Solutions / Gate
IRIS8 Gate

Enforcement your policies can actually express.

Guardrail products block bad text. Gate enforces what your institution actually cares about: who may do what, within which limits, under whose approval — at the same gateway that already sees everything.

Observing nowEnforcing 2027Control tier
app.iris8.ai/gate/approvals
wire-adjustment $18,500loan-servicing agent · §5.1.2Awaiting approval
bulk email to 2,400 customerscollections agentAwaiting approval
tool grant: core-banking writenew vendor agentEscalated
rate quote outside matrixpricing agentAuto-declined
4

autonomy tiers from Observe to Act-Autonomously

<1 s

kill-switch propagation across every enforcement point

Per-tool

MCP permissions: read / write / deny

Full context

attached to every human approval

The problem

One agent is manageable. Hundreds are ungovernable without a control plane.

All-or-nothing access

Agents get API keys, not permissions. One over-scoped credential is a breach waiting for a prompt.

No emergency brake

35% of enterprises admit they couldn’t shut down a rogue agent. "Find the engineer who deployed it" is not a kill switch.

Approvals in email

Material AI actions approved in Slack threads and inboxes — unsearchable, unauditable, unenforceable.

Capabilities in depth

Control, tier by tier.

Identity

Every agent gets an identity, not a key

Role-scoped access to models, tools, and data — including per-tool read/write/deny on MCP connections, with end-user identity forwarded through every hop of delegation.

  • Agent identity with role-scoped permissions
  • Per-tool MCP grants: read / write / deny
  • End-user identity forwarded through agent-to-agent hops
  • Access reviews from live usage, not stale grants
app.iris8.ai/gate/approvals
wire-adjustment $18,500loan-servicing agent · §5.1.2Awaiting approval
bulk email to 2,400 customerscollections agentAwaiting approval
tool grant: core-banking writenew vendor agentEscalated
rate quote outside matrixpricing agentAuto-declined
Approvals

Human judgment, exactly where you want it

Act-with-Approval agents route material actions to the right human — by role, amount, or action type — with full context attached and every intervention filed as evidence.

  • Approval queues routed by role and threshold
  • Full decision context in the approval card
  • Autonomy tiers: Observe → Advise → Act-with-Approval → Act-Autonomously
  • Interventions recorded to the evidence layer automatically
app.iris8.ai/gate/approvals
wire-adjustment $18,500loan-servicing agent · §5.1.2Awaiting approval
bulk email to 2,400 customerscollections agentAwaiting approval
tool grant: core-banking writenew vendor agentEscalated
rate quote outside matrixpricing agentAuto-declined
Limits

Caps, breakers, and the kill switch

Token and dollar budgets, action-rate limits, and session caps per agent — with instant suspension that propagates across every enforcement point at once.

  • Budgets with auto-cutoff per agent and team
  • Action-rate and session limits
  • Circuit breakers on anomalous behavior
  • Kill switch: suspended everywhere in under a second
app.iris8.ai/optimize
$12,480saved this month
34%cache hit rate
9budgets active
route: gpt-class → small-fastsupport triage · quality ≥ bar−78% cost
cache hit: product FAQ cluster2,114 requests served$0.00
budget stop: growth-experimentsmonthly cap reachedHalted
Everything included

The full capability set.

A control plane, not another proxy.

Meet you there

Plugs into what you already run

Enforcement points deploy as plugins for the gateways you have — LiteLLM, Portkey, Kong, Azure APIM — plus SDK hooks for LangGraph, CrewAI, AutoGen, and MCP. No rip-and-replace, no mandatory proxy in your critical path.

Identity

Agent identity & scoped permissions

Every agent gets an identity with role-scoped access to knowledge, tools, and data — including per-tool read/write/deny granularity on MCP connections, with end-user identity forwarded through every hop of agent-to-agent delegation.

Policy-aware

Controls that follow your policies

Action limits, approval thresholds, and topic boundaries derive from your centrally defined policies — not scattered per-tool settings. When the policy changes, the control changes.

Threats

Attack coverage, table stakes included

Prompt injection and jailbreak detection — including multi-turn attack patterns — poisoned tool results, PII and secrets masking, with allow / block / transform / alert enforcement modes. Findings stream to your SIEM as OCSF.

Humans

Approval queues & escalation

Act-with-Approval agents route material actions to the right human — by role, by amount, by policy provision — with full context attached. Interventions are recorded as evidence automatically.

Limits

Caps, budgets, and the kill switch

Token and dollar budgets per agent, team, and tool with automatic cutoff; action-rate limits; session caps; instant suspension that propagates across every enforcement point at once.

Staged honestly

Observation first. Enforcement when it's earned.

  1. Today — Observe & Advise. Gate traces every interaction and evaluates it against your policies, flagging deviations without touching production behavior. Your first weeks produce a governance gap map from real traffic.
  2. 2027 — Act with Approval. Enforcement goes live: scoped permissions, approval queues, action caps, kill switch — every control defined centrally and tested before activation.
  3. The horizon — Act Autonomously. Highest-tier agents operate under continuous Guardian supervision with circuit breakers and rollback. Autonomy, on the record.
Questions

The short answers.

What works today vs. 2027?

Observation and policy-aware flagging run today on the Clarity tier. Inline enforcement — permissions, queues, caps, kill switch — ships with the Control tier in 2027.

Does enforcement add latency?

Checks run at the gateway in the same sub-100ms budget as Secure. Approval waits are policy choices, not performance costs.

What happens when the kill switch fires?

The agent’s identity is suspended at every enforcement point, in-flight actions inside reversal windows are rolled back, and the whole event is filed as evidence.

Put your first agent under observation this quarter.

Enforcement arrives on the same gateway — no migration later.

Start free