Latten

What should an AI agent governance tool show?

An AI agent governance tool should show who the agent acted for, which model ran, what data or service it reached, what PII types were exposed, and what the action cost. Latten shows those crossings on one observe-only graph.

See it on a live graph — no signup →

Govern the actor, not only the prompt

The risk is not just bad output. It is the authority an agent inherits through service accounts, tools, data domains, and handoffs.

Receipts before enforcement

Teams should see the real blast radius before any product changes request behavior. Latten starts observe-only for that reason.

Types and counts, never values

A governance tool should not create a new sensitive-data lake. Latten reports PII as types and counts instead of copying values.

How it works

  1. 1. Seed identity Record the actor and on-behalf-of chain.
  2. 2. Track boundary crossings Instrument LLM, data, API, and handoff calls.
  3. 3. Read the blast radius Find what each actor can reach.
  4. 4. Review fixes Use recommendations only after the evidence is visible.

Common questions

What is AI agent blast radius?

It is everything an agent can reach through its service accounts, tools, and handoffs.

Should governance start by blocking agents?

Usually no. Start by measuring real reach, then bound deliberately.

Does Latten enforce today?

Latten is observe-only at launch. Enforcement is a roadmap direction, not the current public promise.