Enterprise Add-on - Early Access

Governance for agents
you've already built.

Matimo Governance wraps around your existing Matimo Workbench agents. Zero code changes. It activates in Shadow Mode first - so you see exactly what governance would block before anything is actually blocked.

7-step gate, under 5ms
Shadow Mode safe activation
SSO / SAML / SCIM
SOC2 / HIPAA / GDPR exports
Matimo Governance — 7-Step Execution Gate < 5ms PER EXECUTION
Gate Mode
👁 Shadow Mode
Emergency Stop
Identity
🔑 ECDSA token
1
License check
Non-enterprise tenants exit instantly - zero overhead
PASS
2
Emergency Stop check
If active, ALL agents blocked immediately
PASS
3-6
Identity · Lifecycle · Budget · Spawn depth
ECDSA identity, active/suspended status, monthly budget, recursion limit
CHECKING
7
Policy rules
Custom YAML - ALLOW / DENY / ALLOW_WITH_CONDITIONS
QUEUED
Governance Health
Score92 / 100 · A
ModeShadow
Shadow denies14 this week
Emergency StopInactive
Policies9 active
Shadow Mode
🛡 Nothing blocked yet All decisions logged as shadow_deny
Flip to Enforce when ready

You activate it on agents
you've already built.

Nothing about how your agents are coded changes. Governance runs in the execution layer, not the agent layer - which means adoption doesn't require a rebuild, and rollback doesn't require one either.

See before you block

Shadow Mode evaluates every policy on every execution and logs what would have happened - without blocking anything. You see the blast radius before you ever flip the switch.

One button stops everything

Emergency Stop blocks all agent executions across the entire workspace instantly, from the admin dashboard. No deployment required to pull the plug.

Audit evidence on demand

Policy definitions, gate decisions, HITL approvals, and identity records export in one click - built for the moment an auditor or regulator actually asks.

Everything the compliance
conversation actually needs

Matimo Governance is not a policy document - it's an execution-layer gate, an identity system, and an audit trail, wired directly into every Matimo Workbench agent.

7-Step Execution Gate — Under 5ms

Every agent action passes through: license check, Emergency Stop check, agent identity, lifecycle status, monthly governance budget, spawn-depth limit, and policy rules - evaluated in sequence, in real time.

License check Identity Budget Policy rules

Shadow Mode

All policies evaluate on every execution. DENY decisions log as shadow_deny - nothing is actually blocked until you flip a single switch to Enforce.

Safe activation

Emergency Stop

One button in the admin dashboard blocks all agent executions instantly - in progress or new. Persists until an admin clears it. No deployment required.

Instant kill switch

Agent Identity Tokens

Cryptographic ECDSA identity assigned to every agent - proves which agent performed which action, when. Revoking an agent takes effect within milliseconds.

ECDSA Non-repudiation

Agent Soul Documents

A versioned, self-knowledge document per agent - identity, purpose, memory, and behavioral contract. Every change is SHA-256 hashed. Behavioral contract changes require HITL approval.

Versioned HITL-gated changes

Policy Engine

16 built-in policy templates, plus custom YAML rules tested against time, agent risk level, trigger source, LLM model, and spawn depth. Simulate against historical logs before publishing; conflict detection flags contradictions first.

16 templates Simulation

Governance Health Score

A 0–100 score with an A–F grade, covering identity registration, Shadow vs Enforce status, policy coverage, Emergency Stop state, and shadow-deny rate. New tenants reach a healthy score in 15 minutes.

0–100 · A–F grade

Identity Federation

SSO via Okta, Azure AD, Google Workspace, or any SAML 2.0 / OIDC provider. SCIM 2.0 auto-provisioning, JIT provisioning on first login, and LDAP directory sync - all live today.

SSO / SAML / OIDC SCIM 2.0

Content Inspection, Compliance Exports & SIEM Streaming

PII and secret detection plus prompt-injection risk scoring on every request and response. One-click compliance evidence export for SOC2 Type II, HIPAA, and GDPR. Real-time event streaming to Splunk, Datadog, Elastic SIEM, or any webhook-capable tool.

PII detection SOC2 / HIPAA / GDPR SIEM streaming

Wraps around Matimo
Workbench - not inside it.

Matimo Governance sits at the execution layer, between your Matimo Workbench agents and the outside world. It doesn't change how agents are built in Matimo Studio or via the API - it governs what happens when they run.

Every Matimo Workbench agent already inherits Matimo OSS's tool RBAC and audit logging. Matimo Governance adds the centralised policy registry, identity federation, and compliance evidence layer regulated enterprises need on top.

Explore Matimo Workbench →
Matimo Workbench
Matimo Workbench — Your Agents
Agent building · Studio workflows · Execution runtime
▼ gated by
Matimo Governance — 7-Step Gate
Identity · Lifecycle · Budget · Policy rules · Under 5ms
▼ reports to
📋
Compliance & SIEM
SOC2 / HIPAA / GDPR exports · Splunk · Datadog · Elastic

Built for the people
who answer for the agents

CISO / Compliance Officer

Wrap existing agents with a real governance gate

A 7-step governance gate, Shadow Mode safe activation, Emergency Stop, agent identity tokens, and one-click SOC2/HIPAA/GDPR compliance export - on agents that are already running.

IT / Identity Teams

Federate identity without custom integration work

SSO across Okta, Azure AD, and Google Workspace, SCIM 2.0 provisioning, JIT on first login, and LDAP sync - identity management your team already runs, extended to every agent.

Engineering Leaders

Adopt governance without a rebuild

Zero code changes to activate. Shadow Mode shows the blast radius before enforcement. Governance Health Score gives your team a single number to track as coverage matures.

What the gate
actually checks

<5ms
Execution gate overhead per agent action - 7 checks, evaluated in sequence, in real time
16 templates
Built-in policy templates, plus custom YAML rules with simulation and conflict detection
0-100 score
Governance Health Score with an A-F grade across identity, mode, coverage, and review recency
3 frameworks
One-click compliance evidence export for SOC2 Type II, HIPAA, and GDPR
Enterprise Add-on - Early Access

Ready to see what
governance would block?

Request Matimo Governance and activate Shadow Mode on your existing Matimo Workbench agents - no code changes, no risk of blocking anything until you're ready.

Already on Matimo Workbench? Add Matimo Governance to your workspace.