RotaGrant by Rotascale
Govern the action, not the model.
RotaGrant gives every AI agent explicit, bounded authority, and enforces that authority before consequential actions happen.
- Runs in your environment
- No payloads sent to Rotascale
- Verifiable evidence
Agents have identity. They need authority.
- IAM
- tells you who the agent is.
- Evaluation
- tells you whether the model is capable.
- Observability
- tells you what happened.
- RotaGrant
- determines what the agent is allowed to do, before it does it.
Nine gates. One decision before the action.
Every consequential action passes through the same path before execution, in the same order, and the answer is one of six rather than two.
allow deny exhausted
gated review_sync review_async
The agent below was authorised to settle payments. Just not this one.
- authoritypassed
- statuspassed
- windowpassed
- scopepassed
- contextpassed
- boundspassed
- policypassed
- budgetrefused
- reviewnot reached
Refused at gate 8. The agent was inside its own ceiling; an ancestor grant was exhausted, so the tree was not. Gate 9 never ran, and the record says so rather than leaving it blank.
Your governance layer shouldn’t belong to your model vendor.
One governance layer across every agent runtime. A hyperscaler will govern its own estate well and only its own, so an independent layer spanning several runtimes is worth more with each entrant, not less.
- OpenAI
- Anthropic
- Google Gemini
- AWS Bedrock
- LangChain
- LangGraph
- MCP
- Google ADK
- CrewAI
- AutoGen
- AWS Strands
Your environment. Your keys. Your evidence.
RotaGrant does not need your prompts, payloads or business data. Governance executes inside your environment: your VPC, your data centre, or airgapped.
Start by observing. Enforce when you’re ready.
Enforcement is a mode on a grant and it moves one rung at a time:
observe, shadow, canary,
enforce. The first two refuse nothing and cost nothing.
Don’t trust our claims. Check them.
- Live agents
- Agents run on the demo daily, ask for authority and get refused. Nothing on it was seeded. observed →
- Open specification
- Versioned and permissively licensed, so a competitor’s engine could claim conformance to it. observed →
- Verifiable artefacts
- Check a signed pack in your own browser. Nothing is uploaded. observed →
- Published failures
- We attack our own detectors and publish the cells we fail, classified as defect or residual. observed →
- Adversarial assurance
- A search over every identifier and mutation the regime activates, run against our own detector, with a denominator rather than an assurance that we tried. observed →
observed the link goes to the thing itself, not to a description of it. asserted we are telling you, and there is nothing you can verify from outside. The product draws this line in every record it produces, so it would be strange to abandon it here.
We argue in public
What the regulations actually say, where our own controls fail, and the engineering underneath. Written to be disagreed with rather than to rank for anything.
Put one consequential agent under governance.
Deploy RotaGrant around one real workflow and see what would have been allowed, refused or escalated over your own traffic, before anything is blocked.
Newsletter
Occasional, and worth the inbox space.
Notes on agent governance, what the regulations actually say, and what we are building. Roughly monthly. Double opt-in, no tracking, and unsubscribing takes one click and asks you nothing.
RSS works too and needs nothing from you · What happens to your address