Building ConSentra — execution-scoped authorization and governance for enterprise AI agents. ConSentra — authorization for enterprise AI agents. See the architecture →
ConSentra
In active development

Your agent is authenticated. Nothing is deciding whether it should act.

ConSentra is a control point for enterprise AI agents. Every action an agent takes against a real business system stops here, gets a yes or no from your policy, and runs under a permission good for that one action only.

Permission to act Expires in 28 seconds
Agent Invoice triage agent
Acting for D. Okafor, Accounts PayableAuthority granted until 14:32 today
Approved action Post journal entry
Where Ledger / Accounts Payable / July 2026
Permitted uses OneCannot be reused, widened, or handed on
One agent, one action, one record, one use. Then it is gone.
The gap

Knowing who an agent is tells you nothing about what it should do.

Enterprises are giving AI agents real credentials and real reach into finance, HR, and cloud systems. Identity confirms the agent is who it claims to be, and then nothing decides whether it should take this particular action right now.

01

Permission that never narrows

A valid credential lets an agent reach anything it can see, until that credential expires. Nothing limits it to the one thing it was asked to do.

02

Whose authority was that?

Most deployments cannot tell the agent apart from the person it acts for. Once those become one, nobody can say whose authority was spent.

03

Logs are not evidence

Logs record that something happened. An auditor asks who approved it and under which rule. Most log trails cannot answer that.

How it works

Four checks. Any one of them can stop the call.

Agents connect to ConSentra the way they connect to any other tool, and it connects onward only to systems you have registered. Nothing is approved by default. If anything required is missing or cannot be trusted, the request is refused.

01 · Who is asking

The agent and the person are established separately

ConSentra verifies the agent, then separately establishes the person whose authority it is acting under and when that authority runs out.

Refused Unrecognized agent, unclear identity, or authority that has lapsed.
02 · Should it be allowed

Your policy answers, the same way every time

Written rules your team owns return yes, no, or send it to a human first. The AI model is not the one deciding.

Refused Policy says no, or cannot answer in time.
03 · Permission for one action

Approval covers that action and nothing else

Permission is issued for that exact action on that exact record, once. It is short-lived and can be pulled back while the work is still in flight.

Refused Permission expired, already used, altered, or presented by anyone else.
04 · Act and record

Only now does the request reach your system

The action runs, and the decision behind it is written as tamper-evident evidence, kept apart from ordinary application logging.

Refused The line from decision to action cannot be completed.
What changes

Agents you can put in front of an auditor.

A much smaller worst case

Permission is issued per action rather than per session. One that cannot be reused or widened is a far smaller exposure than a credential that works for an hour.

Decisions your team controls

Approvals come from written rules your people own and can change, so any past decision can be replayed against the version that was live at the time.

Evidence ready in advance

Every decision is captured with the rule behind it, so the answer to an audit question already exists rather than being assembled under pressure.

Scope

What it is not.

  • A prompt firewall or model safety product
  • An inventory of every AI agent in your organization
  • A secrets manager
  • A replacement for your identity provider or your policy language
One condition worth stating up front

ConSentra is only a control point if agents cannot reach protected systems some other way. A rollout pairs it with network and identity controls and retires the standing credentials your agents hold today. We treat that as part of the engagement.

Where we are

We would rather tell you this here than on a call.

A working proof of concept demonstrates authenticated agent mediation and action logging today. The rest of this page is an approved engineering plan being delivered in phases, and we are publishing it now because the problem is already live inside enterprises.

Phase 1
Foundation
Controlled access to registered systems, agent identity, and the person being acted for.
In progress
Phase 2
Enforcement
Policy decisions on every protected action, single-use permissions, fail-closed throughout.
Planned
Phase 3
Governance
Durable audit evidence, revocation and kill switch, and day-to-day administration.
Planned
Design partners

Are your agents already reaching systems that matter?

We are working with a small number of organizations running AI agents against real enterprise systems. Design partners shape the first enforced use case.