Find the execution paths
Correlate workloads, agents, tools and runtime evidence. Identify the boundary that controls each consequential operation.
Discovery model →Put action policy before tool execution, verify that protection is attached, and retain the evidence needed to understand what happened next.
See the five control points in an agent workflow →
Six steps connect pre-execution policy with runtime attachment and outcome evidence. Each step answers a different assurance question.
Correlate workloads, agents, tools and runtime evidence. Identify the boundary that controls each consequential operation.
Discovery model →Signed startup manifests and fresh hook heartbeats compare declared and observed protection points, exposing gaps.
Runtime coverage →A short-lived, single-use Action Passport binds actor, purpose, action, arguments, destination, delegation, policy version and trust epoch.
Action protocol →The supported gateway or executor checks expiry, replay, delegation and destination before permitting the business side effect.
Receiving boundary →Move from an immutable tenant draft through bounded impact projection, a deterministic canary and explicit promotion.
Policy releases →Keep SDK-reported, gateway-observed and optional destination-attested outcomes distinct and machine-verifiable.
Outcome evidence →Correlate application decisions, workload observations and governed network activity into a tenant-scoped view. Keep the source of each observation visible.
SDKs and platform integrations provide actor, purpose, tool, action, destination and policy context at connected execution boundaries.
eBPF-powered discovery provides bounded process and connection evidence across selected Linux workloads, including activity outside known application hooks.
Envoy authorization provides destination and enforcement evidence for traffic routed through the configured egress boundary.
Correlation distinguishes application-protected execution, gateway verification, suspected bypass and activity requiring investigation. A network connection alone does not establish the agent’s intent or the business outcome.
Read the Runtime Intelligence Grid research →Connect workloads to the tenant’s assigned runtime in an available published region. Keep regional access and runtime endpoints aligned with the tenant configuration.
View published regions →A dedicated runtime supports customer-specific isolation, capacity and availability requirements under contract.
A contracted runtime can sit within an approved customer VPC, cloud or on-premises boundary, with agreed operational responsibilities and connectivity.
Existing customers should use their assigned region. Log in or find your regional entry point. New customers can get started through the existing registration flow.
Identify the final executor, connect its supported hook or gateway, and test allowed, blocked, sanitised and unavailable paths. Compare expected protection points with fresh runtime evidence. Record paths that remain outside the boundary.
Define timeout, retry and failure behaviour at the integration boundary. Test that consequential actions do not continue without the required decision, and document any intentionally permitted exceptions.
Validate latency with the customer’s workload, deployment region, network and evidence requirements. Deterministic policy paths and local gateway authorization options inform the deployment design; a generic marketing number cannot establish the result for a particular workload.
Record the approved data fields, storage location, retention and support-access model. Runtime Grid’s default evidence uses structured workload, destination and authorization metadata. Content-aware application inspection is a separate deployment choice.
A distinct billable action identifier recorded at an enforcement point is one verified action. Duplicate telemetry with the same identifier is de-duplicated. See the pricing example.
Try a local scenario, then bring your workflow to a deployment review. Start with one agent and one tool, and see exactly where the action can be stopped.