Scale cyber and risk operations with trusted AI agents.
Agent Factory helps cyber and GRC teams turn established procedures into governed, production-ready workflows. Compose pre-tested harnesses, connect enterprise systems and deploy within your cloud environment, accelerating outcomes while keeping data and controls in your tenancy.
An AI agent has completed a control test.
Every step it took is already on the record, available for review.
Autonomy without inspection is unmanaged risk. Agent Factory is built to be inspected, layer by layer.
01 / 08Who designs the workflows?Your teams describe the process. The factory assembles it.
Analysts can combine approved components on a visual canvas or describe the required process in plain language. Each draft passes the same validation controls used for deployment, supporting consistent adoption without unmanaged development.
02 / 08How does a workflow reach production?Every stage must present its own evidence.
Design, benchmark, deployment and monitoring are supported by stage-specific records, and the registry maintains a live inventory of agents, models and tools. Progress is evidenced explicitly, helping teams assess readiness rather than rely on assumptions.
03 / 08What did the agent actually do?Each action writes its own audit record.
Execution journals record what ran, which information was accessed and what changed, together with the supporting evidence for each step, supporting forensic reconstruction of any run.
04 / 08How do people stay in control?Approval before. Intervention during. Cost visibility throughout.
Higher-risk actions pause at defined decision points for authorized review, recording the decision and rationale. Runs can be stopped when required, with the intervention retained in the journal. Oversight is enforced at runtime, not reconstructed after the fact.
05 / 08What can an agent reach?Access is granted per node, never assumed.
Least-privilege access is configured at each workflow node. Untrusted content is identified at entry and prevented from reaching restricted actions without the required controls.
06 / 08What about external agents?External agents work under the same controls, without exception.
Partner agents connect through A2A, are identified through their agent card and are subject to the same journal and trust controls. Responses remain marked as untrusted until validated.
07 / 08Where does the reasoning run?Each task runs on the model environment its sensitivity requires.
Each node defines its model requirements and the router determines where execution occurs. Sensitive tasks can be directed to locally hosted models to support privacy, policy and cost requirements.
08 / 08What does it all stand on?Governance is the foundation, not a feature.
Identity, policy and audit controls underpin the platform, supported by credential management, prompt-injection filtering and a runtime designed for deployment within your tenancy.
One architecture, fully accountable.
Each layer contributes the evidence, oversight and operational controls required for enterprise use.
Designed to be inspected.
Deployed in your tenancy. Prepared for audit.
Turn documented procedures into governed, auditable workflows.
Explore the product through a representative DLP workflow. Define the process in plain language or configure it visually, monitor execution and review the resulting evidence, decisions and source citations.
typing…Build on capabilities designed for control and consistency.
Each harness is a containerized capability with a defined contract covering inputs, outputs, permitted tools and exception handling. Every harness includes an evaluation suite to support validation before deployment.
Teams can configure and combine measured components without developing and maintaining bespoke agent infrastructure.
| Harness | Kind | Returns | Pass rate |
|---|---|---|---|
| Evidence extraction | extraction | Typed record + per-field citation | 96.4% |
| Control research | research | Findings with source and recency | 91.0% |
| Policy decision | decision | Disposition + governing clause | 94.1% |
| Report drafting | drafting | Draft + change log | 89.3% |
| Assessment review | review | Findings with severity | 98.6% |
| Control mapping | decision | Framework crosswalk + rationale | 92.8% |
| Vendor triage | research | Risk summary + evidence links | 93.5% |
| Access certification | review | Entitlement findings + owner | 95.2% |
| Incident summary | drafting | Timeline + affected assets | 90.7% |
| Data classification | extraction | Label + matched policy terms | 94.9% |
| Human approval | gate | Approval + reviewer identity | n/a |
Typed inputs and outputs, an explicit tool allowlist and defined exception paths. Nothing outside the contract is reachable at runtime.
Every harness ships with its own evaluation suite. Releases that fall below the accepted pass rate do not reach production.
Behaviour changes ship as new versions with a changelog. Rollback to any prior version is a single action.
Connect across your existing technology environment.
MCP-compatible connectors give each harness governed access through declared tool contracts. Use the growing connector library or extend the platform for organization-specific systems and APIs.
134 of 134Deploy in your cloud and operate within your controls.
Terraform modules support deployment to AWS, Azure and Google Cloud. Harnesses run as containers within your account and connect to model providers through your approved endpoints. Operational data remains within your defined environment.
Your AWS account· eu-west-2VPC · private subnetsexternal to your tenancyAlert evidence, extracted fields and dispositions remain within the defined boundary. Agent Factory provides the workflow definitions; execution occurs in your account.
terraform init~1 minterraform apply~14 minFirst workflow availablesame business dayTrace decisions and outputs to the evidence that supports them.
Harnesses are designed to support claims with citations. Each run produces a reviewable timeline, links statements to source material and routes defined outcomes to an authorized reviewer before release.






