One platform to govern every AI agent.
GIRD is one platform to see every AI agent, govern every action, and prove every decision. It covers Macs, servers and cloud today. Windows and the browser are on the roadmap.
Nine ways to bring AI agents under control.
They work together, from one console.
Every AI agent, known and shadow, with a real owner.
GIRD keeps a live inventory of every AI agent in your company, the ones you sanctioned and the ones that showed up on their own, each tied to a real person and team.
- Unapproved (shadow) agents flagged as soon as they run
- Every agent attributed to a named owner and team
- One inventory across Macs, servers and cloud
A record of every agent action you can prove.
GIRD keeps a tamper-proof record of every action every agent takes. It's the evidence you need for an incident, an audit, or a regulator.
- Records can't be altered after the fact
- Every action tied to the agent and the person behind it
Every agent inherits your teams and your policies.
Connect Okta, Microsoft Entra ID, or Google Workspace, and your AI agents inherit the teams, roles, and rules you already manage for people.
- Connects to Okta, Microsoft Entra ID, and Google Workspace
- Agents inherit the roles and rules you already manage
- Access follows people as teams and roles change
Control and visibility, agent by agent.
Decide what each agent may use, who it may work with, and where its data can go.
MCP Registry
Approve the MCP (Model Context Protocol) servers, the tools and data connections your agents call, and block the rest.
Agent-to-Agent Governance
Decide which agents may hand work off to which others, and exactly what they're allowed to pass between them.
Skill Registry
Approve the skills (add-on instructions and tools) an agent can load, so it never gains access you didn't grant.
Telemetry & Observability
Watch what every agent does, as it happens.
PII Protection
Catch customer records, secrets, and regulated data before an agent can send it anywhere it shouldn't go.
One policy per agent, with four controls.
Every agent gets a single master policy that says what it may do. You set the rules once, and GIRD enforces them on Macs, servers and cloud.
Tools and tool-servers
Approve the actions and tool-servers an agent may call. Everything else is denied by default.
Peer agents
Decide which other agents it may talk to.
Delegation
Decide which agents may hand work off to which, and how far that delegation can travel.
Skills
Control the skills an agent can pick up, so it never gains a capability you didn't grant.
Wherever your agents run, one control plane.
An AI agent has the same owner and the same policy on a Mac, a server or in your cloud, and everything it does lands in one place. Windows and the browser are on the roadmap.
Mac
Windows
Servers & cloud (AWS, Azure, GCP)
Browser
AI assistants on developer Macs
Your engineers run AI coding assistants on their Macs, and those assistants can reach source code, secrets, and customer data. Argus records and limits what each one can reach, tied to a real person, with nothing for developers to change. Argus is free to download and use. Team and Enterprise rollouts are agreed in a signed contract.
- See every AI assistant on every Mac, tied to its owner
- Keep credentials, secrets, and sensitive files out of reach
- Roll it out through the tools you already manage Macs with
The same protection for Windows fleets
The Windows laptops in your company run the same AI assistants, with the same risks. Windows coverage is on the roadmap and will report into the same console under the same policy.
Planned: one console for Mac and Windows laptops side by side, with the same per-agent policy on either operating system.
AI agents in your production apps and cloud
The AI agents inside your own products act on real customer data and real systems, reaching databases, internal APIs, and each other, often without asking a human first. GIRD for Servers & Cloud brings those agents under the same control: what each can do, who it can talk to, and a tamper-proof record of what it did. It covers agents on your servers and in AWS, Azure, or Google Cloud.
- Set what each production agent is allowed to do, and enforce it
- Stop one agent from reaching systems and data it shouldn't
- A tamper-proof record of what each agent did
Unauthorized AI agents in the browser
Some AI agents work inside the browser, filling forms, clicking through apps, and reading data off the screen. Browser Guard is on the roadmap and is not available today.
Planned: stop unauthorized AI agents from acting in the browser, and redact sensitive data before an agent can take it off the page, with the same record and owner as every other surface.
See the platform on your own agents.
Bring the AI agents your company runs under one policy, with one record.