rotascale

RotaGrant by Rotascale

Govern the action, not the model.

RotaGrant gives every AI agent explicit, bounded authority, and enforces that authority before consequential actions happen.

  • Runs in your environment
  • No payloads sent to Rotascale
  • Verifiable evidence

Agents have identity. They need authority.

IAM
tells you who the agent is.
Evaluation
tells you whether the model is capable.
Observability
tells you what happened.
RotaGrant
determines what the agent is allowed to do, before it does it.

Nine gates. One decision before the action.

Every consequential action passes through the same path before execution, in the same order, and the answer is one of six rather than two.

allow deny exhausted gated review_sync review_async

The agent below was authorised to settle payments. Just not this one.

Inspect the decision →

Your governance layer shouldn’t belong to your model vendor.

One governance layer across every agent runtime. A hyperscaler will govern its own estate well and only its own, so an independent layer spanning several runtimes is worth more with each entrant, not less.

  • OpenAI
  • Anthropic
  • Google Gemini
  • AWS Bedrock
  • LangChain
  • LangGraph
  • MCP
  • Google ADK
  • CrewAI
  • AutoGen
  • AWS Strands

Your environment. Your keys. Your evidence.

RotaGrant does not need your prompts, payloads or business data. Governance executes inside your environment: your VPC, your data centre, or airgapped.

Start by observing. Enforce when you’re ready.

Enforcement is a mode on a grant and it moves one rung at a time: observe, shadow, canary, enforce. The first two refuse nothing and cost nothing.

Don’t trust our claims. Check them.

Live agents
Agents run on the demo daily, ask for authority and get refused. Nothing on it was seeded. observed →
Open specification
Versioned and permissively licensed, so a competitor’s engine could claim conformance to it. observed →
Verifiable artefacts
Check a signed pack in your own browser. Nothing is uploaded. observed →
Published failures
We attack our own detectors and publish the cells we fail, classified as defect or residual. observed →
Adversarial assurance
A search over every identifier and mutation the regime activates, run against our own detector, with a denominator rather than an assurance that we tried. observed →

observed the link goes to the thing itself, not to a description of it. asserted we are telling you, and there is nothing you can verify from outside. The product draws this line in every record it produces, so it would be strange to abandon it here.

We argue in public

What the regulations actually say, where our own controls fail, and the engineering underneath. Written to be disagreed with rather than to rank for anything.

Put one consequential agent under governance.

Deploy RotaGrant around one real workflow and see what would have been allowed, refused or escalated over your own traffic, before anything is blocked.

Newsletter

Occasional, and worth the inbox space.

Notes on agent governance, what the regulations actually say, and what we are building. Roughly monthly. Double opt-in, no tracking, and unsubscribing takes one click and asks you nothing.

RSS works too and needs nothing from you · What happens to your address