Product — Lucidrail Control Plane
Product · Control Plane

Give agents authority without giving away control.

Lucidrail sits between AI agents and consequential actions. Every call is attributed to an identity, evaluated against policy and live context, and allowed, held or blocked — then verified and recorded.

  1. 01IdentifyWhich agent, for whom
  2. 02EvaluatePolicy, risk, provenance, spend
  3. 03DecideAllow, hold, restrict, block
  4. 04ExecuteOnly inside the envelope
  5. 05VerifyAgainst system state
  6. 06RecordStructured audit evidence
Identity

Identity for non-human workers.

Every agent is a first-class principal with an organization, a role, a declared purpose, a tool set, limits and a responsible human. Decisions and evidence attach to that identity — not to a shared API key.

L
LisaChief of Staff · agt_lisa_01
Organization
Acme Holdings
Declared purpose
Coordinate email, calendar, research and follow-up for the CEO office
Tools
gmail.* · calendar.* · crm.update · docs.read
Limits
$2,500 / month · no payments over $1,500
Responsible human
Dana Whitfield
Audit history
4,812 governed actions · 7 days
Governance · Authorization

Policy for verbs that matter, evaluated in context.

Policies govern what agents may do with each system. The same rule can resolve differently depending on the agent’s capability, the task’s provenance, the argument values and current spend.

readmodifysendpublishpurchaseexecutedeleteaccessdelegate
# illustrative policy syntax
policy external-comms/contaminated-trajectory
  when action = email.send
   and recipient.domain ∉ org.domains
   and task.provenance = contaminated
  then require_approval(agent.responsible_human)
  evidence task.sources, draft, recipients
Approvals

Approve the action, not an abstract permission.

Reviewers see the exact proposed action and the evidence behind the hold. They can approve, reject, edit, ask the agent to explain, or inspect sources. The decision is bound to that action — and to the tool schema it was approved against.

Try the approval queue →
email.sendThe actual draft, recipients and attachments.
payments.transferAmount, beneficiary, invoice and ledger evidence.
db.mutateThe statement and the rows it would affect.
github.deployDiff, CI evidence and the target environment.
Provenance

Trust follows the trajectory.

Action provenance records the information sources, tool outputs and external inputs that preceded each action, their trust state, and the downstream actions that depend on them. Lucidrail works from observable inputs and outputs; it does not claim access to a model’s hidden reasoning.

calendar.readinternal
web.fetch vendor-portalexternal
inbox/msg_8812.pdfcontaminated
draft.composeinherits
email.sendheld
Audit

Evidence, not log lines.

Every consequential action produces a structured record you can query, export and hand to a reviewer.

actoractionpolicydecisionapprovalevidenceresulttimestampenvironment

Cryptographic signing of records is applied only where a deployment’s key management supports it; we document exactly which records are signed.

Spend controls

Budgets that act before the invoice.

Per-agent budget$1,284 / $2,500
Per-team budget$31,900 / $40,000
Model spend · escalation at 80%$6,400 / $6,000

Also: tool spend, per-transaction limits, rate limits and escalation thresholds. Illustrative data.

Verification

“The agent says it worked” is not evidence.

Lucidrail records what the agent claimed separately from what the system confirmed. Mismatches are surfaced to the responsible human and count against the agent’s performance signal.

HTTP evidenceStatus, headers, response body
Browser evidenceDOM state after the action
Database stateRead-back of the affected rows
Logs & artifactsBuild output, files, hashes
Independent verifierA separate check of the outcome
Observability

Configured isn’t the same as enforced.

For each control, Lucidrail shows whether it is configured, whether it is in the path and evaluating, how often it triggered, and the most recent evidence. A control that has never produced evidence is flagged — not assumed to work.

See control effectiveness in the console →
ENABLEDA setting says it’s on.
OBSERVED WORKINGEvidence shows it acted.
Mechanisms

Governance that actually runs.

Policy replay

Available

Test governance changes against reality before deploying them.

Replay historical actions under a proposed policy to see what would remain allowed, require approval, or be blocked.

Cross-step taint

Available

A clean final instruction cannot erase a poisoned trajectory.

When an untrusted step contaminates a task, downstream consequential actions remain constrained until cleared.

Capability-aware headroom

Experimental

Authority should reflect capability.

Different models receive different autonomous headroom around consequential tools, based on evaluation evidence.

Governed self-improvement

Experimental

Agents do not receive unlimited permission to rewrite themselves.

Deteriorating performance reduces an agent’s freedom to modify its prompts, skills and workflows.

Idle automation protection

Available

Autonomy should have an accountable owner.

Long-running automations pause when their responsible humans are no longer active.

Approval invalidation

Available

Approval belongs to a specific capability — not merely a tool name.

If a tool’s schema or semantics materially change, standing approvals are invalidated and re-requested.

Control verification

Available

Configured isn’t the same as enforced.

Each control exposes evidence that it is executing and whether it has triggered.

See it on your own agents.

Talk to us Open the console demo