Skip to content

Enterprise machine authority

Capability is not authority.

CipherQuay is an independent, model-agnostic control plane for the authority exercised by AI agents and autonomous systems. It is designed to let an enterprise discover where machine authority already exists, delegate it deliberately, constrain it at the point of action, and evidence what happened afterwards.

Visit CipherQuaycipherquay.com(opens in a new tab)
01Overview

CipherQuay is an independent, model-agnostic control plane for the authority exercised by AI agents and autonomous systems. It is designed to let an enterprise discover where machine authority already exists, delegate it deliberately, constrain it at the point of action, and evidence what happened afterwards.

The positioning is deliberately narrow. Conventional identity systems answer who authenticated and which resources a principal may reach. CipherQuay is built around a different question: what has this machine been authorised to accomplish, on whose behalf, under which present conditions and limits — and can the organisation prove it later.

The problem

Enterprise AI has moved from drafting text to taking actions: opening pull requests, changing infrastructure, moving money, touching production systems. Agents inherit the privileges of the accounts they were given rather than the privileges their task requires, and instructions can arrive from documents, tickets and third-party tools as well as from people.

Intended users

Enterprises running agentic systems, with an initial focus on coding, engineering and DevOps agents.

02Capabilities

What CipherQuay does.

01

CipherQuay Radar

Discovery of agents, models, tools, MCP servers, service accounts, credentials, data pathways, owners and consequential capabilities — a live machine-authority surface map.

02

CipherQuay Mandates

Purpose-bound and time-bound delegation specifying sponsor, permitted purpose, resources, actions, limits, approvals, expiry, evidence requirements and revocation conditions.

03

CipherQuay Gate

Evaluation of proposed consequential actions at the action boundary, returning an enforceable decision: permit, deny, narrow, approve, verify, simulate, delay, terminate or revoke.

04

CipherQuay Black Box

A defensible operating record of what was requested, who sponsored it, which mandate applied, what was decided, what changed and whether containment succeeded.

05

Human sponsorship and interruption

Every consequential machine action is designed to carry an accountable human sponsor, explicit limits and a practical means of interruption and revocation.

03Operational advantages
  • Model-agnostic and independent of any single agent vendor.
  • Enforcement sits at the action boundary rather than inside the model.
  • Delegation is explicit, bounded and expiring rather than standing.
  • Decisions and outcomes are recorded as an operating record.
04User benefits
  • A stated purpose, sponsor and boundary for each consequential machine action.
  • A practical route to narrowing, delaying, interrupting or revoking agent activity.
  • Evidence that supports internal assurance and regulatory conversations.
05Technology & differentiation

An authority layer between access and action

CipherQuay separates model behaviour from enforcement. Prompts and alignment measures are treated as safety properties, not as independent enforcement boundaries; the enforceable decision is made outside the agent, at the boundary where a consequential action is attempted.

  • API-first control plane with a human-managed console.
  • Mandate model carrying sponsor, purpose, limits, expiry and revocation conditions.
  • Deterministic decision surface at the action boundary.
  • Operating evidence produced as a durable record.
06Current stage

Private enterprise preview, with a Machine Authority Exposure Assessment as the primary public offer. Support for regulatory alignment is not certification and does not guarantee compliance.

Visit CipherQuaycipherquay.com(opens in a new tab)