DAMN / Governance
The control layer for AI workforces.
Every agent you run, ops and coding, in-house and connected, under one layer of registry, policy, and audit. On infrastructure you own.
Every agent leaves the same five questions unanswered.
Most companies can’t answer one of them. Not in a spreadsheet, not across a dozen tools.
The control layer
One control layer for every agent.
One registry, one identity for each worker, one policy engine, one approval pipeline, one tamper-evident audit trail. Built in-house or connected from outside, every agent answers to the same five.
Built here
Ops agents
Connected
Coding agents
Connected
Vendor agents
One control layer
The difference
Hold the keys, not the conversation.
Governance without surveillance.
The work stays private.
Governance model
Observed, governed, or contained.
The product tells you exactly which tier each agent is in. We never blur the line between what we observe and what we enforce.
Observed
Visible, attributed, and auditable. Every action flows into your registry and audit trail.
Governed
Policies enforced live. Risky actions are blocked or held for approval before they run.
Contained
Runs inside a Damn-governed environment with fail-closed guarantees on keys and internet.
Unmanaged
Outside your perimeter and not under active control. The gap the registry surfaces first.
Policy engine
Policies apply instantly.

Failure modes
Real failures need a real system.
AI agents move fast. Mistakes, drifts, and malicious attacks move just as fast.
Leaked keys & access
Keys resolve and role-based access (RBAC) is enforced server-side, never on the agent.
Destructive actions
Payments, deletions, and production writes are stopped, or held for a human.
Runaway spend
Cap monthly cost per agent, team, or workspace; overage is blocked.
Access drift
EnterpriseEvery agent tied to your identity provider, via SSO, SAML, and SCIM.
Audit gaps
Every action on a tamper-evident, hash-chained trail.
Data exfiltration
EnterpriseAir-gapped deployment, zero network egress.
Sovereignty
On your servers. Never ours.
Your agents, their permissions, and their audit trail stay inside your boundary. Your machines, your models, your data. Nothing leaves your perimeter.
Outside your control
Your perimeter
Everything runs here. Nothing leaves.
Contained mode
Need airtight execution?
Your agents. Your rules. Your data.
Damn secure.