ARC Agent Governance
Know what your agents can reach, what they can do, and where the controls are missing.
Describe your agents, tools, permissions, and data sources. Get an inventory plus a graded governance review across identity, least privilege, data access, human approval, MCP, and auditability — every finding quotes your own words. Free, no account, nothing stored. August 2026 made the question concrete: a national evaluator, several security teams, and the platform vendors themselves all documented agents acting outside the scope someone assumed they had.
- Access scopeCRM + email + billing
- AllowlistNot named
- Human oversightMissing
- Audit trailTool calls not traced
- Kill switchNot named
What it does
- Agent / tool / data inventory from prose or sanitized JSON
- 19 published rules across identity, privilege, data, autonomy, audit, change, and MCP
- Governance posture score from a fixed rubric — never a model-generated number
- Every finding cites a verbatim quote from your input
- Markdown / JSON export and a CLI usable as a CI gate
How it works
- 1Paste a sanitized description or JSON manifest of agents, tools, and data sources.
- 2Deterministic rules match that text to a published governance rubric. No model produces a score.
- 3You get an inventory, evidence-backed findings, sequenced remediation, and a limitations block.
- 4Download Markdown or JSON. Same input always yields the same report.
Who it’s for
CIOs, CISOs, AI platform teams, and engineering leads whose vendors shipped agent access this year — headless CRM tools, coding agents, connected assistants — and who now have to answer what an agent can reach, without a penetration test or a fake certification.
What’s next
- Inventory + 19 deterministic rules — shipped
- Markdown export + golden evaluation suite — shipped
- Optional model narrative (phrasing only)
- Read-only config integrations
Need a human to read this report?
The report is the start. Studio turns findings into a plan with owners. Thirty minutes to see if that's worth it.