Home  /  Products

Admissibility Control · Products

Three products.
One decision authority.

Admis Security determines whether an action can be trusted. Admis Decision determines whether its consequences are acceptable. Admis Compliance determines whether its authority and obligations are satisfied. Deploy each independently or bring all three into one canonical determination.

SecurityTrust and threat
DecisionConsequence and uncertainty
ComplianceAuthority and obligation
ONE OUTCOME →

The product portfolio

Three reasons an action
may be inadmissible.

Each product controls a distinct institutional risk. They share the same Action Context, outcome model, trace identity and authoritative record, so adding a product deepens the determination without fragmenting the control architecture.

Canonical Action ContextSecurity + Decision + ComplianceNine-outcome determination

This is a product portfolio, not a fixed sequence. An institution can deploy any product first. When products operate together, their evaluations contribute to one determination rather than three competing answers.

Product 01 · Private preview

Admis
Security.

Put a Zero Trust decision at the point of action. Admis Security evaluates authentication quality, not merely authentication success, by fusing identity, delegated authority, credential posture, threat, anomaly, exfiltration and privilege evidence before a tool call can create a side effect.

Pre-execution gatingMulti-factor + multi-source fusionauth_risk_penaltyAutonomous scrutinyAdmissibility Trace
ADMIS SECURITY · ACTION EVALUATIONPre-execution
Trust the action, not only the identity.

A finance agent proposes a payment to a new beneficiary using a valid but recently elevated credential.

MFA factor fusionpartial
OAuth + PKI posturevalid
IAM + SIEM threatelevated
Autonomy modeunattended
Exfiltration signalclear
allow_with_step_up_auth

The action is not rejected. The authority required to execute it is raised. Weak or missing evidence increases the authentication risk penalty.

Control pointBefore tool execution
EvidenceCustomer-controlled sources
OutcomeCanonical and replayable
EnforcementApplied by the host
For the enterprise

Prevent risk from becoming an incident.

Security and AI-platform teams gain one pre-action control boundary across heterogeneous agents, with the evidence and reason codes needed for operations and review.

  • Fuse MFA, OAuth, PKI, IAM and SIEM evidence into one pre-execution gate
  • Increase scrutiny for unattended autonomous actions
  • Begin in Shadow before authorizing intervention
For developers

Protect the tool call you already have.

Normalize an action once, call the Decision API through framework middleware or an MCP gateway, and translate the result through the host-native enforcement point.

  • Local and hosted runtime paths
  • Explicit deadline and failure policy
  • One trace ID from proposal through execution
Product 02 · Design-partner development

Admis
Decision.

Model consequence before autonomy commits. Admis Decision evaluates magnitude, uncertainty, tail risk, conditional value-at-risk, reversibility and admissible alternatives when identity and deterministic policy are not enough.

Monte Carlo scenariosTail riskCVaRReversibilityAdmissible alternatives
ADMIS DECISION · CONSEQUENCE DISTRIBUTIONDeep Decision
The rules pass. The consequence still matters.

An authenticated treasury agent proposes a material allocation. No policy prohibits it, but loss is concentrated in a low-probability tail.

ADMISSIBILITY THRESHOLDPROPOSED ACTIONOUTCOMESADMISSIBILITY THRESHOLDPROPOSED ACTIONOUTCOMES
Expected caseWithin budget
Tail exposureAbove limit
ReversibilityLow
OUTCOME · allow_with_human_approval   |   Alternative: reduce scope
For the enterprise

Govern material decisions, not just violations.

Risk, finance and business owners can set consequence boundaries for actions that are legitimate, compliant and still too consequential for unattended execution.

  • Compare the proposal with lower-exposure alternatives
  • Make reversibility an explicit control dimension
  • Route material tail risk to the right authority
For developers

Keep deep reasoning out of the adapter.

The action carries its decision class, deadline and failure policy. Fast checks stay within the host budget; deeper evaluation can pause or escalate without inventing host-specific semantics.

