One control plane for AI agents: discover, govern, secure, assure and prove.
Every capability Praesidia ships, on one page. Find the agents and MCP servers you run, map what each AI system is built from, decide what it may do before it acts, test it before release, and hand an auditor proof they can check themselves.
Unmarked capabilities are in every plan, including the free Developer plan. Individual Advanced Enterprise mark the plan a capability starts on; see pricing.
Know what is running and what it can reach
Start with an inventory you can trust, built from the traffic that reaches Praesidia and the sources you connect.
-
Agent discovery
An inventory of the agents that reach Praesidia, plus the agents, MCP servers, tools and prompts defined in the GitHub and GitLab repositories you connect.
-
MCP inventory
The MCP servers registered with Praesidia, and the tools each one exposes, each server with its own identity.
-
MCP and skill scans
Scan an MCP server or skill manifest before you adopt it, against the permission policy you set for that server or for the whole organization.
-
AI intake
Teams submit a new AI system for review, and reviewers work through a queue before it is registered.
-
Data assets and data flow
Register the data your AI systems touch, trace each system's data flow down to classified data, and record a cross-border verdict for every flow.
Know what each AI system is made of, what it puts at risk and who owns it
An agent is a model, prompts, tools, data and permissions. Keep each AI system on record with its owner: the parts and how they connect, the risks it carries and the controls that hold them, the access it holds against the access it uses, and what it costs.
-
AI System Graph
What each AI system is built from, how its parts connect, and what is exposed when one part fails.
-
AI bill of materials
A signed, versioned list of every model, prompt, tool, data source and policy an AI system uses, compared release to release and exported as CycloneDX.
-
Risk register
The risks you carry per AI system, the controls that hold each one down, and when each is due for another look.
-
Least privilege
Compare the permissions each agent holds with the ones it actually uses, and turn the difference into a proposal to reduce them.
-
Cost and business value
Model spend attributed per agent, set next to the business KPIs you record for each AI system.
Decide what each agent may do, before it acts
Every call an agent makes through Praesidia is checked against who it is and what it is allowed to do, then allowed, denied or sent to a person.
-
Runtime policy and identity
Each agent gets its own identity, and each tool call is decided against the rules for that identity before it runs.
-
Guardrails
24 ready-made guardrail templates, or your own rules, on what goes into and comes out of an agent.
-
Agent policies
Rate limits and spend caps for a group of agents, rolled out in stages like every other rule.
Individual -
MCP tool permissions
Decide which MCP tools each connection may call, and keep tamper-evident evidence of every call.
-
Model gateway and routing
One gateway to six model providers, with the health of each provider in view. Separately, routing policies pick among the model configurations you give an agent, by data classification, residency and cost.
-
Staged rollout and policy replay
Move a rule from simulate to observe to alert to enforce, with optional automatic rollback. Replay a rule against past traffic before you turn it on.
Replay Advanced -
Sequence rules
Catch one action followed by another within a time window, such as a customer-list read followed by an external email.
Advanced -
Human approval
Send a risky tool call to a named person, who approves or refuses it before it runs.
Enterprise -
Emergency freeze
Stop agent traffic for the whole organization in one step, after previewing every AI system that will stop.
In observe mode the rule is evaluated and recorded and the call goes through unchanged; in enforce mode the same rule can deny it or send it to a person.
Test it before it ships, and keep fixing what you find
Evaluations, red-team campaigns and release gates tell you whether a release meets your bar; findings and remediation close the gap.
-
Evaluations and release gates
Test each agent release against your own cases and your own bar, and hold the release until it passes.
-
Red team
Attack campaigns against the agents, connections and MCP servers you opt in, on demand or on a schedule.
Assurance Advanced -
Decision explanations
Open any policy decision and see its outcome, the rule that matched, the data classification, the identity behind it and its EU AI Act basis.
-
Findings
Findings raised automatically across the platform, in one list a person reviews, triages and accepts.
-
Remediation planner
Proposed fixes that are simulated, tested, approved, applied and monitored, and rolled back if they cause trouble.
Show afterwards what happened, and let others check it
Evidence an auditor, regulator or buyer can verify without trusting our console.
-
Signed audit trail
Every governed decision recorded, signed and chained, and checked offline by your auditor.
-
Audit package
One export for a period: executive summary, inventory, risk register, controls, evaluations, incidents and the signed evidence bundle.
-
Trust passport
A public page, badge and PDF for the AI systems you choose to publish, and a check for the passports your vendors send you.
-
Incident response
Related signals grouped into one incident, a nine-step response, a signed evidence bundle and a regulator report.
-
Compliance mappings
Controls and evidence mapped to ISO/IEC 42001, the NIST AI RMF and the EU AI Act, with evidence coverage per framework and an ISO/IEC 42001 gap view.
Coverage and gap view Enterprise -
Reports and forensic search
A weekly executive report for organization owners, and search across audit records when you need to reconstruct what happened.
Forensic search Advanced
It fits the stack you already run
-
Integrations
Agent frameworks, model providers and MCP servers on the way in; security events to your SIEM and tickets to your ITSM on the way out.
SIEM and ITSM Advanced -
Observability
OTLP traces in; organization metrics in Prometheus format for the monitoring stack you already run.
-
Governance packs
Ready-made sets of policies and controls to start from instead of a blank page.
Docs Advanced
Put one agent under the control plane.
Create your workspace, connect one agent, and inspect the decisions it produces.