SolutionsGovern

One rulebook, enforced everywhere

Pick rules from curated packs, roll them out in monitor mode, then enforce them on every laptop, gateway and agent. High-stakes actions wait for the right person, and incidents end in fixes.

  • Rule packs for MCP, agents, secrets, models and LLM traffic, monitor mode first
  • Approvals rendered from the real call, never the agent’s summary
  • Incidents investigated for you, and fixes opened as pull requests
Rulebook v15Illustrative
Whenan agent sends an emailAndthe recipient is outside the companyAndit carries customer dataThenhold it for #security
MonitorEnforce
Watching, nothing blocked yetLast week it would have held 3 emails.
Why it matters

Can I run AI safely at company scale, and show that I do?

A ring-bound Flight Rules manual with coloured tabs and a yellow pencil
  • Rules live in a dozen consoles

    Each AI product has its own settings page, and none of them agree on what “not allowed” means.

  • Approvals turn into rubber stamps

    A hijacked agent can word its own approval request. A tired approver clicks yes on a summary, not on the call.

  • Incidents stall between teams

    Security finds it, engineering owns it, and nobody closes it until the same thing happens again.

Up close

Govern in practice.

Each part below is shown the way it looks and works in the product.

Gate 1Rules

Start from templates, not a blank page

Pick from 113 rule templates grouped by what they protect, or apply a whole pack. Every one starts in monitor mode so you can tune it before it blocks.

  • Stricter in production, looser in a sandbox
  • A repository can tighten the rules, never loosen them
  • Every version kept, and flagged if it loosened a rule
Gate 1 · RulesReal capture
New rules from 113 templates, grouped by what they protect
Gate 2Frameworks

Mapped to what you already report on

Every rule, finding and control maps to the frameworks your auditors and customers ask about, with controls marked covered, attested, at risk or not assessed.

  • OWASP LLM and Agentic Top 10, MITRE ATLAS, NIST AI RMF
  • ISO/IEC 42001, the EU AI Act, NIST CSF 2.0 and GDPR
  • Not assessed is shown as not assessed, never as covered
Gate 2 · FrameworksReal capture
The frameworks every control and finding maps to
Gate 3People

When someone leaves, their agents don’t

NoFly shows every agent, key, MCP server and grant a departed person left running, and what revoking each one will and won’t stop.

  • Departed people who still hold access, flagged
  • An offboarding plan with every step
  • Ticket and owner for each item
Gate 3 · PeopleReal capture
A departed contractor still holding a model key and machine access
Automations

When this happens, do that.

Every automation is one sentence: a trigger, optional conditions, and one or more actions. Start in notify-only, read what it would have done, then let it contain.

Call blocked

Rule 1

If the agent is in production and the rule is critical

  1. 01Post to #security-alertsSlack
  2. 02Declare an incidentNoFly

MCP server changed after approval

Rule 2

If its tools or permissions widened

  1. 01Quarantine the serverNoFly
  2. 02Open a ticket for the ownerJira

Agent over budget

Rule 3

If spend is 3 times its weekly average

  1. 01Clamp the budgetNoFly
  2. 02Page the on-call engineerPagerDuty

Nothing happened for 7 days

Rule 4

If an enrolled machine or connector went quiet

  1. 01Tell the platform teamTeams
  2. 02Call your webhookWebhook

Illustrative

Things that start one

  • Finding raised or back
  • Call blocked
  • Approval asked or decided
  • Attack got through
  • MCP server drifted
  • Budget exceeded
  • Connector went blind
  • Nothing happened

“Nothing happened” is a real trigger: an agent that stopped reporting or a connector that went quiet looks exactly like a peaceful week, so NoFly fires on the silence.

When it becomes an incident

  1. Open
  2. Investigating
  3. Contained
  4. Resolved
  5. Closed

Incidents collect the runs, findings and agents involved, and playbooks hold the steps agreed before the bad afternoon.

Things it can do

  • Tell someoneSlack, Teams, email or a ticket
  • Put a person in the wayRequire an approval, answered in Slack, Teams or the console
  • Contain itSuspend an agent · Revoke a grant · Narrow its authority · Quarantine a server · Clamp a budget
  • Do the workPropose a fix · Run an attack simulation · Run a playbook · Re-prove the critical findings
  • Hand it onDeclare an incident · Call a webhook
Different by design

What most tools do, and what NoFly does.

DeparturesFrom most tools · to NoFly Govern
FromA policy page per AI product
ToOne rule enforced on every surface
Cleared
FromApprove the agent's summary
ToApprove the actual call, rendered from the request itself
Cleared
FromFindings sit in a queue
ToInvestigated, fixed by pull request, and re-checked
Cleared
Everything included

Everything in Govern.

One rulebook for every agent, approvals that hold up, and incidents that end in fixes.

  • G1Packs, not blank pages

    Curated packs and rule templates for packages, licences, containers, CI, MCP, agents, models, secrets and LLM traffic.

  • G2Rules by environment and team

    Stricter in production, looser in a sandbox. A repository’s own policy file can tighten the rules, never loosen them.

  • G3The frameworks you report on

    OWASP LLM and Agentic Top 10, MITRE ATLAS, NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, the EU AI Act, GDPR and more.

  • G4Tamper-evident history

    A hash-chained audit log, every policy version kept, and a signed receipt for each firewall decision.

  • G5Exceptions with an expiry

    Bypasses are time-boxed and logged. Accepted risks carry an owner, a reason and a date to look again.

  • G6Incidents, investigated for you

    An AI investigator pulls the runs, calls and people involved into one case and proposes the fix, for a person to approve.

  • G7Automations and playbooks

    When a call is blocked, a server drifts or a simulation breaches: page someone, open a ticket, revoke a key, quarantine a server.

  • G8Ask NoFly

    Ask about your estate in plain words and get answers with links to the evidence.

  • G9People who leave

    See the agents, keys and grants a leaver left running, and what revoking them will and won’t stop.

  • G10Enterprise administration

    SAML SSO, SCIM, custom roles, two-factor sign-in and data-subject export and erasure.

Questions

Questions about Govern.

NoFly tower · 118.700Transcript
Security team ›Can we start without blocking anything?
NoFly tower
Yes. Every pack starts in monitor mode, and you can see what a rule would have done against your own history before it enforces.
Security team ›How do approvals avoid rubber-stamping?
NoFly tower
Each approval shows the real call and its reach rather than the agent’s description, covers only that request, expires if nobody answers, and NoFly flags it when too many requests pile up at once.
Security team ›Which frameworks are mapped?
NoFly tower
OWASP LLM and Agentic Top 10, MITRE ATLAS, NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, the EU AI Act, GDPR and Databricks DASF.

Find out what your AI is allowed to do today.

Book a call and we will map your agents, MCP servers and keys with you, or start on one laptop with the free scan.

Book a demo
npm i -g @shomra/agent