Watch every agent.
Stop the ones that cross the line.
Parapet checks every prompt, tool call, and response your agents make — the data involved and the identity behind it — and blocks anything outside policy before it reaches Salesforce, Stripe, your cloud, or anywhere else your agents can touch.
Finance Admin · ACMEUSER
agent_4831AGENT
$18,400 · StripeACTION
refund:create · delegated limit $10,00012ms
Amount exceeds delegated authorityPolicy 17
Parapet covers the agents built on these — and plenty more.
AI agents don’t just generate answers anymore. They change systems.
Identity tells you who the actor is. Observability tells you what happened. Parapet answers the question that must be decided before the consequence: is this action allowed for this identity, right now?
- Who is the human?
- Which agent is acting?
- What is it trying to do?
- What resource will it affect?
- Is that action within its authority?
Observe. Govern. Secure. Enforce. Measure.
One control plane for the teams accountable for agent behavior, backed by enforcement in the runtime where the model and tool calls actually happen.
Observe
See agents, models, tools, runs, decisions, cost, latency, and exceptions across the fleet.
Govern
Apply policy, guardrails, data rules, spend limits, reviews, and compliance controls centrally.
Secure
Bind human and non-human identity to least-privilege access and bounded permissions.
Enforce
Allow, deny, alter, or require review before a model or tool call executes.
Measure
Track policy outcomes, token usage, spend, latency, and operational drift.
| Time | User | Agent | Action | Resource | Decision | Latency |
|---|---|---|---|---|---|---|
| 14:08:32 | Sarah Chen | invoice-agent | read_customer | Stripe | ALLOW | 8ms |
| 14:08:35 | Sarah Chen | invoice-agent | issue_refund | Stripe | DENY | 12ms |
| 14:07:21 | Mike Torres | support-agent | update_record | Salesforce | ALLOW | 10ms |
| 14:06:18 | Priya Desai | research-agent | delete_file | Google Drive | DENY | 11ms |
| 14:05:03 | Alex Kim | hr-agent | create_user | Entra | REVIEW | 15ms |
Refund authority
Permit refunds only when the acting user is in Finance, the agent has delegated refund permission, and the amount is inside the user’s authority.
user.role = "finance_admin"
agent.permission = "refund:create"
amount = 18400
limit = 10000
decision = DENY
Human identity + agent identity + requested authority
Scope actions using the identity systems you already operate, then resolve the exact tool, resource, and permission the agent is attempting to use.
Escalate sensitive actions instead of guessing.
A third outcome — REVIEW — routes selected decisions to accountable humans with the action, identity context, determining policy, and audit evidence attached.
Know exactly what can go wrong, from either direction.
Answer the question two ways: what can this one agent reach, and — just as important — everything that can reach one sensitive resource.
What can this agent reach?
Answer the questions security and IAM teams actually ask: who is this agent acting for, which systems can it reach, which permissions does it hold, and what is the maximum consequence of those permissions?
Authority map
What can reach this resource?
Flip the search: pick a resource and a permission, and see every tool and MCP server that grants it. Any agent connected to one of those servers inherits that same reach — that inherited set is the real blast radius, not just what one agent was directly assigned.
Who can delete Salesforce Opportunity records
Every agent connected to one of these MCP servers inherits the ability to delete Opportunity records — that inherited set is the blast radius, not just the tools directly assigned to one agent.
How Parapet brings agents under control
Build new agents, protect code-authored agents, or govern SaaS and desktop agents through one control plane.
See what every agent is doing. Stop what it shouldn’t do — as it happens.
Parapet gives security, platform, and compliance teams continuous visibility into agent activity, and applies protection in real time, before a risky action or an unsafe response reaches a person or a system.
Inspect prompts, tool arguments, and model responses in real time, then map the outcome to the compliance frameworks your teams already report against.
- Sensitive data detectionREALTIME
- Profanity / unsafe contentREALTIME
- Compliance framework mappingREPORTING
Authorize every action against who is asking and who is acting — human user and non-human agent identity — to enforce least privilege and limit blast radius.
