Security layer for AI agents

Every agent action,
checked before it runs.

Ancros is a security layer between your AI agents and the tools they use. Before a sensitive action runs, it checks the action against your policy, then allows it, blocks it or sends it to a person for approval. Every decision is logged.

See how it works ↓

Illustrative interface with sample data. A Finance Agent asks to export 8,421 customer records. Ancros checks identity, access and policy, holds the request for approval, then records the decision.

Sample dashboard
Illustrative UI with sample data.
ONE REQUEST, START TO FINISH

Follow one risky request from start to finish.

Here's what happens when an agent asks to export customer records.

REQUEST

An agent asks to export 8,421 customer records.

The request goes to Ancros first, not straight to the database. Nothing has been exported yet.

Exampleanc_req_82941Request received
Finance AgentExport 8,421 customer records
ANCROSRequest held for checks
Customer databaseNo action yet

Illustrative UI with sample data.

IDENTITY + ACCESS

Check who is asking and what it can access.

Ancros checks which agent is asking, which environment it's running in, and whether it has been given access to the customer database.

Exampleanc_req_82941Identity verified
ANCROS
Identity: Finance AgentWhich agent is this?
Environment: ProductionWhere is it running?
Permissions: Customer database: grantedMay it touch this system?

Illustrative UI with sample data.

POLICY

Check the action against your rules.

The export is larger than the 1,000-record limit in your policy, so Ancros holds it instead of letting the agent carry on.

Exampleanc_req_82941Policy matched
ANCROS
REQUEST8,421 records
POLICY LIMIT1,000 records
!
Rule matched: High-risk customer exportAction held.

Illustrative UI with sample data.

APPROVAL

Send the risky action to a person.

The request is routed to Finance for approval. Routine actions keep running while this one waits for a decision.

Exampleanc_req_82941Waiting for approval
ANCROS
FINANCE APPROVAL NEEDEDExport 8,421 customer records
DenyApprove
Routine requestAllowed while the risky request waits
Allowed

Illustrative UI with sample data.

AUDIT

Record the decision and release the action.

Once approved, Ancros lets the agent continue and records the request, policy checks, approver and final outcome in the audit log.

Exampleanc_req_82941Released + logged
ANCROS
REQUESTanc_req_82941
AGENTFinance Agent
ACTIONExport 8,421 customer records
RULEHigh-risk customer export
APPROVED BYSample approver
OUTCOMEReleased

Illustrative UI with sample data.

Exampleanc_req_82941Request received
Finance AgentExport 8,421 customer records
ANCROSRequest held for checks
Customer databaseNo action yet

Illustrative UI with sample data.

HOW IT FITS

Ancros sits in the path between an agent and the tool it wants to use.

When an agent requests a sensitive action, the request goes through Ancros before it reaches the target system. Ancros checks the request against policy and returns an allow, block or approval-required decision.

1 · REQUESTAgent or workflow requests an action
2 · CHECKAncros evaluates identity, access and policy
3 · DECISIONAllow, block or wait for a person
IDENTITY

Which agent is this?

Identify the agent making the request and the environment it is running in.

PERMISSIONS

May it touch this system?

Check whether that agent has been given access to the target system or resource.

POLICY

Does this action break a rule?

Evaluate the exact requested action against the rules you have defined.

POLICY

Write rules for what each agent may do.

Match on the agent, the system it's touching, the type of action and the size of the request. Ancros checks the rules before the action runs.

EXAMPLE POLICYHigh-risk customer export
Example
WHEN
Action
=
Export customer records
AND
Record count
>
1,000
THEN
Hold the action
Require Finance approval
Write the decision to the audit log
Finance AgentExport customer records142 records

Identity: example agent identified

Permissions: example access check passed

Rule not triggered: 142 records is below the 1,000-record limit.

DECISIONALLOWED

Illustrative UI with sample data.

REQUEST PATH

Sits between your agents and your tools.

Point agent traffic at Ancros and it checks each action before it reaches the tool.

Examples shown. Named vendors are intentionally omitted until support is confirmed.

AI agentCustom agentInternal workflow
ANCROSIdentity · permissions · policy · approval · audit
Customer databaseCRMPayments toolInternal API
EARLY ACCESS

Start with one agent.

Pick one agent or workflow. Write the rules for what it may do, and require a person's approval for the actions that are too risky to run on their own.

Prefer email? hello@ancros.ai

By submitting, you agree that Ancros may use the details you provide to respond to your enquiry. See the Privacy notice.