Real-time protection & visibility for enterprise AI agents

Watch every agent.
Stop the ones that cross the line.

Parapet checks every prompt, tool call, and response your agents make — the data involved and the identity behind it — and blocks anything outside policy before it reaches Salesforce, Stripe, your cloud, or anywhere else your agents can touch.

Real-time enforcement Intent & Identity based checks Blast-radius analysis
Sarah Chen
Finance Admin · ACME
USER
↓ acting through
Invoice Agent
agent_4831
AGENT
↓ requests
issue_refund
$18,400 · Stripe
ACTION
↓ evaluated locally
Parapet Runtime
refund:create · delegated limit $10,000
12ms
DENY
Amount exceeds delegated authority
Policy 17
Agent coverage

Parapet covers the agents built on these — and plenty more.

Cloud
AWS
Azure
Google Cloud
+ more
SaaS platforms
Salesforce
ServiceNow
HubSpot
+ more
AI assistants
Claude
Codex
+ more
Agent frameworks · in-process
Microsoft Agent Framework
Google ADK
LangGraph
+ more
Protocol-level
MCP
A2A
+ more
Frontier models
Claude · Anthropic
GPT-5 · OpenAI
Gemini · Google
Llama · Meta
+ more
The authority gap

AI agents don’t just generate answers anymore. They change systems.

Identity tells you who the actor is. Observability tells you what happened. Parapet answers the question that must be decided before the consequence: is this action allowed for this identity, right now?

BEFORE AN AGENT ACTS, PARAPET ASKS FIVE QUESTIONS
Should this agent be allowed to do this, for this user, to this resource?
  1. Who is the human?
  2. Which agent is acting?
  3. What is it trying to do?
  4. What resource will it affect?
  5. Is that action within its authority?
ALLOW·DENY·REVIEW
Parapet Control

Observe. Govern. Secure. Enforce. Measure.

One control plane for the teams accountable for agent behavior, backed by enforcement in the runtime where the model and tool calls actually happen.

◎

Observe

See agents, models, tools, runs, decisions, cost, latency, and exceptions across the fleet.

◇

Govern

Apply policy, guardrails, data rules, spend limits, reviews, and compliance controls centrally.

⌁

Secure

Bind human and non-human identity to least-privilege access and bounded permissions.

↯

Enforce

Allow, deny, alter, or require review before a model or tool call executes.

↗

Measure

Track policy outcomes, token usage, spend, latency, and operational drift.

Parapet Control
47 enforcing agents
TimeUserAgentActionResourceDecisionLatency
14:08:32Sarah Cheninvoice-agentread_customerStripeALLOW8ms
14:08:35Sarah Cheninvoice-agentissue_refundStripeDENY12ms
14:07:21Mike Torressupport-agentupdate_recordSalesforceALLOW10ms
14:06:18Priya Desairesearch-agentdelete_fileGoogle DriveDENY11ms
14:05:03Alex Kimhr-agentcreate_userEntraREVIEW15ms
Policy 17

Refund authority

Permit refunds only when the acting user is in Finance, the agent has delegated refund permission, and the amount is inside the user’s authority.

DECISION CONTEXT

user.role = "finance_admin"
agent.permission = "refund:create"
amount = 18400
limit = 10000

decision = DENY

Human identity + agent identity + requested authority

Scope actions using the identity systems you already operate, then resolve the exact tool, resource, and permission the agent is attempting to use.

Sarah Chen→Invoice Agent→Stripe→refund:create
REVIEW QUEUE

Escalate sensitive actions instead of guessing.

A third outcome — REVIEW — routes selected decisions to accountable humans with the action, identity context, determining policy, and audit evidence attached.

Blast radius

Know exactly what can go wrong, from either direction.

Answer the question two ways: what can this one agent reach, and — just as important — everything that can reach one sensitive resource.

USE CASE 1 · PER-AGENT

What can this agent reach?

Answer the questions security and IAM teams actually ask: who is this agent acting for, which systems can it reach, which permissions does it hold, and what is the maximum consequence of those permissions?

TIER-1 SUPPORT AGENT

Authority map

BLAST RADIUS · MODERATE
Jira
Read issueALLOW
CommentALLOW
Delete issueDENY
ServiceNow
Read incidentALLOW
Update incidentALLOW
Delete incidentDENY
Salesforce
Read accountALLOW
Update opportunityREVIEW
Stripe
Read customerALLOW
Issue refundDENY
USE CASE 2 · PER-RESOURCE

What can reach this resource?

Flip the search: pick a resource and a permission, and see every tool and MCP server that grants it. Any agent connected to one of those servers inherits that same reach — that inherited set is the real blast radius, not just what one agent was directly assigned.

⌕ Salesforce · Opportunity · Delete
10Tools
5Official MCP servers
3Agents = blast radius
Resource → tool → MCP server → agent

Who can delete Salesforce Opportunity records

BLAST RADIUS · 3 AGENTS
RESOURCE TOOLS MCP SERVERS AGENTS Opportunity DELETE delete_opportunity bulk_delete_records admin_purge_object + 7 more tools Salesforce MCP (official) + 4 more servers support-agent ops-agent + 1 more agent

Every agent connected to one of these MCP servers inherits the ability to delete Opportunity records — that inherited set is the blast radius, not just the tools directly assigned to one agent.