- User authorization (role, attributes)REALTIME
- Agent / non-human identity authorizationREALTIME
- Goal- and intent-scoped permissionREALTIME
Parapet also applies post-response evaluation — groundedness checks, SLM judges, and human review — using the same runtime context, and can convert any decision into a regression test.
Every denied action becomes evidence, not a mystery.
Fleet inventory, review queues, policy, evals, cost, and decision detail all connect back to the same runtime event. That gives security, platform, IAM, and audit teams one shared view of agent authority.
Production agents
| Agent | Policy | Denied | Status |
|---|---|---|---|
| invoice-agent | gen 128 | 4.3% | ENFORCING |
| support-triage | gen 128 | 1.1% | ENFORCING |
| claims-agent | gen 127 | 8.9% | REVIEW |
Ask your coding agent to add it.
The default way to bring Parapet into a project is the Parapet MCP. Point Claude Code — or another coding agent — at it, and just ask in plain English. No hand-written integration, no hunting through docs to wire up the SDK yourself. A Python SDK and framework-specific packages are there too, for teams who want to wire it in directly.
# install the Parapet MCP $ pipx install parapetai-mcp $ parapetai-mcp init # register it with Claude Code $ claude mcp add parapet \ -e PARAPETAI_CONTROL_PLANE_URL=https://app.parapet.run \ -- parapetai-mcp serve # then just ask, in plain English: # "add Parapet to this project"
# install the runtime SDK $ pip install parapetai-agent from parapetai_agent import GovernedAgent agent = GovernedAgent( name="support", tools=[lookup_order], agent_id="pa-…", ) # model + tool calls now pass through policy
from parapetai_agent import GovernedAgent as Agent agent = Agent( name="support", tools=[lookup_order], agent_id="pa-…", control_plane_url="https://app.parapet.run", ) # a denied tool call never executes
Same agent. Same model. Same requested action.
In the existing Parapet demo, the model makes the same destructive choice in both runs. The difference is whether the tool call crosses an authorization boundary before it reaches the database.
delete_records("4471")
The requested action executes. The model’s choice becomes the production consequence.
delete_records("4471")
The same requested tool call is stopped in-process before the tool runs.
Give autonomy a boundary your security team can explain.
Parapet is designed around deterministic policy, fail-closed enforcement, existing identity systems, minimal telemetry, and deployment choices that meet the agent where it runs.
Decision records carry structured context and policy results without requiring prompt or response text in the control plane.
Use the human and non-human identities your enterprise already issues, then enforce action-level authority on top.
Authorization stays in the action path. Missing or invalid policy does not silently become permission.
Parapet-hosted, your own AWS, Azure, or Google Cloud account, or fully on-prem and Kubernetes — deployed alongside the agents and data it governs.
Start with proof. Move to runtime enforcement when you’re ready.
Questions buyers should not have to hunt for.
What exactly does Parapet control?
Parapet governs model and tool calls inside an agent runtime, using identity and action context to decide whether a call is allowed, denied, modified, or routed for review.
How is this different from observability?
Observability explains what happened. Parapet’s differentiating job is to make a deterministic authorization decision before a consequential action executes, then retain the decision as evidence.
How is this different from guardrails?
Traditional guardrails focus on content. Parapet includes content checks and post-response evaluation, but leads with identity-scoped authorization of actions against tools and resources.
What happens if I cannot modify the agent code?
Use the MCP / gateway path as a compatibility option. It preserves the common Control plane and policy model while giving up some of the context available to the in-process SDK.
Do prompts and model responses have to leave my runtime?
The product’s current public posture is content-minimized by default: the control plane can receive decision metadata and telemetry without prompt and response text. Final production wording should continue to match the exact deployed telemetry configuration.
Let agents act.
Keep authority bounded.
Runtime authorization your security, IAM, platform, and audit teams can explain.