Company
Somebody has to govern the agents nobody owns.
Rotascale builds RotaGrant: a governance layer for autonomous agents that works across runtimes rather than inside one vendor's estate. Authority stated in advance, enforced before the action, and evidence that survives being checked by somebody who does not trust you.
Why this, and why now
Every serious enterprise is putting agents into production faster than it can answer a simple question about them: who said this one could move money. The tooling that grew up around models answers a different question — how a model scores, what it cost, what it said. None of it constrains what an agent may do at four in the afternoon with a payment API in reach, and none of it produces a record a supervisor can check afterwards.
The action is the governable unit
Not the model, not the prompt, not the token spend. An agent's consequential actions are where the money moves and where the obligation attaches, and they are the only thing a control can sit in front of.
observed →Nobody will build this across
Every platform vendor is building agent governance for their own estate, which is rational and is also the opening: governing a competitor's runtime well is a feature that helps a customer leave. An enterprise runs agents on several. Each new entrant makes a neutral layer worth more.
observed →Several jurisdictions, one workload
A Singapore bank with European customers is under PDPA and GDPR and the AI Act at once, possibly on a Canadian host. A product built for one country resolves one regime. This one resolves a profile per decision and seals it into the record.
observed →Where the product came from
Rotascale spent several years doing senior advisory work on AI in banking, insurance and government — the sectors where an autonomous system's mistakes have a regulator attached. That work is why RotaGrant looks the way it does, and it taught us three things we have built into the product rather than into a slide.
- Nobody is short of dashboards
- Every institution we worked with could tell you what its models did. None could tell you what a named person had authorised, or produce the refusal that should have happened and did not.
- The evidence question arrives late and hard
- It arrives as an incident, an audit, or a supervisor's letter — and by then the record either exists or it does not. Nothing you build afterwards can make last quarter checkable.
- A control that cannot refuse is not a control
- The most common finding in that work was a governance layer that observed everything and stopped nothing, presented internally as though it were enforcement.
How we work
The vocabulary is open, and unbranded
The entity model and authority grammar are published under Apache 2.0 with our name in them exactly once, as the reference implementation. A competitor's engine can claim conformance to it. That is the point.
observed →The demo is a running deployment
Not a video and not seeded rows. Agents run daily, ask for authority, get refused, and the evidence is sealed. When a grant runs down a named person renews it, and that is on the page too.
observed →We publish where our own controls fail
The adversarial grid against our own identifier detector is on the site, including the cells it fails and the two wrong gates we built before the right one.
observed →The company
RotaGrant is built by Rotascale. Rotascale is a product of Rota, Inc., San Francisco, alongside Rotalabs, the research entity. For India we point at Rotavision — a separate company we are not part of, doing for India what this does globally.
Who is building this
Engineers who spent fifteen years building enterprise systems at Google Cloud and Microsoft, alongside people who have run regulated data and risk functions from the inside. The people who wrote the nine gates have been on the other side of an audit, which is why the product argues about evidence rather than about dashboards.
Several of us are still finishing commitments elsewhere, and naming somebody before they have finished doing right by their current employer is not a thing we are prepared to do to get a logo on a page. That resolves, and this page changes when it does.
The specification is open and unbranded, the SDKs are open source, the demo is a running deployment rather than a video, and the red-team grid publishes the cells our own detector fails. None of that requires you to take a view about who we are.
You should not have to trust us, and this page is the weakest kind of evidence on the site. A biography is an assertion; a signed artefact you can verify in your own browser is not. If who we are is the deciding factor, ask — we will get on a call and you can judge for yourself, which is a better test than a page of photographs.
The research behind it
Rotalabs is the research entity in the same group, and the reason several of the harder ideas in RotaGrant exist as engineering rather than as intentions. Its work on detecting strategic underperformance in AI systems and on verifying agent behaviour at scale is what the assurance side of this platform is built on.
The red-team grid is a quality-diversity search rather than a fixed list of attacks, and the distinction between a defect and a residual — which decides whether an evidence check passes — came out of that work rather than out of a product meeting.
Research that can only ever confirm the product is not research. Kept as its own entity, it is free to publish a result that says a control we ship does not work — and the red-team page on this site exists because it has.