Why the same questions for everyone
Vendors in this category describe themselves in similar words, so a feature list rarely separates them. Four questions do. Each one tests whether a control acts at the moment an agent calls, and whether the record it leaves would stand up in front of an auditor. Put them to every vendor on your shortlist, and to KPATH.
The four questions to ask any vendor
They come from the Verify-Enforce-Stop-Prove test.
| Question | What a good answer looks like |
|---|---|
| Evidence or logs? | The audit record is signed and tamper-evident, exported to your SIEM and write-once storage, and an auditor can verify it has not been altered without trusting the vendor’s console. A log you control is not evidence. |
| Whole-chain containment? | Stopping one agent also stops every agent it set in motion, the chain loses the credentials it relied on, and a record shows nothing was authorised after the stop. |
| Delegation-chain governance? | Policy, budget and approval apply to the chain that a request started, not only to the first hop. Spend and decisions roll up to the originating request. |
| Identity bound to the principal? | Every call carries the agent’s own identity, with an owner and a risk tier, and when the agent acts for a person policy can insist the person is verified too. |
How KPATH answers them
KPATH is the inline enforcement layer for enterprise AI agents. Every governed action passes through its Policy Enforcement Point before the payload reaches the target. The PEP verifies the agent’s non-human identity and the principal it acts for, then applies least-privilege policy, budgets and human approval. It can stop one agent or an entire in-flight delegation chain, and it writes every decision to a signed, tamper-evident audit log exported to your SIEM.
KPATH governs the request envelope: identity, target, action, size, delegation chain. Of the payload, it reads only the values you declare for a rule, such as a payment amount. Keys stay in your custody. Your identity provider decides. KPATH enforces.
What a comparison cannot settle
A website shows what a vendor chooses to document. It does not show what they ship under NDA, what is on their roadmap, or how their product behaves under your policy. Use the four questions to frame the conversation, then run each shortlisted product against your real estate and compare the records they produce.
Every deployment of KPATH starts in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress.