Twelve controls · six minutes

Most organisations can name their AI policy.
Very few can name who authorised the agent.

Regulators in Singapore, the US and the EU have converged on the same expectation: every autonomous agent carries a unique identity, and every action traces back to a human who authorised it. Named Principal gives every AI agent a named human owner, bounded authority, risk-based approval, and an audit-ready record — starting with knowing exactly where your organisation stands today.

78%of organisations have no documented policy for creating or removing AI identitiesCloud Security Alliance / Oasis Security, State of Non-Human Identity and AI Security, 2026
28%of organisations can trace an agent's actions back to a human sponsor across every environmentCloud Security Alliance research, 2026
21%of organisations deploying agentic AI report a mature governance model for itDeloitte, State of AI in the Enterprise, 2026
Talk to us about a pilot

We store your email and your scores. Nothing else. No agent names, no system details. Privacy notice

How it works

Three steps from "we think we have some AI agents" to a governed, auditable estate.

STEP 1

Assess

Score your organisation across twelve controls, or one specific agent across nine risk factors — six minutes, no account needed.

STEP 2

Register

Save the result as a persistent Agent Passport — identity, purpose, named owner, and the controls its risk tier requires.

STEP 3

Approve & audit

A named principal signs off before an agent goes live. Every decision is timestamped and kept — evidence, not memory.

The three modules

Two are free to use with nothing stored unless you ask. The third — the persistent record — needs an account, because a record that isn't kept isn't a record.

Live now

Organisational readiness assessment

Twelve controls, six minutes. Where your organisation stands against IMDA, MAS, NIST, ISO 42001 and the EU AI Act, and the three fixes that matter most.

You're looking at it ↓
Live now

Agent risk profiler

Nine questions about one specific agent. Returns its risk tier, the OWASP agentic risks it exposes you to, and the controls that become mandatory before deployment.

Open the profiler →
Live now — sign in required

Agent Estate & Passports

A persistent record per agent — identity, accountability, risk and approval history — instead of a result that disappears when the tab closes.

Sign in →

Framework coverage

Every control maps to the provisions regulators and auditors already reference — one assessment, five frameworks, kept current.

IMDAModel AI Governance Framework for Agentic AISingapore · updated May 2026
MASGuidelines on AI Risk ManagementSingapore financial sector
NISTAI RMF 1.0 + COSAiS control overlaysUnited States
ISOISO/IEC 42001 AI management systemInternational · certifiable
EUEU AI ActHigh-risk obligations from Dec 2027

Security & privacy, briefly

The agent risk profiler runs entirely in your browser — no network calls, no storage, nothing transmitted. Agent names and purposes describe your internal architecture, so they never leave your device.

The organisational assessment stores only what you explicitly submit for a report: your email, your organisation name if given, and your scores. Never your individual answers. See the full privacy notice for what's collected, why, and how to have it deleted.