BII | Business Intelligence & Insights

Agents that stay governed, wherever they run.

Build the control plane once, and every agent is governed the same way, whichever platform it runs on, whichever cloud it lives in. Nothing is retrofitted later, and nothing is locked to one vendor's roadmap.

The problem

Two questions, not one.

"How do I run agents inside this one system?" and "how do I govern every agent my company runs, on every cloud, indefinitely?" get asked as if they're the same question. They aren't. An agent platform built into a CRM or a ticketing suite answers the first one well. It was never designed to answer the second, because answering it would mean governing agents that live outside that vendor's own suite, which isn't in that vendor's interest.

So we build the second one as its own layer: a control plane that sits beside whatever platforms you already use, governs agents built anywhere, and doesn't care which model or vendor is underneath.

Architecture

The architecture, four planes.

Read top to bottom: where agents actually run, the layer we build to govern them, the systems they read from and write to, and the cloud account underneath all of it, yours, not ours.

Four-plane agent architecture Agent plane at top, showing where agents run. Below it, the control plane we build, split into a build-and-govern layer and a test-and-certify layer. Below that, the data and workflow plane of systems of record. At the bottom, your own cloud account. Agent plane: where agents actually run Agents we build for you on our orchestration layer Your in-house agents custom-built, internal Third-party agents SaaS copilots, MCP tools Native platform agents e.g. ServiceNow, Agentforce Control plane: the layer we build, deployed inside your own cloud Build & govern Orchestration: one framework, any cloud Governance & guardrails (PII/PHI) Model gateway: route, swap, cost Tool & connector layer, scoped Model hosting: region-pinned, VPC-private Test & certify Observability & audit Evaluation & drift detection Certification & evidence SOC 2 · ISO 42001 · NIST AI RMF Data & workflow plane: systems agents read from and write to ServiceNow records & workflows Salesforce CRM system of record Databases & APIs internal systems Other SaaS systems M365, data platforms, etc. Your cloud: AWS or Azure Region-pinned, VPC-private, your keys, your data, your audit trail: the whole control plane runs here Foundation models Secrets / KMS / IAM

Four planes, top to bottom. The control plane in the middle is the seam everything passes through.

An agent doesn't have to live only behind an API. We build them as Slack and Microsoft Teams bots, as desktop copilots the way Claude Desktop works, as browser-based assistants, and as chat interfaces embedded directly in your own product.

Wherever the agent shows up, it still calls through the same gateway underneath and gets governed the same way.

Seven layers

What the control plane actually does.

Seven layers, in the order we build them. The first five are the build-and-govern side; the last two are the test-and-certify side that keeps checking after launch, not just at it.

  • BUILD & GOVERN

    Model hosting

    Foundation models run inside your own cloud account, region-pinned, with private network endpoints. Data sovereignty and a no-training guarantee start here, not later.

  • BUILD & GOVERN

    Model gateway

    Every agent calls one internal endpoint, never a provider directly. It owns routing, model swapping without application changes, per-team credentials and quotas, and cost attribution by team.

  • BUILD & GOVERN

    Governance & guardrails

    PII and PHI detection and redaction, content and safety guardrails, and tenant isolation, enforced once in the gateway path rather than rebuilt by every team that stands up an agent.

  • BUILD & GOVERN

    Orchestration

    One framework, wrapped so auth, logging, and guardrails come built in by default, whatever the agent on top of it is actually trying to do.

  • BUILD & GOVERN

    Tool & integration

    Scoped, audited access to exactly the data and systems an agent needs, and nothing else. This is where an agent could do real damage, so permissions stay tight by default.

  • TEST & CERTIFY

    Observability & audit

    Immutable, queryable capture of every prompt, response, tool call, and model version, across every agent in the organisation, not per application.

  • TEST & CERTIFY

    Evaluation & certification

    Every agent tested against policy before it runs, and continuously re-tested after, with an audit trail that maps to SOC 2, ISO 42001, and NIST AI RMF.

SOC 2 ISO 42001 NIST AI RMF

Want to see how this fits your own systems, and which of the two ways of working with us makes sense?

Talk to us