Who published it and what the fleet looked like under it. Nothing is edited in place, so the table can always say what the rule said on a given day.

Versionsversion · in effect from · published by · counts
VersionIn effect fromPublished bySanctionedUnsanctioned
v14 in effect2 Sep 2026, 09:12R. Patel62
v1329 Aug 2026, 16:40J. Okafor61
v1226 Aug 2026, 11:05R. Patel61
v1119 Aug 2026, 14:22J. Okafor51

Deleting is disabling. Removing an entry publishes a version in which it is not enforced. The old version stays readable here.

Events

What needs attention now

A control transition, an unsanctioned tool, a device silent for a day, a snapshot quarantined. Fixing the problem removes the row.

Needs attentionevent · device · since
EventDeviceSince
Unsanctioned tool · Codex CLIblr-imac-5872 days
Permitted MCP hosts · pass → faillon-mbp-2186 hours
Device silent · no pause recordednyc-win-37731 hours

Archiving records who ignored an issue, and when. Recent detections is the thirty-day feed.

Requests

The one page that removes software

One row per blocked thing, not per device. An app on two hundred machines is one decision.

Requestsblocked · found on · standing
BlockedFound onBlocked byStanding
Windsurf13 devicesLibrary, v14awaiting approval
mcp.internal-crm.example21 devicesLibrary, v13removing · 17 done

Nothing is removed until you approve it. Stopping a removal prevents it spreading to machines that have not checked in.

Regulations became Packages. Remediations and Data collection folded into the Library. Every old path still resolves.

every feature

Rules, versions, removals and evidence.

The parts a policy document does not have: rules that grade, versions that cannot be edited, removal that waits for approval, runtime controls inside the coding agent, and evidence an auditor can check. Each is a row or a control in the console.

Disallowed AI toolson · 2 listed
Codex CLIWindsurf+ add
graded · fails and stays installed
rules

Nineteen rules, each with a switch

Turn one on and fill the list. Every default is off, so the fleet has no position until you give it one.

v13→ v14
Disallowed AI tools+1
published by R. Patel · 09:12immutable
versions

Every change is a new version

Publishing inserts v+1. The old version stays readable, and a stale editor is refused by name.

passwarnfailunknown
200 devices · v14unknown is not pass
regrade

The fleet regrades within fifteen minutes

Every device rechecks on its next report. A device that could not be checked is never counted as passing.

SOC 214/23
EU AI Act9/13
rules in forcenever compliance
packages

Frameworks counted as rules in force

Adopt a package and its rules switch on together. The figure is rules in force, never compliance.

Windsurf · 13 devicesblocked by v14
leave in placeuninstall all
approval is standing · stop it any time
requests

Removal waits for a person

A blocked app raises one request for the whole fleet. Nothing is uninstalled until an administrator approves it.

Data leakage.3/.7
Prompt injection.4/.7
13 verticalswarn · block
guardian

Prompts scored before they run

A plugin in Claude Code, Cursor, Codex CLI and Antigravity, with your thresholds. It reports the score, never the text.

sensitive data in prompts30 detectors
payment cardAWS keyNHS numberIBAN+ 26
142 caught · 3 redacted2 allowed through unscanned
data protection

Secrets and personal data caught on the way out

Warned on, redacted or blocked inside the agent. Matched text never leaves the machine.

evidence.ndjsonnightly · 05:11
verdicts, versionedall
storage you ownnever the prose
evidence

A record that outlives the deployment

Evidence packs on request, one export file a day. Every read is logged against the person who made it.

versioning

Every change is saved as a version.

There is no update operation. That absence is what lets History answer what the rule said on any given day.

v13 → v14 · published 2 Sep 2026, 09:12 by R. Patelone line changed · everything else identical
v13still readable
Approved AI tools6 listed
Disallowed AI tools1 listed
Permitted MCP hosts3 listed
Guardian pluginon · 4 hosts
v14in effect
Approved AI tools6 listed
Disallowed AI tools2 listed+ Codex CLI
Permitted MCP hosts3 listed
Guardian pluginon · 4 hosts
v13 is not overwritten. Both stay readable, and every verdict cites the version it was graded under.
v+1Every publish is a whole new version, with a name and a time, and a regrade of every device.
409Stale editors are refused, by name. If a colleague published first, you are told both version numbers.
noneDeleting is disabling. Removing an entry publishes a version in which it is not enforced.
what it tells you

Every check gets a clear result.

Every rule is graded as a pure function of the measurement and the published policy, so the same inputs always give the same verdict. A pass rate that quietly includes unknowns will not survive an auditor. Governance keeps unknown, ungraded and not applicable apart from pass, always.

Disallowed AI tools · v14 · 200 devicespass rate 71%, over all 200, never over the 142 that could be checked
pass
142

Checked, and holds. Drawn in the neutral fill, never green.

warn
12

Checked, does not hold, where the policy chose the softer verdict.

fail
12

Checked, does not hold. Reaches Events.

unknown
16

Could not be checked. A stale list, a machine gone quiet.

ungraded
10

No decision yet. The rule is off.

not applicable
8

Does not apply to this device. Never folded into unknown.

where your data lives

Your data stays in your own platform.

Audit evidence in endlayer is the versions, the verdicts, the access log and a nightly export, kept short in the product and as long as you like in storage you own. Everything lives in your own endlayer platform.

day 0
Collected on the device

Metadata by default. Titles and messages only after an administrator types a lawful basis.

your platform
Held, and graded

Snapshot bodies for 14 days, derived rows for 30. Read only by roles your admins grant.

