Watchlight AI

Why Watchlight

One architecture, stage by stage

Governing one checkpoint is a feature. Governing a run from the intent an agent declared to the record of what it did is an architecture. Here is what Watchlight AI Beacon does at each stage, and why each stage needs the one before it.

  1. Intent
  2. Authorization
  3. Execution
  4. Drift
  5. Containment
  6. Lineage
Why Watchlight

One architecture, stage by stage

These are not six features that happen to ship together. Each one is what Watchlight AI Beacon does at a stage of the execution lifecycle, and each depends on the ones before it.

Intent

Task-scoped, intent-aware authority

Authority is granted for the intent the agent declared and the task in front of it, and nothing more.

Authorization

Deterministic pre-action authorization

Every action is checked against formal, versioned policy before it runs, and scoped, time-bound authority is validated across every hop, agent to agent to tool. No language model sits in the trust path.

Execution

Two enforcement layers, one decision

The same decision is enforced in-process through the framework plugins and on the wire through the proxy, across agent frameworks, evaluated locally in your environment.

Drift

Drift measured against the agent’s own baseline

Behavior is scored against the baseline that agent established and the plan it declared, against a threshold rather than a model’s judgment, so the same behavior yields the same result.

Containment

Containment while the run is still going

Stop the run, quarantine the agent, sever the delegation subtree, or revoke the authority across the fleet, while the run is still going.

Lineage

Signed execution lineage

A tamper-evident record of who authorized each action, and why, as audit-grade evidence.

IAM & security depth
23+ years of enterprise identity and security architecture, applied to autonomous agents
Published framework
We authored the 12 Non-Negotiable Principles for Agent Runtime Governance
Read the 12 Principles
Defining the discipline
60+ published articles on Agent Runtime Governance, each backed by working code
Read the blog
Available now
Watchlight AI Beacon, version 0.9.13, is available now, ready to install in your environment, on-premises or air-gapped.
Designed against enterprise standards
ISO/IEC 42001ISO 27001SOC 2EU AI ActOWASP Agentic Top 10CIS Controls v8
Explore Watchlight AI Beacon
Questions

Common questions

What is Agent Execution Governance?

Agent Execution Governance is what Watchlight practices within the Agent Runtime Governance category: governing an agent’s execution from the intent it declared, through authorization, execution, drift and containment, to a signed record of what it did, rather than deciding a single tool call in isolation.

How is Watchlight different from a tool-call gateway?

A per-call check decides one request and is finished. Watchlight AI Beacon governs the whole run: authority is scoped to the intent the agent declared, validated across every delegation hop, enforced in-process and on the wire, and a run that drifts from its plan can be contained while it is still going.

We value your privacy

We use cookies for analytics and to remember your preferences. Learn more ·