Foundry360 · AI Action Governance Gateway
Govern AI Actions From Policy To Proof.
Enigma determines whether AI actions may proceed under enterprise policy, enforces the decision at the request boundary, routes exceptions to authorized approvers, and creates proof of what was decided and what happened.
The gap
Your AI Can Act. Nothing Decides Whether It Should.
Identity systems, governance programs, and written AI policy all stop short of the moment that matters: the instant an agent attempts a consequential action.
No Decision Authority
Agents propose writes, tool calls, and regulated completions all day, but coarse application permissions cannot judge this action, on this data, for this purpose. The policy that should answer the question lives in documents rather than on the request path.
No Enforcement On The Path
Controls are applied after the fact, if they are applied at all. There is no consistent hold for high-consequence actions, and human approval happens over email instead of acting as a gate the action has to pass through.
No Defensible Evidence
Who acted, what was attempted, what was decided, and who approved it? Application logs can be edited, so they are not proof. Regulators and boards ask for the chain, not a dashboard.
The missing layer is an authoritative decision at action time, on the request path, with enforcement behind it and evidence after it.
Product thesis
Enigma Governs AI Actions From Policy To Proof.
AI governance becomes meaningful when policy is applied to an actual AI action and produces an authoritative decision that can be enforced, reviewed, and evidenced.
Bind
Who and what is acting
Application, user, agent, tool, and operation are resolved server-side rather than trusted from the client.
Decide
One authoritative decision
A single policy evaluation produces one immutable decision record for the attempt.
Enforce
Control at the boundary
Block, tokenize, restrict the model path, hold the write, or authorize the commit.
Review
Human authorization
Decisions held for review route to an authorized approver, never to the requesting end user.
Prove
Evidence chain
Decision, enforcement, and reported outcome, sealed in a tamper-evident audit chain.
How it works
One Decision Path On The AI Request Path.
Applications and agents call Enigma instead of calling models and tools directly.
Enterprise App Or Agent
Copilots, internal agents, services
Enigma Gateway
Bind actors, classify data
Policy engine produces a decision
Enforce controls
Execution
Gateway runs the model,
or authorizes the client system
to perform the change
Evidence
Decision and audit chain
plus reported outcome
Completions
Enigma applies controls such as tokenization, redaction, and model eligibility, then executes the model itself.
Actions And Writes
Enigma authorizes the commit. Your system of record performs the change and reports the outcome back.
Fail-Closed
If the registry or the policy engine cannot establish authorization, the attempt is denied rather than assumed safe.
Reference architecture
One Path, Drawn End To End.
Every governed AI action converges on one authoritative decision. The control applied, the approval, and the reported outcome are all recorded against that decision.
Decision model
Four Decisions. One Record. No Silent Allow.
One policy evaluation. Exactly one outcome.
Enforcement boundary
We Are Precise About What The Gateway Controls.
Enforcement honesty is a feature. Buyers who over-trust a governance layer eventually discover the gap themselves.
Gateway-Enforced
Enigma itself applies the control.
Authentication and actor binding, data classification and transforms, model eligibility and invocation, and inspection of the response before release all happen inside the gateway. When the decision is deny or review, Enigma withholds authorization rather than trusting the caller to stop.
Client-Commit-Required
Enigma authorizes; your system performs the change.
After an allow or an approval, Enigma issues authorization to commit, your system of record executes the write, and the client reports the outcome back for the evidence chain. Bypassing the gateway altogether remains a customer-side risk.
Proof
Evidence A Regulator Can Follow, Not A Dashboard.
Decision, enforcement, outcome, and evidence, with integrity that survives scrutiny.
Decision Of Record
Every governed request writes one immutable machine decision capturing actor, action, policy, reasoning, and enforcement.
Tamper-Evident Audit
Audit events are append-only, hash-chained, and signed, with periodic checkpoints and optional external anchoring.
Reported Outcome
Client-commit actions return a sealed outcome receipt with conflict detection, recorded as reported evidence rather than assumed success.
Frozen History
Later policy or registry changes never rewrite past decisions. The record reflects what was true at decision time.
Cryptographic, tamper-evident audit, hash-chained and signed. Deliberately not a blockchain ledger.
Where Enigma fits
Adjacent Tools Govern Programs. Enigma Governs The Attempt.
This is a category boundary, not a competitive attack. Most of these stay in the stack alongside Enigma.
Identity Management
Who may sign in and hold access
Governance And Risk
Programs, registers, attestations
Data Loss Prevention
Data movement and exfiltration
Security Monitoring
Telemetry and correlation
AI Gateways
Model routing, keys, and cost
AI Observability
Traces, quality, and drift
AI Action Governance: Enigma
Action-time decision, enforcement on the path, authorized human review, and evidence of what was decided and reported.
None of the adjacent categories answer the runtime question: should this specific AI action, by this actor, on this data, for this purpose, be allowed right now?
Product
Available Now As An Enterprise Appliance.
Deliberately scoped to the action-time governance chain and hardened.
What Ships
Governed completions and actions APIs sit in front of a server-authoritative agent and tool registry and a single policy engine that writes one decision record per attempt. Approver review resumes the original request, and a decisions-first operator console sits over tamper-evident audit and outcome receipts.
Deployment
Enigma runs connected inside the enterprise or fully air-gapped against local models. Evidence stays in storage the customer controls, and production defaults are fail-closed rather than permissive.
Packaging
Enigma Core covers the enterprise, and the healthcare policy pack is an option layered on top. Customer-specific policies run on the same engine as everything else rather than on a forked one.
Next step
Start With One Real AI Action.
A working session on a single consequential action in your environment, followed by a live walkthrough of the decision, the hold, the approval, and the evidence it produces.
