Watchlight AI

Agent Runtime Governance

Give AI agentsreal capability.With real control.

Watch what agents are allowed to do, what they actually do, and stop unauthorized actions before they execute.

  • DecideDefine authority and policy
  • EnforceControl execution in real time
  • ContainStop and isolate when things go off plan

Built for security teams. Designed for the agentic future.

Agent Execution

Live

Plan: Analyze customer data and create a summary report.

  1. Read database schemaAllowed
  2. Query customer dataAllowed
  3. Send summary reportAllowed
  4. Delete customer recordsOutside its delegated authorityBlocked

Governed execution keeps your agents on mission.

From intent to outcome, with provable lineage.

Learn more

Defining the category

  • Created Agent Runtime GovernanceThe category, defined February 2026
  • Architecture reviewed by Fortune 50 security teamsPlus Fortune 1000 enterprises
  • Authored the 12 PrinciplesThe framework that defines ARG
  • Architecture submitted to NISTResponse to the NCCoE concept paper
  • Watchlight AI Beacon 0.9.13Available now, ready to install
  • 9 native framework pluginsPlus MCP servers and custom agents
  • Watchlight CloudEarly-access control center for Developer Edition
  • Developer EditionFree, with an open-source SDK
  • 60+ published articlesDefining the discipline in the open
  • Founded by an identity architect23+ years in IAM, co-inventor of IAM Microservices
  • Deterministic authorizationNo model in the trust path
  • Delegated authorityChild agents can’t exceed parent permissions
  • Complete lineageTrace every decision and action
  • Runtime containmentStop, isolate, and revoke when needed
  • Deploy anywhereYour cloud, on-prem, or air-gapped
Secure today. Enable tomorrow.
Agent Execution Governance

Govern the Entire Agent Execution Lifecycle

An agent does not take one action. It runs. Watchlight AI Beacon governs every stage of that run, from the intent it declared to the record of what it did.

Stop damage. Limit blast radius. Prove every decision.

  1. Intent
  2. Authorization
  3. Execution
  4. Drift
  5. Containment
  6. Lineage
  1. Intent

    What the agent says it is trying to do.

    Capture the task, the declared goal, the plan, and the context under which authority is being exercised, so every later decision has something to be measured against.

    How Beacon does this
  2. Authorization

    A deterministic decision before the action runs.

    Evaluate identity, delegated authority, the task, policy, the action arguments, execution state, and runtime context, then return a decision. No language model sits in the trust path.

    How Beacon does this
  3. Execution

    The decision enforced where the action happens.

    Two independent enforcement points carry the same decision: in-process through the framework plugins, and on the wire through the enforcement proxy when an agent leaves the instrumented path.

    How Beacon does this
  4. Drift

    Divergence caught while the run is still going.

    Behavior is scored against the baseline the agent established for itself and the plan it declared. Divergence is measured against a threshold rather than judged by a model, so the same behavior yields the same result every time.

    How Beacon does this
  5. Containment

    Act on a run already in motion.

    When execution becomes unsafe or unauthorized, the response is immediate rather than queued for a human to triage later.

    Stop the runQuarantineSever subtreeRevoke
    How Beacon does this
  6. Lineage

    Proof of what happened and why.

    Signed, tamper-evident records of which agent initiated the action, how authority propagated, which policy was evaluated, and what Watchlight decided, so the chain can be reconstructed on demand.

    How Beacon does this

Governance you can watch happen

Don’t take our word for it.Watch it execute.

See how deterministic authorization, real-time enforcement, and runtime containment keep AI agents on mission.

We value your privacy

We use cookies for analytics and to remember your preferences. Learn more ·