Security
Give security teams control at the point of AI action.
Visibility tells you what AI did. Governance determines what AI is allowed to do. Oconee Runtime gives security teams both: named detection across supported AI surfaces, policy that resolves to allow, warn, block or redact, and a decision record that names the action, the context evaluated and the rule that matched.
No sales call required.
An inventory is not a control
Most AI security tooling reports usage. That is worth having and it does not change an outcome — a report that an agent deleted something is not a control over whether it could.
The question a security team is eventually asked is not how much AI is in use. It is what AI was permitted to do, who decided, and what happened when the rule was tested.
Example scenario
One action, evaluated
Proposed action
Coding agent
Destructive command against infrastructureContext
- Actor
- Developer
- Agent
- Coding agent
- Resource
- Infrastructure definition
- Signal
- destructive_command_intent
- Policy
- Organisational rule for destructive commands
Policy decision
BLOCK
The decision is recorded with the signal, the policy and the context, so the follow-up question — what was evaluated, and why — has an answer.
Recorded as evidence
- actor
- agent
- action
- resource
- context
- policy
- decision
- timestamp
What an investigation gets
Every decision is recorded, including the ones that allowed an action. An allow is evidence that the control ran and reached a conclusion, which is exactly what someone reconstructing an incident needs.
- The actor and the agent, where the surface reports them
- The action and the resource it targeted
- The context evaluated, including repository sensitivity
- The policy that matched and the decision it produced
- A timestamp, on an append-only record
- Actor
- Agent
- Action
- Resource
- Context
- Policy
- Decision
- Evidence
Relevant capabilities
- Named signals rather than an undifferentiated risk score
- Allow, warn, block and redact enforcement
- Exception requests, time-limited or single-use, when a block needs an appeal
- Alerting to Slack and email
- Export, including SIEM export where the plan enables it
Oconee is one layer
Oconee adds action governance to a defence-in-depth architecture. It does not replace IAM, DLP, EDR, AppSec or prompt security, and is not designed to. What it adds is a decision at the point an AI-assisted action is attempted, and a record of that decision afterwards.
Common questions
- What is action-level AI governance?
- Applying policy to what an AI system does rather than only to what it is asked. The control evaluates a proposed action against identity, resource and context at the moment it is attempted, and records the decision.
- Can decisions be exported to a SIEM?
- Export is available, and SIEM export specifically is a plan-gated capability. Decision records carry the action, resource, context, policy and outcome.
Related
Other use cases
Prevent sensitive AI actions
Risk appears after the prompt, in what the agent reads and assembles.
Protect critical repositories
The same command is routine in a sandbox and unacceptable in production.
For engineering leaders
Blanket restrictions push engineers to unmanaged tools and lose you the visibility.