The governed workstation

Keep control without keeping AI out.

Full autonomy where you allow it. None where you don’t. Decided per command, at the moment the command acts — on the exact application, process and window it is about to touch.

What we govern

Everyone governs the data the AI reads. We govern the actions it takes.

Identity tells you who the agent is. A sandbox tells you where it runs. Approval tells you when it may. None of them tells you what it is about to touch. InvokeFlow checks that — every command, at the target, as it resolves right then.

Five controls, on every command

Control at the moment it matters.

Control you already trust

Your cloud already works this way. Your desktop didn’t.

A cloud key that opens one bucket, not the account. A sandboxed app that gets the file the user picked, not the filesystem. Data-loss controls that govern the channel. Authority bound to the action is how enterprises already stay in control — everywhere except the desktop, where the work actually happens.

Now it does.

The execution of record

Every company has a system of record. Almost none has an execution of record.

Tamper-evident, hash-chained, and ready to hand to an auditor. Every command, every refusal, every policy change — in one chain, exportable to the tools your security team already runs.

#ActorApplicationCommandAuthorityResult may go toEvidenceOutcome
4181agentCRM (desktop)Record.Updategrant-2f9a · per-commandsame applicationread-back checkran · verified
4182agentDialerCall.Placegrant-2f9a · per-commandsame applicationnative responseran
4183personNotesDocument.Insertseat · human in seatsame application—ran
4184agentEmailMessage.Sendgrant-2f9a · destructiveexternal—refused · not named for this run
4185agentSheetRange.Readgrant-2f9a · per-commandsame application—ran · text, 14 chars
4186admin—Policy.Changeconsole——recorded

No titles. No text. No URLs. A read’s result never enters the chain — a type-and-size descriptor stands in for it. Destructive steps are skipped unless a person names each one, every run. There is no “approve all.”

Local-first, cloud-optional

Your machines. Your model. Your record.

Your machines

The runtime and the broker run in your environment. Nothing leaves the endpoint unless you send it.

Your model

Bring the agent and the model you already chose — cloud or local. Nothing about the runtime needs ours.

Your record

The chain lives with you and exports to your SIEM. It is evidence you own, not a report you request.

What we call it, depending on who’s asking

One thing, described at four heights.

The idea
Software invocation

The software you already own, doing the work — invoked by a person or an AI, governed at the moment it fires, with a record it ran.

What it is · for the security room
A governed programmable runtime

A runtime for unmodified applications on Windows, macOS and Linux, where every command passes a check at the live target and lands in one chain.

How it works · for the engineer
Native application invocation

Agents call the application’s own commands, discovered from the running application itself — not from a screen, and not from a plugin the vendor had to ship.

What you get · for the auditor
The execution of record

Every command checked where it lands, signed, and kept — attested at the endpoint, where the action happened.

Designed for the failure modes

Built for the ways AI agents go wrong.

Overreaching. Taking access they weren’t given. Acting on a window that changed underneath them. The runtime treats each one as a refusal on the record, not an incident to investigate — and the way it checks authority is patent-pending.

Start here

Start with the application you’ve never let an agent touch.

It runs governed from the first command, with every refusal on the record — and the record is yours to hand to whoever asks.