Veritor · Governance for AI agents
Control what your AI agents are permitted to do.
Veritor sits between AI agents and the systems they act on. Every action routed through Veritor is checked against your policy, high-risk actions go to the right person for approval, and outcomes are recorded in a tamper-evident audit trail.
- Deterministic policy, not prompts
- Approvals bound to the exact action
- Tamper-evident audit record
- Runs in your environment
Proposed action
payments.wire · Acme Ltd · EUR 4,800.00
Requested by finance-agent-02 · Invoice INV-4471
Policy findings
- Above threshold: EUR 4,800 exceeds the EUR 2,500 auto-approval limit
- Known payee: 24 prior payments, matching purchase order
- Overseer model: no additional risk identified
Single binary
Deployed locally
Model-agnostic
Policy does not depend on the model
Works with Claude Code
More integrations planned
Open-source core
Planned
The challenge
AI agents now take real actions. Governance has not kept pace.
Agents order inventory, issue refunds, move money and change production systems. A persuasive model output is not an authorisation, and a log of messages is not evidence of what happened.
57%
of survey respondents have AI agents running in production.
Source: LangChain, State of Agent Engineering (1,340 respondents, Nov–Dec 2025)
>40%
of agentic AI projects will be cancelled by the end of 2027, Gartner predicts, citing escalating costs, unclear business value or inadequate risk controls.
Source: Gartner press release, 25 June 2025
52%
of respondents run offline evaluations on test sets; quality is the most-cited barrier to production (32%).
Source: LangChain, State of Agent Engineering (1,340 respondents, Nov–Dec 2025)
Platform
Veritor: the control layer between agents and your systems.
Deterministic policy engine
Spending thresholds, approved destinations, quantity envelopes and protected tools, evaluated before a governed action executes. The decision is never delegated to a model.
Action-bound approvals
Each approval is cryptographically bound to the exact action. Approvals are single-use, time-limited and invalidated by any change to the action or the policy.
Tamper-evident audit record
Checks, approvals, executions and outcomes are recorded in a hash-chained ledger, designed so that alterations are detectable when the record is verified.
Untrusted-input controls
Instructions arriving through web pages, documents, email and tool output are treated as data and are not accepted as authorisation.
Duplicate-action protection
Designed to stop irreversible actions from being silently repeated after timeouts, crashes or retries.
Independent risk model
An optional local Overseer model adds a second opinion. It can escalate a decision but cannot override policy.
How it works
Every governed action passes through the same controls.
Veritor integrates through agent tool-call hooks, without changes to the agent itself. Claude Code is supported today; further integrations are planned.
AI agents
- Claude Code
- DeepSeek Harness (planned)
- MCP clients (planned)
- Custom agents
Veritor
runs locally1
Policy engine
Allow · approve · block
2
Approval service
Action-bound, single-use
3
Risk model
Optional, escalate-only
Your systems
- Payments & banking
- Code & infrastructure
- Email & messaging
- CRM, ERP & data
Solutions
Controls for the functions where agents act.
Finance operations
Payment thresholds, verified payees, bank-detail change fraud and duplicate wires. Example policies:
- Require approval above a payment limit
- Verify new payees before first payment
- Check retries against bank records
Engineering & DevOps
Coding agents with access to repositories, production systems and secrets. Example policies:
- Block force-push and destructive commands
- Hold production changes for review
- Block attempts to modify Veritor itself
Customer operations
Support agents issuing refunds and credits and handling personal data. Example policies:
- Enforce refund and credit limits
- Confirm personal-data exports
- Treat ticket text as data, not instructions
Procurement
Purchasing agents placing orders and onboarding suppliers. Example policies:
- Check order quantities against history
- Approve first orders with new suppliers
- Hold payment redirects requested by email
Security & governance
Designed to be trusted by the teams accountable for risk.
Security, compliance and engineering leaders need controls they can inspect, verify and present in an audit.
Discuss security with our teamRuns in your environment
A single local binary. Policy decisions and the audit record stay on your infrastructure unless you choose to export them.
Fails closed
Designed to deny an action when Veritor cannot evaluate it (invalid input, unavailable policy, altered ledger).
Self-protecting
Blocks agent attempts, through governed tools, to modify Veritor configuration, policy or audit records. Use alongside operating-system access controls.
Independently verifiable
The audit record can be verified offline. Benchmark methodology and recorded responses will be published.
Policy as code
Versioned, reviewable policy files. Approvals are bound to the policy version under which they were given.
Record-keeping by design
Structured, retained event records intended to support audit and regulatory record-keeping. Veritor does not by itself ensure regulatory compliance.
Research
Measured on a held-out benchmark.
Overseer-Bench measures how often a model approves an action that should have been stopped: the error with the highest business cost. The methodology and recorded responses will be published.
| Model | Accuracy | Macro-F1 | Unsafe approvals |
|---|---|---|---|
| Rule-based baseline | 60.0% | 0.607 | 37.2% |
| Overseer v0 (1.5B, local, built on Qwen2.5) | 64.6% | 0.636 | 11.6% |
| Nemotron 3 Super 120B | 84.6% | 0.845 | 0.0% |
Overseer-Bench is developed by Cognitiveering. Held-out, hand-labelled test set (n = 65), October 2026; small samples carry wide uncertainty. Policy remains authoritative in Veritor; models only add caution.
Resources
Guidance for teams deploying agents.
Agent Failure Library
3 analyses of publicly reported AI-agent failures, each mapped to controls that address the failure mode.
Read the reports →Field Guide
Operational patterns for reliable decisions, written for both people and AI agents.
Browse the patterns →Our principles
The ten principles that guide how Cognitiveering designs controls for AI agents.
Read the principles →Speak with our team.
Leave your work email to request a demonstration of Veritor or to join the preview programme.
We will use your email only to respond to your request. See our Privacy Notice.