Institution route · AI and agent governance (KYA)
Know your agents before they become operational risk.
Agentic AI is becoming infrastructure faster than governance can describe it. Institutions need mandates, refusal gates, evidence trails and release discipline – not another prompt library.
Founder-direct intake · NDA before data · review-grade evidence
The agent should never be the source of the number. SAA separates deterministic compute from agentic narrative. ARIN governs agent deliberation, KOKON governs action discipline, and the audit trail records what the agent was allowed to do, what it refused and who approved the exception.
Four governance failures agentic AI makes visible.
This page is for enterprise AI, model-risk, platform and control teams that must make agents inspectable.
Mandates drift.
Pain. An agent built for summarization quietly becomes a decision participant.
SAA. Mandate registry and scope controls under KYA discipline.
Refusal is not documented.
Pain. A policy that refuses in principle but not in code will fail under audit.
SAA. Hard refusal gates and visible fail-closed states.
Learning becomes mutation.
Pain. Runtime weight or prompt changes can invalidate yesterday’s evidence.
SAA. Release-managed recalibration only, with version and chain hash.
AI gets blamed for numbers.
Pain. If AI touches risk metrics, the model-risk conversation changes completely.
SAA. Zero percent AI in governed risk numbers. AI writes narrative only and can be switched off
Four workflows for KYA and agent oversight.
Treat agents as governed operational actors with mandates, boundaries and evidence trails.
Agent mandate registry
Who the agent is, what it may do, what it may not do and who owns it.
Refusal and escalation gates
P0/P1/P2 refusal, human-in-the-loop and Governor-visible exceptions.
Release-managed learning
Corrections feed versioned releases, not silent runtime mutation.
Audit ledger
Every output carries sources, model version, decision path and cannot-claim boundary.
We examine agents the way auditors examine companies.
23 sealed synthetic cases. Every exam plants ground truth, sets traps that must NOT fire, and poisons data that must be refused – then seals the verdict with a hash.
11 full agentic case exams + 12 micro-fixtures: AML structuring, mimicry, threshold probing, swarm, runaway loops, model concentration.
Example exam (consolidation audit): 7/7 planted mechanics recalled · 3/3 false-positive traps refused · 3/3 ambiguous cases held INDETERMINATE, not guessed.
Every run lands with a sealed hash and a WORM-anchored decision tape. Negative control: on a human-only baseline the detectors fire nothing.
SYNTHETIC VALIDATION SUITE · sealed fixtures · no real entities. Full cockpits and scorecards are demonstrated live and released under NDA.
SIX AGENTIC FAILURE MODES WE TEST FOR
The public page names the threat vocabulary and verdict shapes. Full fixture narratives, amounts and cockpits stay inside the NDA review path.
10,000 micro-operations that single-instrument rules miss; caught by mandate-aggregate view.
agent traffic labeled human, exposed by calendar/timezone inconsistency.
monotone A/B climbs testing control perimeters.
one user, 50 agents, 200 instruments; distributed structuring aggregated by mandate.
agent-to-agent cycles burning spend with no human in path.
85% of operations on one model hash: a single point of correlated failure.
Each mode has a sealed fixture, a must-not-fire twin and an INDETERMINATE trap.
Founder-direct intake
Bring one agent workflow.
We map mandates, refusal gates, owner, release policy and audit trail before production use.
