KPATH

What is an AI agent control plane?

Agents are scaling into production faster than the controls to govern them. A control plane closes that gap: the layer that sees every agent, decides what each one is allowed to do, and enforces that decision on live traffic. KPATH is that control plane.

A decision is not an enforcement: a control plane sits on the path of the call and allows or refuses it in real time, so the decision has teeth because it happens before the action does.

Three questions, answered continuously

Without a control plane these answers live in scattered logs, static registers and individual tools. Under one, they are a single coherent picture that can be enforced.

What agents exist. A complete, current inventory of every agent, registered or not, built from the calls they make rather than from a register kept by hand. The control plane cannot govern what it cannot see.

What each may do. Policy tied to identity, purpose and real behaviour, so every agent has a defined boundary rather than whatever access it happened to be handed on day one.

What each actually did. A record of every call, decision and outcome, which is the difference between asserting that agents are governed and being able to show it.

A decision is not an enforcement

Many tools stop at recommendation. They flag a risky call, log it, and let it proceed. For a regulated enterprise that is commentary, not control. A control plane sits on the path of the call and allows or refuses it in real time, so the decision has teeth because it happens before the action does.

Any agent, any framework

On one side, the agents: personal assistants, LangChain and CrewAI, Claude and OpenAI agents, MCP servers and tools. On the other, the governed services: internal service agents, enterprise APIs, MCP tool servers and external SaaS, proxied.

Between them sits KPATH’s policy enforcement point, carrying identity, kill switch, cost, policy, approval and guardrails, and writing a tamper-evident audit to your SIEM.

One path between every agent and every system it can touch. Agents carry no system addresses and no credentials, so every call is identified, checked against policy and recorded, whatever framework the agent runs on.

Discover, identify, govern, contain, prove

KPATH structures agent governance as five capabilities. Discovery gives you the map, enforcement gives the map consequences, and proof turns the whole thing into something you can defend.

  1. Discover. Build a complete inventory by watching real calls, including agents nobody registered. Everything downstream depends on having the full map first.
  2. Identify. Attach identity and ownership to every agent, so each call has an accountable source rather than an anonymous credential.
  3. Govern. Set what each agent is allowed to reach and do, with policy grounded in observed behaviour rather than in assumptions about how an agent should act.
  4. Contain. Enforce those decisions on live traffic. Calls are allowed or refused at the point they are made, so risk is bounded rather than merely noted after the fact.
  5. Prove. Produce the evidence that shows what ran, what was allowed, what was refused and why, in a form a supervisor or auditor can accept.

One layer, four concerns that would otherwise be four programmes

Cost. Agent calls translate directly into spend. Seeing and governing them keeps costs from climbing without anyone deciding they should.

Governance. Policy applies consistently across every agent and framework, rather than being reinvented team by team with different limits each time.

Security. Over credentialled and unrecognised agents are contained at the point of the call, so the blast radius of any one of them stays bounded.

Observability. Every action is visible and recorded, so the questions that follow an incident or an audit have answers rather than gaps.

It works with the stack you already run

A control plane should not force a rebuild. Keep your identity provider, your guardrails engine, your agent platform and your existing APIs. KPATH observes both ends of every call across all of them and enforces policy in the path. It starts in monitor mode, so you see the full picture and what policy would do before anything is refused.

Related: AI agent discovery, or what the EU AI Act asks of agent estates.

Agents are already doing business. Govern it, and prove it.

Begin in monitor mode. Every call is permitted while you watch what the policy would decide.

FAQ

Common questions

What is an AI agent control plane?

It is the layer that governs AI agents in production. It maintains a complete inventory of agents, decides what each is allowed to do, enforces that decision on live calls and records the outcome as evidence. Borrowing the term from networking, the control plane decides what is allowed to happen while the data plane carries it out.

How is a control plane different from monitoring or observability?

Monitoring tells you what happened. A control plane also decides what is allowed and enforces it in real time. A decision is not an enforcement, and KPATH enforces at the point of the call rather than reporting on it afterwards.

Does KPATH replace our identity provider or agent platform?

No. KPATH works alongside your identity provider, guardrails engine, agent platform and existing APIs, and adds the control layer across them. Agents keep their own frameworks and payloads; teams point their outbound calls at one governed path instead of reaching services directly.

Will it block agents as soon as we turn it on?

No. KPATH starts in monitor mode, building the inventory and showing what policy would do before it enforces anything. You see the full picture, and choose when to move from watching to enforcing.

How does the control plane actually enforce a decision?

It sits on the path between agents and the services they reach, and allows or refuses each call according to policy, so a governance decision takes effect before the action happens rather than being logged after it.

Who is KPATH for?

Regulated enterprises that need to govern AI agents and prove that governance, with a particular focus on banking, financial services and insurance, where an agent that moves data or takes an action is held to the same standard as any other system that does.

Published Updated

The first step

Start in monitor mode. See everything before you enforce anything.

Deploy in monitor mode: observe only, enforce no policy, rewrite no agents. Flip to enforce by repointing egress. See the agents already running in your estate before you decide what to enforce.

Book a monitor-mode pilot See the platform