Agent Execution Governance
Watchlight AI Beacon. Govern AI agent execution from intent to outcome.
The enterprise runtime control plane for autonomous AI agents. Beacon authorizes every action, enforces delegated authority throughout execution, detects drift, contains unsafe behavior in real time, and preserves signed execution lineage. Deterministic. On-prem. Air-gapped.
Where Beacon goes deeper
Per-call allow or deny is table stakes. Beacon governs the whole run, from the intent an agent declared through the lineage of what it did, and acts on it in real time.
Real-time enforcement effects
Stop a run, quarantine an agent, sever a delegation subtree, and revoke authority, fleet-wide, when a chain goes wrong mid-execution.
See containmentDrift detection that quarantines
When an agent drifts from its declared plan, it is quarantined at machine speed, not queued as an alert for a human to triage later.
See containmentStrict-subset attenuation
A sub-agent receives a strict subset of its parent’s authority, and any attempt to widen it is denied before the action runs.
See authorizationTwo enforcement layers, one policy decision
In-process plugins govern the plan and every tool call inside the framework. The proxy governs every request on the wire. An unauthorized action has to clear both.
Six Tiers of Agent Runtime Governance
Each tier builds on the one below it, and each one governs a stage of the execution lifecycle. Together they form a complete governance stack for autonomous AI agents.
Discovery & Registry
Lifecycle stage: Before the lifecycleYou can't govern what you can't see.
Continuously discover every AI agent and MCP server across your environment. Register, classify, and track trust state for every autonomous actor.
Agentic Policy Decision Point
Lifecycle stage: Intent · AuthorizationEvery action evaluated. Every decision justified.
Real-time, intent-based authorization for every agent action, returning Allow, Require approval, or Deny. Delegated authority with strict-subset attenuation: a sub-agent can never exceed its parent.
Runtime Enforcement Proxy
Lifecycle stage: ExecutionPolicy enforced at the point of action.
Enforcement on the wire between agents and the resources they access, sharing one policy decision with the in-process plugins. Real-time enforcement effects: stop a run, quarantine an agent, sever a subtree, revoke authority.
Runtime Containment
Lifecycle stage: Drift · ContainmentStop an agent that is already running.
Behavioral drift scored against the agent’s own baseline, and real-time effects that act on the whole run: stop it, quarantine the agent, sever the delegation subtree, revoke authority fleet-wide.
Execution Lineage
Lifecycle stage: LineageTrace how every action happened.
Signed, tamper-evident execution lineage that reconstructs the full chain from the human who authorized it, through every delegation hop and policy decision, to the downstream resource. Drift from a declared plan triggers quarantine, not just an alert.
Framework Plugins
Lifecycle stage: ExecutionGovernance for the frameworks your teams actually run.
Drop-in plugins extend the same policy and audit trail across the agent frameworks your teams run, including LangGraph, Claude Agent SDK, Claude Code, Google ADK, AWS Bedrock Agents, Microsoft Agent Framework, Pydantic AI, DeepAgents, and OpenClaw, plus MCP servers, with no agent code changes.
What You Get
Measurable governance outcomes for your organization.
Built on 12 Non-Negotiable Principles
Every capability in Watchlight AI Beacon traces back to a governance principle. Three layers: Foundations, Execution, and Operations.
Download the FrameworkCommon questions
What is Watchlight AI Beacon?
Watchlight AI Beacon is the enterprise runtime control plane for autonomous AI agents. It governs agent execution from intent to outcome: it authorizes every action, enforces delegated authority throughout execution, detects drift, contains unsafe behavior in real time, and preserves signed execution lineage.
How is Beacon different from identity and access management?
Your identity provider decides who an agent is and what token it carries. Beacon governs what the agent does with that authority: it decides each action at runtime against current policy, enforces delegated authority across agent-to-agent delegation, and can stop a run that is already in motion. It works downstream of your identity provider rather than replacing it.
Which agent frameworks does Beacon support?
Beacon ships native plugins for LangGraph, the Claude Agent SDK, Claude Code, Google ADK, AWS Bedrock Agents, Microsoft Agent Framework, Pydantic AI, DeepAgents and OpenClaw, plus MCP servers, and it covers custom and in-house agents through a documented integration contract. It also integrates with NVIDIA OpenShell, deciding every request inside OpenShell’s supervisor for agents running in OpenShell sandboxes. Coverage for each framework depends on what its lifecycle exposes.
Where does Beacon run?
In your environment: on-premises, in your private cloud, or air-gapped with no outbound connectivity. The deterministic policy engine evaluates every action locally, so the control plane never depends on a vendor cloud. Watchlight AI Beacon 0.9.13 is available now.
Ready to Govern Your AI Agents?
Watchlight AI Beacon is available now, ready to install in your environment, on-premises or air-gapped.