Architecture

How Parapet brings agents under control

Build new agents, protect code-authored agents, or govern SaaS and desktop agents through one control plane.

Parapet architecture showing Builder, SDK Wrapping, and MCP Gateway feeding into Parapet Control, with governance, security, enforcement, measurement, enterprise integrations, and deployment options.
Real-time protection & visibility

See what every agent is doing. Stop what it shouldn’t do — as it happens.

Parapet gives security, platform, and compliance teams continuous visibility into agent activity, and applies protection in real time, before a risky action or an unsafe response reaches a person or a system.

◈Content-based checks

Inspect prompts, tool arguments, and model responses in real time, then map the outcome to the compliance frameworks your teams already report against.

Data protection / PII
Profanity & unsafe content
Secrets in context
  • Sensitive data detectionREALTIME
  • Profanity / unsafe contentREALTIME
  • Compliance framework mappingREPORTING
⌁Identity-based checks

Authorize every action against who is asking and who is acting — human user and non-human agent identity — to enforce least privilege and limit blast radius.

Role & attributes
Agent (NHI) identity
Goal & intent
  • User authorization (role, attributes)REALTIME
  • Agent / non-human identity authorizationREALTIME
  • Goal- and intent-scoped permissionREALTIME

Parapet also applies post-response evaluation — groundedness checks, SLM judges, and human review — using the same runtime context, and can convert any decision into a regression test.

A control plane built around decisions

Every denied action becomes evidence, not a mystery.

Fleet inventory, review queues, policy, evals, cost, and decision detail all connect back to the same runtime event. That gives security, platform, IAM, and audit teams one shared view of agent authority.

Decision-level auditHuman review queueRegression evals
FLEET OVERVIEW

Production agents

Live
Agents47
Calls today8.4k
Denied184
Review23
AgentPolicyDeniedStatus
invoice-agentgen 1284.3%ENFORCING
support-triagegen 1281.1%ENFORCING
claims-agentgen 1278.9%REVIEW
Developers

Ask your coding agent to add it.

The default way to bring Parapet into a project is the Parapet MCP. Point Claude Code — or another coding agent — at it, and just ask in plain English. No hand-written integration, no hunting through docs to wire up the SDK yourself. A Python SDK and framework-specific packages are there too, for teams who want to wire it in directly.

# install the Parapet MCP
$ pipx install parapetai-mcp
$ parapetai-mcp init

# register it with Claude Code
$ claude mcp add parapet \
  -e PARAPETAI_CONTROL_PLANE_URL=https://app.parapet.run \
  -- parapetai-mcp serve

# then just ask, in plain English:
#   "add Parapet to this project"
# install the runtime SDK
$ pip install parapetai-agent

from parapetai_agent import GovernedAgent

agent = GovernedAgent(
    name="support",
    tools=[lookup_order],
    agent_id="pa-…",
)

# model + tool calls now pass through policy
from parapetai_agent import GovernedAgent as Agent

agent = Agent(
    name="support",
    tools=[lookup_order],
    agent_id="pa-…",
    control_plane_url="https://app.parapet.run",
)

# a denied tool call never executes
Proof, not a diagram

Same agent. Same model. Same requested action.

In the existing Parapet demo, the model makes the same destructive choice in both runs. The difference is whether the tool call crosses an authorization boundary before it reaches the database.

WITHOUT PARAPET

delete_records("4471")

12,405 → 0

The requested action executes. The model’s choice becomes the production consequence.

VS
PARAPET GOVERNED

delete_records("4471")

DENY

The same requested tool call is stopped in-process before the tool runs.

Enterprise trust

Give autonomy a boundary your security team can explain.

Parapet is designed around deterministic policy, fail-closed enforcement, existing identity systems, minimal telemetry, and deployment choices that meet the agent where it runs.

Content-minimized by default

Decision records carry structured context and policy results without requiring prompt or response text in the control plane.

Identity-aware

Use the human and non-human identities your enterprise already issues, then enforce action-level authority on top.

Fail-closed runtime

Authorization stays in the action path. Missing or invalid policy does not silently become permission.

Runs where your agents already do

Parapet-hosted, your own AWS, Azure, or Google Cloud account, or fully on-prem and Kubernetes — deployed alongside the agents and data it governs.

FAQ

Questions buyers should not have to hunt for.

What exactly does Parapet control?

Parapet governs model and tool calls inside an agent runtime, using identity and action context to decide whether a call is allowed, denied, modified, or routed for review.

How is this different from observability?

Observability explains what happened. Parapet’s differentiating job is to make a deterministic authorization decision before a consequential action executes, then retain the decision as evidence.

How is this different from guardrails?

Traditional guardrails focus on content. Parapet includes content checks and post-response evaluation, but leads with identity-scoped authorization of actions against tools and resources.

What happens if I cannot modify the agent code?

Use the MCP / gateway path as a compatibility option. It preserves the common Control plane and policy model while giving up some of the context available to the in-process SDK.

Do prompts and model responses have to leave my runtime?

The product’s current public posture is content-minimized by default: the control plane can receive decision metadata and telemetry without prompt and response text. Final production wording should continue to match the exact deployed telemetry configuration.

Let agents act.
Keep authority bounded.

Runtime authorization your security, IAM, platform, and audit teams can explain.