KPATH

How should you compare AI agent governance vendors?

Put the same four questions to every vendor, KPATH included: is the audit record evidence or a log, does stopping one agent stop the chain it started, does policy cover the whole delegation chain, and is each agent's identity bound to the person or system it acts for.

Ask every vendor the same four questions: evidence or logs, whole-chain containment, delegation-chain governance, and identity bound to the principal.

Why the same questions for everyone

Vendors in this category describe themselves in similar words, so a feature list rarely separates them. Four questions do. Each one tests whether a control acts at the moment an agent calls, and whether the record it leaves would stand up in front of an auditor. Put them to every vendor on your shortlist, and to KPATH.

The four questions to ask any vendor

They come from the Verify-Enforce-Stop-Prove test.

Question What a good answer looks like
Evidence or logs? The audit record is signed and tamper-evident, exported to your SIEM and write-once storage, and an auditor can verify it has not been altered without trusting the vendor’s console. A log you control is not evidence.
Whole-chain containment? Stopping one agent also stops every agent it set in motion, the chain loses the credentials it relied on, and a record shows nothing was authorised after the stop.
Delegation-chain governance? Policy, budget and approval apply to the chain that a request started, not only to the first hop. Spend and decisions roll up to the originating request.
Identity bound to the principal? Every call carries the agent’s own identity, with an owner and a risk tier, and when the agent acts for a person policy can insist the person is verified too.

How KPATH answers them

KPATH is the inline enforcement layer for enterprise AI agents. Every governed action passes through its Policy Enforcement Point before the payload reaches the target. The PEP verifies the agent’s non-human identity and the principal it acts for, then applies least-privilege policy, budgets and human approval. It can stop one agent or an entire in-flight delegation chain, and it writes every decision to a signed, tamper-evident audit log exported to your SIEM.

KPATH governs the request envelope: identity, target, action, size, delegation chain. Of the payload, it reads only the values you declare for a rule, such as a payment amount. Keys stay in your custody. Your identity provider decides. KPATH enforces.

What a comparison cannot settle

A website shows what a vendor chooses to document. It does not show what they ship under NDA, what is on their roadmap, or how their product behaves under your policy. Use the four questions to frame the conversation, then run each shortlisted product against your real estate and compare the records they produce.

Every deployment of KPATH starts in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress.

Every page in Compare

FAQ

Common questions

What are the four questions to ask any AI agent governance vendor?

Whether the audit record is evidence a third party can verify or a log the vendor controls; whether stopping one agent also stops the chain it started; whether policy applies to the delegation chain rather than only the first hop; and whether an agent's identity is bound to the human or system principal it acts for.

Does KPATH replace an API gateway or an identity provider?

No. KPATH sits in the call path the way a gateway does but checks different things: who the agent is, what it may reach across APIs, other agents and MCP servers, and what the whole chain is doing. The customer's identity provider remains the policy decision point and KPATH enforces its decisions.

Should we build our own agent gateway instead of buying one?

A gateway plus scripts is often enough for a small estate on one framework with low stakes. It stops being enough when the estate is many-to-many, multi-framework and high stakes at the same time. The build-versus-buy page sets out the conditions and the categories of cost.

Published Updated

The first step

Start in monitor mode. See everything before you enforce anything.

Deploy in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress. See the agents already running in your estate before you decide what to enforce.

Book a monitor-mode pilot See the platform