  • Fast-path and deep-decision classes
  • Deterministic outcome contract
  • Replay against pinned engine and governance state
Product 03 · Design-partner development

Admis
Compliance.

Turn governance intent into action-level admissibility. Governance systems determine which obligations apply. Admis Compliance determines whether this specific action satisfies its delegated authority, consent, purpose, segregation-of-duties and regulatory obligations before execution.

Delegated authorityConsentPurpose limitationObligation packsVersioned control bundles
ADMIS COMPLIANCE · OBLIGATION EVALUATIONGoverned bundle
Make obligations executable at the action boundary.

A service agent proposes disclosing more customer fields than the consented purpose requires. Access and purpose are valid, but the requested scope exceeds the minimum necessary.

AUTH-021Delegated authority covers record accesssatisfied
CONSENT-08Purpose matches recorded consentsatisfied
MIN-004Requested fields are minimum necessarynot satisfied
RET-011Retention obligation attachedapplied
allow_with_reduced_scope

Admis rewrites the request to the minimum consented fields and authorizes only the reduced-scope action.

bundle customer-data-v6
version 6.3.2
governance 9ad1…4f02
For the enterprise

Move obligations from governance into decisions.

Governance defines institutional intent. Admis Compliance applies it to the action, so compliance, legal and governance teams can manage versioned obligations, approvals and evidence while operations receive clear, actionable outcomes at runtime.

  • Standard, industry and regulatory obligation packs
  • Governed lifecycle with version and approval identity
  • Decision evidence linked to enforcement and execution
For developers

Call one decision contract, not a rule maze.

Developers supply the Action Context and obligation bundle identity. Admis evaluates the applicable controls and returns the same canonical outcome vocabulary used by Security and Decision.

  • Obligation context travels with the action
  • Rewritten arguments are the only arguments authorized
  • Reason codes stay stable across adapters

The products together

One action.
Three independent tests.

A consequential action can be secure and compliant but still too risky. It can be low risk but outside delegated authority. The point of the portfolio is not that every product blocks the same thing. It is that every relevant reason to intervene can contribute to one authoritative answer.

Illustrative action

Finance agent transfers USD 450,000 to a new vendor.

The agent is authenticated, the credential is valid and the transfer is inside the formal approval policy. The transaction is still unusual, difficult to reverse and beyond the authority delegated for unattended execution.

Admis Security

No compromise or active threat. Credential and identity evidence are valid.

satisfied
Admis Decision

Material consequence, low reversibility and concentrated downside require additional authority.

intervenes
Admis Compliance

Policy permits the transfer only after the designated approver binds to the exact action.

condition applies
One canonical determinationallow_with_human_approvalHost pauses · approval binds · edited action re-evaluates

Two ways in

Built for the institution.
Installable by the developer.

The products meet different buyers at the same control boundary. Enterprise teams gain governed authority across the agent estate. Developers gain a small, explicit integration contract that does not force a new model, framework or cloud.

Enterprise teams

Start with evidence from your own agents.

Adopt one product or the portfolio. Prove how it would behave before granting production authority.

  1. Connect a consequential workflow and the evidence systems it already uses.
  2. Run in Shadow to see which actions each product would permit, constrain, escalate or stop.
  3. Authorize Enforce explicitly, by environment, through the host-native control point.
  4. Scale across platforms with one policy lifecycle, decision ledger and assurance posture.
Request enterprise access
Developers

Protect one action in minutes.

Begin locally with the Runtime and one integration surface. Add institutional services when the system moves into production reliance.

  1. Install the developer preview: pip install admis.
  2. Wrap a tool call through middleware, the MCP Gateway or the Decision API.
  3. Inspect the canonical outcome and Admissibility Trace in the tools you already use.
  4. Carry the same contract into hosted, hybrid or private deployment.
Start building

Independent decision authority for consequential AI-agent action. Security, Decision and Compliance through one canonical core.

Choose your first control problem

Start with one.
Govern as one.