DAMN / Governance

The control layer for AI workforces.

Every agent you run, ops and coding, in-house and connected, under one layer of registry, policy, and audit. On infrastructure you own.

Every agent leaves the same five questions unanswered.

Who owns this agent?
What can it access?
What did it do?
Who approved it?
Who's accountable?

Most companies can’t answer one of them. Not in a spreadsheet, not across a dozen tools.

The control layer

One control layer for every agent.

One registry, one identity for each worker, one policy engine, one approval pipeline, one tamper-evident audit trail. Built in-house or connected from outside, every agent answers to the same five.

Built here

Ops agents

LegalFinanceOps

Connected

Coding agents

Claude CodeCursorCodex

Connected

Vendor agents

AgentforceServiceNow

One control layer

RegistryIdentityPolicyApprovalsAudit
Runs on your infrastructure.Your data never leaves.

The difference

Hold the keys, not the conversation.

Damn governs what agents can access: keys, tools, internet, and actions. It never reads your prompts, your code, or your data.

Governance without surveillance.

Governed by Damn
Keys
APIs
Databases
Internet
Execution
Never read by Damn
Prompts
Code
Data

The work stays private.

Control the access. Not the content.

Governance model

Observed, governed, or contained.

The product tells you exactly which tier each agent is in. We never blur the line between what we observe and what we enforce.

Observed

Visible, attributed, and auditable. Every action flows into your registry and audit trail.

Governed

Policies enforced live. Risky actions are blocked or held for approval before they run.

Enterprise

Contained

Runs inside a Damn-governed environment with fail-closed guarantees on keys and internet.

Unmanaged

Outside your perimeter and not under active control. The gap the registry surfaces first.

Policy engine

Policies apply instantly.

Change a rule once and it takes effect immediately. Target specific agent types, teams, tools, or environments. No redeploy, no code changes, no rollout.
The policy console: approval tiers, capabilities, and escalation rules, applied live

Failure modes

Real failures need a real system.

AI agents move fast. Mistakes, drifts, and malicious attacks move just as fast.

Leaked keys & access

Keys resolve and role-based access (RBAC) is enforced server-side, never on the agent.

Destructive actions

Payments, deletions, and production writes are stopped, or held for a human.

Runaway spend

Cap monthly cost per agent, team, or workspace; overage is blocked.

Access drift

Enterprise

Every agent tied to your identity provider, via SSO, SAML, and SCIM.

Audit gaps

Every action on a tamper-evident, hash-chained trail.

Data exfiltration

Enterprise

Air-gapped deployment, zero network egress.

Sovereignty

On your servers. Never ours.

Your agents, their permissions, and their audit trail stay inside your boundary. Your machines, your models, your data. Nothing leaves your perimeter.

Outside your control

ChatGPT
Claude
Copilot
Public cloud
Data never crosses this line

Your perimeter

Your agents
Your data
Your models

Everything runs here. Nothing leaves.

Contained mode

Need airtight execution?

In the Enterprise tier, run coding agents inside a Damn-governed environment where keys and internet are yours. Zero change to how your developers work.
Damn-governed boxfail-closed
🤖Coding agentworking normally
keys
via Damn · short-lived
internet
via Damn · allowlist
No standing keys. The only door out is Damn.

Your agents. Your rules. Your data.

Damn secure.