Compile
Organizational and regulatory rules become machine-checkable policies — a metric, an operator, a threshold — grouped into packs like an EU AI Act High-Risk Pack.
Platform · Observatory
Observatory is FlowX.AI's observability and governance plane. GAVEL enforces policy on live agent telemetry, harvests compliance evidence from every trace, and answers an audit by walking evidence back to the regulation.
enforced at runtime · evidence by default
A policy that lives in a documentcannot govern an agent that chains a dozen tool calls in a second.
The dominant failure mode in production isn't hallucination — it's privilege excess: an agent doing something it was technically able to but never should have, faster than any review cycle can follow. Governance has to run where the agent runs, check what the agent actually did, and leave behind the evidence that it did.
GAVEL · Governed Autonomy, Verified by an Evidence LayerDocument suites pass a paper audit while agents misbehave; control planes stop agents but prove nothing. GAVEL closes the gap — one evidence chain from regulation to what the agent did.
Organizational and regulatory rules become machine-checkable policies — a metric, an operator, a threshold — grouped into packs like an EU AI Act High-Risk Pack.
Policies evaluate against live execution telemetry, not a questionnaire — mandatory or advisory, continuously. A policy being violated says so the moment it happens.
Compliance evidence is auto-harvested from traces as a byproduct of enforcement — collect, review, approve.
An audit is answered by walking evidence back through policy to requirement — every link grounded in what the agent actually did.
02 / What it does
Every agent run is captured, evaluated against policy, and turned into audit-ready evidence — without a parallel record to maintain.
Machine-checkable rules enforced against live telemetry, grouped into reusable regulatory packs.
Compliance evidence auto-collected from traces, with a collect → review → approve workflow.
EU AI Act, GDPR, HIPAA, SOC 2, PCI-DSS, ISO 27001 — requirement → policy → evidence, with continuous gap analysis.
Hierarchical traces of every run, tool call, retrieval and decision, with token, cost and latency telemetry.
In-the-loop for high-risk, on-the-loop otherwise, with a kill switch — human review recorded as evidence.
Every access, enforcement action and human review recorded, tamper-evident, and retained for years.
Bring a high-risk workflow — we'll enforce a policy pack against a live run and hand you the evidence chain.