05:11 UTC, nightly
Exported to storage you own

One NDJSON file per organisation per day, over HTTPS only. Never the prose.

on request
Read for an audit

Evidence packs, from a safe projection. Every read is logged against the person.

03:17 UTC
Expired, or erased

Expiry is the window closing. Erasure is a decision: one person, one device, or everything.

day 014 d · bodies gone30 d · rows goneyour export · as long as you keep it
What devices may send at allfive switches in the Library · content switches need a typed lawful basis, kept with a name and a time
Token usagemetadataDaily token and message totals per tool and modelon
SessionsmetadataThe same totals per conversation, with the repository each ran inon
Token costderivedPrices the tokens already collected. No device reports a coston
Session titlescontentThe model's one-line description of each conversationoff
Session messagescontentWhat people typed and the replies. Bounded: forty messages a sessionoff
how it connects to Surfaces and Monitoring

Governance completes Surfaces and Monitoring.

Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.

01 · surfaces

Surfaces

What is on this machine?

One row per device. Finds the AI tools, agents, models and keys on each one.

Read about Surfaces →
02 · monitoring

Monitoring

What is out there, across all of them?

One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.

Read about Monitoring →
03 · governance

Governance

What should be allowed?

The rules every device is graded against, with a version on every decision.

One machineSurfaces finds Codex CLI on a laptop.
The fleetMonitoring shows it on 24 devices, undecided.
A decisionGovernance publishes v14: Codex CLI disallowed.
The regrade24 devices fail on their next report. Events lists them.
The proofHistory has v14, who and when. The pack cites it.
common questions

Common questions.

the words on this pagethe same list the page's structured data carries
AI governance
The rules, records and evidence a company keeps about the AI it uses.
AI policy
A rule an organisation defines centrally about which AI tools may run, what they may do and what they may reach. In endlayer every policy is versioned and graded against devices.
Shadow AI
AI tools people install and use for work without anyone approving them. The AI case of shadow IT.
AI agent
Software that can take actions on its own to reach a goal. A coding agent that edits files and runs commands without a person approving each step is the case endlayer governs.
Model Context Protocol (MCP)
An open standard for connecting AI assistants to tools and data. An MCP server declared on a device can carry a credential to a system outside the company.
Data loss prevention (DLP)
Controls that detect and stop sensitive data leaving. endlayer's sensitive-data rule runs inside the coding agent before a prompt is sent.
SOC 2
An assurance report on a service organisation's controls, against the AICPA Trust Services Criteria.
EU AI Act
Regulation (EU) 2024/1689, the European Union's law on artificial intelligence, including duties on organisations deploying AI.
ISO/IEC 42001
The international standard for an AI management system.
NIST AI RMF
The US NIST AI Risk Management Framework: govern, map, measure, manage. Voluntary.
GDPR
Regulation (EU) 2016/679, the European Union's data protection law.
Audit evidence
The retained record an auditor can check a claim against. In endlayer: versions, verdicts, access logs and a nightly export.
What is endlayer Governance?

It is the endlayer module where you set the rules for AI on your devices. It holds the rules your fleet is graded against and publishes every change as a version. Devices are regraded on their next report, removals wait for an administrator, and History keeps the record.

Can we write our own rules?

You turn on, configure and package the nineteen that ship. You cannot invent a rule kind, because each needs a collector in the agent and a grader in the backend. A rule without a measurement would be a checkbox.

If we adopt the SOC 2 package, are we SOC 2 compliant?

No, and the product will not say you are. A package is a named selection of rules mapped to a reading of the framework. The figure is always rules in force, never compliance.

What is the difference between disallowed and blocked?

A disallowed tool fails its check and stays installed. A blocked app fails and raises a removal request. Nothing is removed until an administrator approves it.

Does the Guardian plugin read our developers' prompts?

It scores them inside the agent host, against the thresholds you published. What comes back is the vertical, the action and the score. Never the text.

What happens to a device that could not be checked?

It is unknown. Unknown is drawn as its own segment and kept out of the pass rate. A control that could not be evaluated has not passed.

Does endlayer help with EU AI Act, ISO/IEC 42001, NIST AI RMF or SOC 2 compliance?

It gives you the device-side evidence those frameworks ask for: which AI tools run, what agents may do, what left in a prompt, and who decided what, with a version on each decision. Packages map rules to the framework clauses. The product reports rules in force and leaves the compliance judgement to you and your auditor.

Can it block AI tools on employee laptops?

Yes, in two ways. Real-time guardrails inside the agent act on the device as it happens: a prompt is scored before it runs, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app waits for a person: the Blocked apps rule raises a removal request, and the uninstall happens only after an administrator approves it. Disallowed is the softer option: the tool fails its check and stays installed. Every rule is graded on every device within fifteen minutes of publishing.

Does it block violations automatically, in real time?

The guardrails do. They run inside the agent on the device, so a blocked prompt or a redacted secret happens at the moment it would have left the machine, and the matched text never leaves it. Grading runs on every report: a device is checked against your policy version, a failure gets an owner, a state and a date it closed, and the evidence is kept and exported. The one action that is never automatic is uninstalling an app. That waits for an administrator. Cloud connectors and SDK ingestion are the planned layers, and the same rules and the same enforcement apply to them the day they ship.

Who can change the policy, and can we tell who did?

Publishing is a capability you grant. Every publish is a new version with a name and a time on it, and a stale editor is refused with both version numbers named. Nothing is ever edited in place.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow