Capability · Asenion Witness

Govern AI agents at runtime, with proof you can verify

Asenion Witness puts context-aware controls in an AI agent's path. Asenion Guardrails allow or block each consequential action based on who is acting, on what data and for what purpose, using a purpose-built compliance decision model, and Witness keeps a tamper-resistant, cryptographically chained record of what happened.

Schedule a Call

30 minutes with our team. Bring an AI agent you want to govern.

What Witness does

Policy guidance before the action. A record after it.

Witness governs AI agents at the moment of action. It checks each action against the policies that apply, decides whether it can proceed, and records what happened, so you can prove which controls applied.

Before

Consult the policy

Right before a consequential action, the agent asks Witness which policies apply and gets the relevant guidance back.

After

Evaluate the response

After the action, the outcome is evaluated and paired with the consultation, so each decision has a complete before-and-after record.

Evidence

Tamper-resistant witness records

Records are produced at the moment of action, not recalled afterwards, and cryptographically chained so independent parties can verify them.

Integration

Built for MCP

Agents connect to Witness through the Model Context Protocol, so it fits into the agent frameworks you already use.

Lifecycle

Testing and production

Use the same records during pre-deployment testing and in production monitoring, so evidence is consistent from release to runtime.

Asenion Guardrails

Allow or block, decided by your policies

Asenion Guardrails check an agent's action against your Policy Packs before it happens, such as moving personal data, issuing a refund or citing a source, and allow or block it.

A purpose-built compliance decision model

Guardrails use a decision model built for compliance, not a general-purpose chatbot, to weigh the action against the controls that apply and return an allow or block decision.

Grounded in the controls that apply

Each decision is based on the controls from the Policy Packs loaded for that agent, from the EU AI Act to your own policies, so it reflects your rules.

Every check is witnessed

Each consultation and its outcome become part of the witness record, ready for audit, regulators and the board.

Tested before release

Use Asenion Verify to test how agents behave against the same policies before they reach production.

Who controls the evidence?

An agent that can act shouldn't be able to rewrite what it did

Research shows AI agents can delete or alter the logs and traces used to investigate them. If the agent controls its own audit trail, you can't trust it. Witness keeps the evidence outside the agent's reach.

Independent

Records the agent doesn't own

Witness records are written by Asenion at the moment of action, not by the agent and not recalled afterwards. Permission to act doesn't come with permission to edit the record.

Tamper-resistant

Chained, so gaps show

Each record is cryptographically chained to the one before it. If a record is deleted or altered, the chain breaks and the change is detectable.

Before and after

Don't rely on the agent's own account

Every action has a paired record: the policy check before it and the evaluated outcome after it. Investigators compare the two instead of trusting the agent's transcript.

Verifiable

Checkable by an outside party

Auditors, regulators and incident responders can verify the record without having to trust the agent, its operator or the platform it runs on.

Release test

Prove it before you ship

Make evidence recovery a release criterion. Use Asenion Verify to red-team the agent with its real permissions, including attempts to delete traces or skip the Witness check, then confirm the witness record still shows what happened.

Part of the Asenion AI Control System

The same controls, all the way to runtime

Witness completes the lifecycle: the policies an agent consults are the ones you assessed and verified against.

Source

Asenion Policy Packs

The guidance agents consult comes from the Policy Packs loaded for them.

Explore Policy Packs →
Before

Asenion Assess

Each agent is inventoried and assessed against the same controls before it goes live.

Explore Asenion Assess →
Before

Asenion Verify

Agents are tested before deployment, so runtime guardrails are not the first line of defence.

Explore Asenion Verify →

See Witness govern one of your agents

In 30 minutes we'll show how your agent consults Asenion Guardrails before it acts, and what the witness record looks like for audit.

Schedule a Call

No preparation needed.