Skip to content
CipherQuay

Platform

An independent control plane at the action boundary.

CipherQuay is a human-managed console plus an API-first control plane. Humans define authority, policy, approvals and oversight. AI agents and enterprise systems interact through APIs, gateways, connectors, SDKs and enforcement integrations.

Private enterprise preview — capability is being introduced in stages

Architecture

Four functions, one operating record.

Discovery informs delegation. Delegation constrains enforcement. Enforcement produces evidence. Evidence corrects delegation.

Control plane architecture — conceptual
HUMAN OVERSIGHT · SPONSORS, APPROVERS, RISK, AUDITRADARobserveMANDATESauthoriseGATEenforceBLACK BOXevidenceAPIs · GATEWAYS · CONNECTORS · SDKs · IDENTITY · CI/CD · CLOUD · DATA · FINANCE

Module 01

CipherQuay Radar

Discovery and machine-authority mapping

Radar builds and maintains the picture of what is operating in your estate: agents, models, frameworks, skills, tools, MCP servers, service accounts, credentials, data pathways, accountable owners and the consequential capabilities each machine holds. It distinguishes documented authority from inherited or undeclared reach, and highlights machines with no accountable sponsor.

  • Inventory of agents, tools, skills and MCP servers
  • Credential and identity reachability
  • Owner and sponsor attribution
  • Consequential capability classification
  • Change detection across the authority surface
Machine authority surface — conceptual
MachineAccountable sponsorReachable systemsAuthority state
Build fleet agentPlatform EngineeringRepositories, CIMandated
Release pilotEngineeringCI/CD, staging, productionOverbroad
Cloud housekeeperUnassignedCloud, IAMNo sponsor
Support responderCustomer OperationsCRM, emailUnder review
Procurement assistantFinanceSupplier recordsMandated
MCP tool serverUndocumentedFiles, shell, networkUnmapped

Illustrative — not live data

Module 02

CipherQuay Mandates

Purpose-bound delegation and policy

A mandate is a written, versioned statement of delegated authority. It names the sponsor and the permitted purpose, lists the resources and actions in scope, sets limits and approval requirements, defines expiry, states the evidence required, and specifies the conditions under which authority is revoked. Anything not granted is not authorised.

  • Sponsor, purpose and scope
  • Explicit exclusions and limits
  • Approval and quorum requirements
  • Time bounds, expiry and renewal
  • Revocation conditions and evidence expectations
Agent mandate — conceptual
mandate.id
mnd_4f1c · v3
machine
agent://build-fleet/refactor-01
sponsor
Head of Platform Engineering
purpose
Remediate dependency advisories in service repositories
resources
repo:payments-api, repo:ledger-lib
actions
read, branch, propose-change
excluded
merge, deploy:production, iam:*, secrets:rotate
limits
≤ 25 changed files per proposal, no schema changes
approvals
human review by repository owner
credential
short-lived, purpose-scoped, non-retained
expiry
14 days from issue
revocation
on sponsor withdrawal, policy change, or anomaly
evidence
full request, decision and diff record required

Illustrative — not live data

Module 03

CipherQuay Gate

Runtime action control and approval

Gate evaluates a proposed consequential action at the action boundary and returns an enforceable decision. Evaluation considers the machine's identity, its sponsor, the applicable mandate and policy, the target environment, and the present operating conditions. Approvals are routed to accountable humans rather than to the requesting machine.

  • Decision at the action boundary, not after the fact
  • Independent approval routing
  • Environment separation and change windows
  • Interruption, containment and revocation paths
Action gate — conceptual decision
REQUESTdeploy service payments-api → environment production
Machine
agent://release-pilot-02
Sponsor
Director of Engineering
Mandate
mnd_9a20 · staging release
Present conditions
outside declared change window
DECISION · NARROW + HUMAN APPROVAL

Production deployment is outside the mandate. The action is narrowed to a staging release; a production release requires an independently controlled approval from a sponsor who is not the requesting machine.

PermitDenyNarrowHuman approvalQuorum approvalVerifySimulateTemporary credentialDelayRevoke

Illustrative — not live data

Module 04

CipherQuay Black Box

Evidence, incident reconstruction and audit support

Black Box retains a defensible operating record: what was requested, which machine acted, who sponsored it, which mandate and policy applied, what decision was returned, what approvals were obtained, what changed, whether the action stayed within authority, and whether containment or reversal succeeded.

  • Chronological reconstruction of an incident
  • Authority attribution for each action
  • Approval and decision provenance
  • Export for internal audit and regulatory enquiry
Evidence record — conceptual
record
evd_77b1 · sealed
requested
production deployment of payments-api
machine
agent://release-pilot-02
sponsor
Director of Engineering
mandate applied
mnd_9a20 · v2
policy applied
change-window, environment-separation
decision
narrowed to staging; production approval required
approvals
1 of 2 obtained; production approval not granted
state change
staging revision 41 → 42
within authority
yes
containment
not required
retained for
audit, incident reconstruction, regulator enquiry

Illustrative — not live data

Decisions

Enforcement is more than permit or deny.

A useful control plane can reduce an action rather than refuse it outright, so that legitimate work continues under a tighter boundary.

Permit

The action is within an active mandate and present conditions are satisfied.

Deny

The action falls outside any granted authority.

Narrow

A reduced form of the action is permitted; the consequential part is withheld.

Human approval

An accountable person must approve before the action proceeds.

Quorum approval

Two or more independent approvers are required.

Verify

Additional assurance about context, target or intent is required first.

Simulate

The action may be modelled or dry-run without effect.

Temporary credential

A short-lived, purpose-scoped credential is issued and not retained.

Delay

The action is held for a defined interval or window.

Revoke

Authority is withdrawn and the machine's active grants are terminated.

Integration

Placed where consequence occurs.

CipherQuay is model-agnostic and designed to be introduced incrementally: observe first, mandate next, enforce where consequence is highest, and evidence throughout.

Interfaces
  • Control-plane API
  • Agent and service SDKs
  • Gateway and proxy enforcement
  • Connectors and webhooks
Enterprise surfaces
  • Identity providers
  • Repositories and CI/CD
  • Cloud and IAM
  • Databases and data platforms
Business surfaces
  • Finance and procurement
  • Communications and CRM
  • Ticketing and change management
  • Security operations

Illustrative — not live data

Integration surfaces described here are planned or illustrative. CipherQuay is in private enterprise preview; no integration or enforcement capability should be assumed to be generally available. Availability is confirmed in writing during preview engagement.

Next step

Understand the authority your machines already hold.

The Machine Authority Exposure Assessment is a read-only engagement that establishes what your agents can do today, who sponsors them, and what evidence exists if something goes wrong.