Skip to main content
Adomo
AI agent governanceAgentic AI risk managementAI agent access control

Set the rules. Enforce them before it runs.

Adomo checks every workflow against your authority rules before execution. Consequential steps wait for a named human, and every action, approval and refused request goes into one audit trail.Adomo checks every workflow against your authority rules before it executes. Spend limits and approval gates stop an agent from moving money without permission, and every decision is logged.Agent access follows the roles you manage in your identity provider. Adomo enforces tenant isolation at the data layer and logs both permitted and refused requests.

Policy checked pre-execution Approvals routed to a human Immutable, exportable audit trail SOC 2 Type II in progress
The control model

Four controls outside the model.

Adomo checks the proposed plan against your policy before execution. The model cannot override that check or grant itself permission to act.

authority-policy.md
Spend > $50k → VP approval
Vendor not on allowlist
PO required on all orders
Blocked pre-flight

Check the plan against your rules

Your authority rules live in a document you write in plain English: spend limits, approval thresholds, department scopes, who-can-do-what. Adomo validates the whole workflow against them before the first step runs. A plan that breaks a rule is blocked.

Payment
$120,000
Mgr
VP
CFO
Routes by amount · escalates on timeout

Approvals go to a person, by name

Consequential steps stop and route by amount, role or department, with a notification in Slack or email. If the approver does not answer, it escalates. If they are away, it delegates. The work waits for approval.

AI Proposes the plan
You Approve / reject
Engine Executes, exactly once

Keep permissions outside the model

The model proposes a plan. Adomo checks it against policy, routes any required approvals to a human, and executes the approved steps. The model cannot grant itself permission.

09:42:07 Payment executed · $48,200
09:41:55 CFO approved
09:41:02 Policy validated · passed
Tamper-evident Export → SIEM

Keep a record of every decision

Every decision, action and input goes into an immutable audit trail you can export.

How a policy is written

If you can write the rule down, you can enforce it.

An agent that raises a bad purchase order can spend your money before anyone reviews its output. Adomo checks the proposed workflow against your authority rules before it acts.

Those rules may already be in a finance SOP, a delegation-of-authority matrix or a procurement policy. Some may only be in the head of the person who has signed things off for six years. Write those down too.

Upload the policy as you already wrote it. Adomo checks each workflow against that document before execution. When the policy changes, edit the document; you do not need to retrain a model or file an engineering ticket.

If a workflow reaches a step the policy does not cover, Adomo stops and asks a person to decide.

Controls and records

What gets enforced, and what gets recorded.

Policy in plain English

Your SOPs, spend limits and thresholds, as written

Policy checks before execution

Every workflow validated before it executes

Approval routing

By amount, role or department

Escalation and delegation

On timeout, and when an approver is away

AI agent observability

Logs, traces and metrics, streamed to your SIEM

Evidence for your auditor

Every decision, action and input, in order

Compliance status
SOC 2 Type II In progress ISO 27001 Architected for HIPAA controls Architected for

We will walk your security team through the controls, the architecture and the roadmap under NDA.

How the approaches differ

Compare how each approach enforces your rules.

How the approaches differ
Capability Adomo Guardrail libraries LLM gateways Policy in the prompt
Policy checked before the action runs After the fact Rate limits only
Enforcement sits outside the model
Rules written in plain English
Consequential steps routed to a named human
Escalation on timeout, delegation on absence
Immutable audit trail of every action Partial Request logs only
Applies across your connected systems
Survives a crash and resumes mid-process
What you can check

Controls your risk team can inspect.

We do not have customer logos to publish yet. Your team can inspect the controls below and review a deployment that keeps your data where your policy requires.

SSO / SAML

Okta, Azure AD, Ping

Your VPC or on-prem

Air-gapped tier available

Immutable audit log

Exportable to your SIEM

Vault-backed secrets

You keep the keys

How a governance review runs

Test the controls against your own policy.

Bring one policy and one process. We will run through permitted and prohibited actions together so your team can check the results.

01

Bring the policy you already have

Bring your delegation-of-authority matrix, finance SOP or procurement thresholds in their current form.

02

Encode it and try to break it

We load it, then run workflows designed to violate it. You watch what gets stopped, and read the reason it was stopped.

03

Run one real process

A single high-value workflow in your own environment, with approvals routed to the people who really sign off today.

04

Take the evidence away

Export the audit trail for the people responsible for signing off on the deployment.

What risk teams ask us first.

Is the guardrail the model, or something outside it?
The check runs outside the model. Deterministic code validates the proposed workflow against your policy before execution. The model proposes the plan but cannot override the result.
What happens when an agent hits something the policy does not cover?
It pauses the unresolved step and asks a human to decide.
Can an agent widen its own permissions?
No. Access follows the roles you already manage in your identity provider, through SSO and SAML with role-based access control, and tenant isolation is enforced at the data layer. Secrets live in your own HashiCorp Vault, so the credentials a workflow can reach are the ones you granted it and no others. Nothing inside a run can widen that, and an attempt to reach something out of scope is logged like any other action.
Who gets asked for approval, and what if they are away?
Routing is by amount, role or department, so a $500 step and a $500,000 step do not go to the same person. Notifications land in Slack or email. If nobody responds the request escalates, and delegation covers a named absence. The work waits until somebody with the authority answers.
What exactly is in the audit trail?
Every decision, action and input appears in order in an immutable, exportable record. It includes blocked steps and the reasons they were blocked. On the Enterprise tier, you can stream it to your SIEM and send logs, traces and metrics to Grafana or Prometheus.
Does Adomo map to the NIST AI RMF or the EU AI Act?
We do not publish a formal control mapping to either. We can review our controls, architecture and roadmap with your team under NDA so your compliance lead can map them against the framework you use.
What is your certification status?
SOC 2 Type II is in progress and not yet certified. The platform is architected against ISO 27001 and HIPAA controls. Adomo is early and founder-led, with design partners in finance and healthcare whose data cannot sit in someone else's cloud. If procurement requires a current SOC 2 report, we cannot meet that requirement today.

Bring one policy. See what it stops.

Book a working session with our team. We will encode a rule you already have and run workflows against it, including the ones that should fail.

Book a security review
Policy checked before execution
Runs in your cloud or ours
Every action logged

Get in touch

Reach our team. We'll respond within 24 hours.

All fields are required.

Call us

Available during business hours

+1 (866) 995-4498

Monday – Friday, 9 AM – 6 PM PST