The Governed Action Layer

Agents that take
action. Under control.

Retrieval answers questions. The work is in the doing. Praxis lets agents take real, reversible, fully-audited actions across the systems you already run — with a governance gate on every step.

Deploy anywhere — your cloud, partner-managed, on-prem, sovereign Model-agnostic Open core
GOVERNANCE GATElive
01Validate & scope to callerauto
02Injection & taint guardauto
03Risk-tiered approvalhuman
04Idempotency · kill-switch · rate capauto
05Execute · auto-rollback on failuresaga
06Hash-chained tamper-evident auditsigned
The completion gap

Everyone can answer. Almost no one can act safely.

The market converged on copilots that retrieve and summarize. But resolving an incident, issuing a refund, or suspending a compromised account means changing a system of record — and that is exactly where trust, permission, and reversibility have to live.

Retrieval-first tools

Answer, then hand back to a human

The agent finds the runbook and drafts a reply. A person still does the work, re-checks permissions, and hopes nothing was missed. Value stops at the suggestion.

Praxis · action-first

Act, with a gate on every step

The agent proposes a step; Praxis validates it, scopes it to the caller, requires human sign-off on high-risk actions, executes, and can undo it — leaving a verifiable record.

How it works

One gate. Every action. Whether the agent is yours or someone else's.

Praxis federates over the systems you run rather than replacing them. Bring your own agents (via MCP or A2A) or use the prebuilt library — every action they take passes the same gate, and is metered, reversible, and signed.

FEDERATE

Don't own the data — act on it

Eleven production connectors (ServiceNow, Jira, Slack, Okta, Salesforce, Zendesk, PagerDuty, and more). Praxis is the action plane across them, not another system of record.

connectors · MCP server · A2A · voice channel
SCOPE

An agent can never exceed its caller

Per-agent identities with delegation; every action is scoped to the intersection of the agent's grant and the user's. RBAC in, segregation-of-duties enforced on approval.

agent identity · delegation chain · SoD
REVERSE

Saga-style rollback by design

Writes register their compensators; if a later step fails, completed actions are automatically undone. Reversibility is a first-class property, not an afterthought.

compensation · kill-switch · rate caps
PROVE

An audit you can verify, not just read

Every step is written to a hash-chained ledger. Any later edit or deletion breaks the chain — and a single call proves it. Trust that doesn't depend on trusting the vendor.

tamper-evident · DLP-redacted · durable
Why Praxis

The things the incumbents still don't have.

Parity is table stakes — Praxis has the conversational front door, the agent control tower, model routing, DLP, and consumption pricing. The difference is in what they can't offer.

DEPLOY-ANYWHERE

Not a hosted black box

The same zero-dependency build runs as SaaS, in your own cloud account, in a partner-managed cloud (e.g. operated for you by Accenture), fully on-prem, or in a sovereign enclave. Deployment is a config choice, not a sales exception.

GUARDRAIL-PASS^k

We benchmark the governance

τ²-bench measures whether the agent succeeds. Nobody measures whether the guardrails do. Praxis publishes Guardrail-Pass^k — reliability of block / approval / SoD / dedup / rollback across repeated runs.

OPEN-CORE

Inspect the kernel you're trusting

The governance kernel is open and self-hostable. Security teams can read exactly how the gate works rather than taking a datasheet's word for it.

MODEL-AGNOSTIC

Your model, your perimeter

Frontier API or a self-hosted open-weights model behind your firewall — same gate, same audit. No data has to leave the boundary you choose.

Deployment profiles

Runs where you need it to run.

SaaS
Praxis-hosted, multi-tenant. Fastest start.
Customer cloud
Your own cloud account / VPC. Data stays with you.
Partner-managed
Operated for you by an SI such as Accenture.
On-prem
Your data center. Self-hosted model. Air-gappable.
Sovereign
In-jurisdiction enclave, open weights, BYO keys.
Pricing

Subscription plus metered action.

A fixed platform subscription with a generous bank of included governed actions; consumption beyond that is metered. Enterprise and Sovereign are typically tailored.

Starter
$2,500/mo
50,000 actions included · $0.03 overage
  • Up to 25 seats
  • 5 connectors
  • Governance gate + tamper-evident audit
  • DLP redaction
  • Operator console
Start →
Growth
$12,000/mo
300,000 actions included · $0.02 overage · 99.9% SLA
  • Up to 100 seats
  • 15 connectors
  • Everything in Starter, plus:
  • SSO, conversational assistant
  • Model routing, voice channel
Choose Growth →
Enterprise
$45,000/mo
1.5M actions included · $0.015 overage · 99.95% SLA
  • Up to 500 seats
  • Unlimited connectors
  • Everything in Growth, plus:
  • A2A, Agent Studio, Control Tower
  • Custom connectors, dedicated support
Talk to sales →
Sovereign
Custom
from $90,000/mo · dedicated · 99.95%+
  • Unlimited seats
  • Everything in Enterprise, plus:
  • On-prem / air-gapped
  • Self-hosted model, BYO keys
  • Data-residency & compliance support
Contact us →
A handful of Enterprise + Sovereign deployments is multi-million ARR. Overage is metered per governed action; budgets cap spend at the gate.
Security & trust

Built for teams that have to answer to a regulator.

Tamper-evident audit

Hash-chained, append-only ledger. Independently verifiable; any edit breaks the chain.

Data masking (DLP)

PII and secrets are redacted before anything is written to the ledger or sent to a model.

Tenant isolation

Every run, approval, and audit row is org-scoped; kill-switch and rate caps are per-tenant.

RBAC + agent identity

Roles resolve to scopes; agents act under delegated identities bounded by the caller.

Policy-as-code

Governance is a versioned, git-reviewable document — not clicks in a vendor console.

Compliance roadmap

Designed toward SOC 2 / ISO 27001 / DPDP, and aligned to the EU AI Act control expectations.

See an agent act —
and watch the gate hold.

We'll run a live incident in your environment, with a high-risk action held for your approval and the whole thing on a verifiable ledger.

Request access Read the architecture →