Microsoft Entra
Identity & directory
The governance layer for enterprise AI agents.
Every identity owned. Every decision governed. Every action accounted for.
Your infrastructure. Your identities. Your authority.
Read and export 2,400 customer records from Salesforce through crm.contacts.export.
One action. One named approver.
| Agent | Reserved | Ceiling | Utilization |
|---|---|---|---|
| analytics_01 | $10.00 | $50.00 | |
| support_02 | $3.20 | $20.00 | |
| data_04 | $44.50 | $45.00 | |
| research_07 | $12.00 | $30.00 |
analytics_01crm.contacts.export · 2,400 recordsPriya RamanAuthorized#4181 · 77b1c0e2…03aa9ab42a…0c91Built to run on the stack you already trust
Agents can already reach your applications and your data. AAES puts identity, human authority, and enforceable boundaries in front of the actions that matter.
Every agent has a registered identity and a named human manager.
Delete, send, pay, deploy, and approve always reach a person.
analytics_01 requests permission to export customer records.
Try a decision. This is an illustrative interaction.
Know which agent is acting and which human is responsible.
Agents only see what they are allowed. For anything else, they request human access.
Consequential actions need a human. An agent cannot approve itself.
Budgets are reserved when the decision is made.
Over the ceiling, the call never leaves. The refusal becomes part of the record.
| Agent | Reserved | Ceiling | Utilization | Decision |
|---|---|---|---|---|
| analytics_01 | $10.00 | $50.00 | Within budget | |
| support_02 | $3.20 | $20.00 | Within budget | |
| data_04 | $44.50 | $45.00 | Near ceiling | |
| research_07 | $12.00 | $30.00 | Within budget |
Account for the spend before the action, not after the bill arrives.
An over budget request is refused before a call can leave AAES.
Refusals stay visible, alongside the decisions that went through.
From an agent's request to a sealed record. The controls happen on the path to execution, not in a review after the fact.
The agent names the capability it wants to use. The destination and credential come from the registration, never from the agent.
analytics_01crm.contacts.export2,400 recordsKeep your identity provider, collaboration tools, vault, and monitoring. AAES works with the infrastructure your enterprise already runs.
Identity & directory
Identity & directory
Directory & collaboration
Enterprise communication
Secrets & key custody
Evidence & monitoring
From a single VM to an isolated enterprise environment.
Choose where the system runs and where your data and keys live.
Run the daemon, ledger anchor, and operator CLI with Docker Compose. Your records live on your host. You create and control the keys.
One sealed, hash chained record per action.
Verify it offline against a key AAES does not hold. No dashboard required.
analytics_01crm.contacts.export · 2,400 recordsPriya Ramanallow_export · R3$10.00 / $50.00Enforcede94d…f7c077b1…03aa3f9c…8e21The recorded authorization, scope, named approver, and integrity of the sealed bytes. The evidence travels with you, not with a subscription.
Work outside AAES is invisible. A confirmed call does not prove the intended outcome, and a source label does not authenticate external evidence. Observed is never presented as enforced.
AAES stands for Autonomous Agentic Enterprise Systems. It is a governance layer for enterprise AI agents, connecting registered identities and human managers to permissions, approvals, budgets, and sealed action records.
No. AAES can govern your agents while people remain in your existing identity provider. It works with Microsoft Entra, Okta, and Google Workspace. You do not need a new directory to get started.
An agent that can call an API or MCP can integrate with AAES. The system sits on the action path, not inside a particular agent framework. The agent only discovers the capabilities it is entitled to use.
Yes. A capability can be registered as observed, with every record labeled accordingly. AAES cannot stop calls while the agent retains its own direct credentials. Enforcement requires moving credential authority and blocking the agent's direct path to the vendor.
Not yet. The coverage matrix lists 65 native adapters, 3 interface only entries, and 17 named gaps. Native adapters are tested against local servers speaking vendor API formats, not live vendor tenants. No live verification or production adoption is claimed.
No. The AAES hosted cell is a planned deployment mode, gated on SOC 2 Type I. AAES has no SOC 2 report today. Single VM, Kubernetes, and air gapped or on premises deployment modes run on customer infrastructure.
You retain the exported records and verifier. Verification works offline against a key AAES does not hold. No external witness or timestamp authority is wired yet, and the tools make that limitation explicit.

Thirty minutes. One governed action.
A human approval and a sealed record you can take with you.
Pre pilot. Built for scrutiny, not overclaiming.