Governed agentic AI

The operating system for governed AI agents.

Build, govern, observe, and distribute AI agents across regulated enterprises — with 21,500+ governed skills and agents ready to install, every run gated, every decision provable.

Aligned with EU AI Act · NIST AI RMF · ISO 42001

Control Tower
pause all disable tool export report kill switch armed
Fraud Triage$0.018 · 1.2sExecuted
Payout Approver$0.041 · pendingHold
Return Reviewer$0.009 · 0.8sExecuted
KYC Screenermodel not allowedBlocked
trust-ledger ▸ 1,284,902 actions recorded today

Trusted by teams in financial services, healthcare, and the public sector

The library

21,500+ governed skills & agents.

24 industries. 12 roles per industry. 18 agent patterns. Every item installs from the catalog, wires to your systems, and runs through the same fail-closed gates as everything else on Cortex — 21,511 items today, counted live from the catalog.

The problem

Shadow agents are a governance time bomb.

Teams are scaling AI past pilots with no audit trail, no policy gate, and no kill switch — exactly the exposure EU AI Act and NIST AI RMF were written for. Cortex puts every agent under one governed runtime.

Ungoverned sprawl
? unknown agents
no identity · no audit · no caps
Governed runtime
Fraud Triage200 OK · ledgerPayout ApproverHOLD · ledgerKYC Screener403 · ledgerReturn Reviewer200 OK · ledger
identity → gates → ledger
One runtime, four jobs

Everything between the prompt and production.

Build

Author governed agents in plain English or code — skills, knowledge, guardrails, and a no-code studio with 11 role packs.

Govern

Every run passes the same gates: identity, budget, guardrails, registry, control-tower, policy, oversight, audit. Fail-closed by design.

Observe

Monitor, score, evaluate, simulate, and debug every run — with reliability gates and a tamper-evident trust ledger underneath.

Distribute

Ship a governed solution once and deploy anywhere as signed, verifiable Solution Packs — across tenants and air-gapped environments.

The platform, end to end

Every control between prompt and production.

40+ governed capabilities across one runtime — the full operating system for enterprise AI, not a scattering of point tools.

Build
  • No-code Agent Studio
  • Behavior & guardrails
  • Knowledge & RAG
  • Agent marketplace
Govern
  • Policy-as-Code
  • Action Fabric
  • Agent IAM
  • Oversight modes
  • Risk register
  • MCP gateway
Automate
  • Workflows
  • Automations (ECA)
  • Channel intake
  • Batch runner
  • Real-time hub
  • Schedules & queue
Observe
  • Monitoring
  • AI insights
  • Evaluation
  • Simulation lab
  • Reliability score
  • Agent debugger
Data & Ontology
  • Business ontology
  • Object & property permissions
  • Asset catalog
  • Lineage & provenance
Cost & Value
  • Cost governance & caps
  • Adoption & ROI
  • Business value
  • Model ops & compute broker
Distribute
  • Solution studio
  • Signed Solution Packs
  • Pack registry
  • Certification
How it works

Follow one run from author to proof.

Scroll the lifecycle: the visual on the right tracks each step a governed run actually takes.

studio ▸ build → publish

Author

Build an agent with skills, knowledge, and plain-English guardrails — or install one of 21,000+ skills and agents from the library. Publishing requires a passing reliability score.

8 gates · deny is the default

Every run hits the gates

Identity → budget → guardrails → registry → control tower → policy → execute → audit. Over budget returns a 402, out of policy a 403, conflicts a 409 — before anything touches your systems.

HOLD · human approval

High-risk actions pend

Payouts, refunds, POs, access grants — anything crossing your thresholds stops on an approval board with full context. The agent proposes; your people dispose.

hashOk: true

Every outcome is provable

Executed, held, or blocked — the run seals into a tamper-evident, hash-chained ledger with 10-hop provenance. Replay it, hand it to an auditor, verify it offline.

Agent Studio
skills
Search KBCreate ticketSend email add
Publishedv4 · reliability 96
Where is order #4471?
Shipped, arriving Thursday.tools: Search KB · $0.004
studio ▸ build → publish → chat-test
01Identitydeny 40302Budgetdeny 40203Guardrailsdeny 45104Registrydeny 40405Control Towerdeny 40906Executepass07Output guarddeny 45108Auditpass
Action Fabric
Dry-run
Refund $240
risk: low · evidence
Proposed
Close case #4471
risk: med · evidence
Pending approval
Payout $5,000
risk: high · evidence
Executed
Email customer
risk: low · evidence
actions ▸ dry-run → propose → approve → execute → compensate
audit/verify
#101hash ✓#102hash ✓#103hash ✓#104hash ✓#105hash ✓
head 0x9f3a…c1ok: true
verifyChain ▸ chained SHA-256 · signed receipts
97%Tax pack accuracy SLA (published target)
95%Citation-coverage SLA on grounded answers
10-hopProvenance on every outcome
100Live-verified run quality score
Prove it — don't just claim it

Every number traces to its source, in a ledger you can hand an auditor.

Cortex records every run in a tamper-evident, hash-chained Trust Ledger — with signed receipts you can verify offline and a 10-hop provenance graph from human to outcome.

  • Tamper-evident, hash-chained audit (verifyChain detects any edit)
  • Signed outcome receipts, verifiable offline
  • Datapoint provenance: every fact links to its source filing, page, and box
audit/verify
#101hash ✓#102hash ✓#103hash ✓#104hash ✓#105hash ✓
head 0x9f3a…c1ok: true
verifyChain ▸ chained SHA-256 · signed receipts
Solution Packs

One certified pack shipping — two reference blueprints.

Versioned bundles of ontology, policies, actions and agents — install into your tenant, verified by hash and signature. The Tax pack ships signed today; Claims and KYC/AML are reference blueprints on the roadmap.

US Individual Tax
2025 · signed
  • Ontology types4
  • Policies6
  • Actions4
  • Agents4
CertifiedInstall
Insurance Claims
Reference blueprint
  • Ontology types3
  • Policies5
  • Actions4
  • Agents3
BlueprintInstall
KYC / AML Review
Reference blueprint
  • Ontology types2
  • Policies7
  • Actions3
  • Agents3
BlueprintInstall
Security & compliance

Built for the enterprise security review.

Fail-closed gates, RBAC, DLP, agent detection & response, and multi-tenant isolation — mapped to the frameworks your auditors already use.

SOC 2ISO 27001ISO 42001HIPAAGDPREU AI ActNIST AI RMFFINRA
Cortex is the first thing that let us put agents in front of regulated work. Every decision has a receipt, and I can pause the whole fleet from one screen.
Head of AI GovernanceGlobal financial-services firm

Run agents. Keep control.

Put your AI agents under air-traffic control — governed, observable, and provable from day one.