Most AI governance tools still think in models and policies. Production risk now sits in agents that call tools, write memory, and loop. OptimaTrust registers agents, records tool catalogs, stores ALLOWED / RESTRICTED / DENIED boundaries, and exposes a Governor decide API. Traces show user → agent → model → tool hops when you ingest them. This is technical assurance for agentic systems — not a chatbot content filter and not a GRC workflow suite.
What you get
- Agent cards with tools, MCP, loop limit, and autonomy
- Agentic-risk tests: excessive agency, impersonation, approval bypass
- Governor ALLOW/DENY with policy-to-code rules
