Elanter is coming soon. We’re opening a small design partner programme for banks, government entities and regulated enterprises. Register your interest →
Coming soon · Now accepting design partners

Trust and control for autonomous agents. Yours, and everyone else’s.

Elanter decides, before it happens, whether an AI agent may take an action: on whose authority, for what purpose and within what limits. It works for the agents you run and for the agents other organisations send to you.

Live decisions · example
issue_refundOur payments agent · AED 340
ALLOW
issue_refundOur payments agent · AED 18,500
APPROVE
add_payeeA customer’s own assistant
CHALLENGE
read_account_statementPartner’s agent · not its client
BLOCK
update_supplier_bank_detailsInstruction came from an email
BLOCK
The shift

A new kind of actor is working inside your organisation.

Your systems were built to authenticate people and applications. AI agents are different: they reason, choose tools, pursue goals and act on someone else’s behalf. Logging in isn’t the hard part. Deciding what they may do is.

Should this actor be allowed to perform this action, right now, on behalf of this principal, for this purpose?The one question Elanter answers, every time an agent acts.
Two problems, one engine

Control your agents. Trust external agents.

Agent governance
“Can we safely give our own agents more autonomy?”
  • Register every agent with an owner, a credential and a mandate
  • Grant only the authority each agent needs, with limits
  • Send sensitive actions to the right person to approve
  • Watch sessions for mission drift; pause or stop them instantly
  • Keep a complete, replayable record of every decision
External agent trust
“Can we safely let someone else’s agent transact with us?”
  • Verify who the agent is and which company operates it
  • Check whose authority it carries, and that it’s real
  • Give it short-lived access, bound to one mission
  • Check ownership against your records, not the agent’s word
  • Share signed evidence of what was agreed with the other side

Both run on the same identity, policy, approval and audit engine. External trust is an extension of governance, not a second product.

See it decide

Every action, checked before it happens.

Pick an agent, then step through what it tries to do. These are illustrative scenarios with fictional organisations.

How it works

Elanter decides. Your infrastructure enforces.

Elanter is a control plane. It decides who may act, on whose authority, for what mission and within what limits, then hands that decision to the enforcement points you already run.

IdentityWho is acting?
→
AuthorityOn whose behalf?
→
MissionFor what purpose?
→
Risk & policyAllowed here, now?
→
Human approvalWho must decide?
→
EvidenceCan we prove it?
Enforced throughAPI gatewaysMCP and tool gatewaysIdentity and access managementAgent sandboxes and runtimesKubernetesYour own systems of record

Allowed actions receive a single-use permit, valid for seconds and bound to one agent’s key and one exact action. Your systems check the permit themselves, so there’s no way around the decision.

Four verdicts

Not just yes or no.

ALLOW

Proceed. Within the agent’s authority. A short-lived, single-use permit is issued.

APPROVE

A human decides. The agent prepares; a named role, or the customer, approves.

CHALLENGE

Prove it first. Proceeds once specific verification is obtained, such as the customer confirming.

BLOCK

Not permitted. Nothing reaches your systems, and the reason is recorded.

Design partners

Shape Elanter around your riskiest agent workflow.

We’re working with a small number of banks, government entities and regulated enterprises. Bring one high-consequence workflow; we’ll model its authority, run it through Elanter and show you every decision.

Platform

One trust engine for every agent action.

Identity, delegated authority, mission, policy, human approval and evidence, in one control plane that plugs into the infrastructure you already run.

Mandates

Authority, written down.

A mandate lists what an agent may do on its own, what needs a person, what needs extra proof and what it may never do. Anything not listed is refused.

  • Limits on amounts, records and scope
  • A named owner for every agent
  • Versioned, so every past decision can be explained
  • Changed by the business, not by engineers
Mandate v3 · payments servicing agent
issue_refund≤ AED 2,000ALLOW
issue_refundabove AED 2,000APPROVE
add_beneficiarycustomer confirmsCHALLENGE
export_customer_recordsneverBLOCK
Delegations

Know whose authority an agent carries.

When a customer’s or partner’s agent arrives, Elanter checks the delegation behind it. You set the most that may ever be delegated; the principal grants within that; policies tighten it further.

  • Granted and revoked in your own channels, never through the agent
  • Limits the principal controls
  • The principal can be the approver
  • An agent can never widen its own authority
Chain of authority
1 · You set the outer limitdelegation profile
2 · The principal grants within itin your app or portal
3 · Policies tighten at runtimeorganisation-wide
= What the agent can actually doENFORCED
Policies

Guardrails that only ever tighten.

Organisation-wide rules react to the situation: where an instruction came from, how much, how many records. The strictest answer always wins, so adding a rule never gives an agent more power.

  • Maker–checker review for every change
  • Replay recent decisions against a draft before it goes live
  • One rule protects every agent, yours and external
Impact of a draft policy · last 30 days replayed
Decisions re-evaluated5,412,880
Would become stricter241
Would become looser0
Illustrative figures
Sessions & permits

Control while it runs, not just at the door.

Each session is one agent, one mission, one principal. Elanter watches for drift from the declared mission and can pause a session automatically. Every allowed action gets a permit that expires in seconds and works once.

  • Automatic pause when an agent drifts off mission
  • Kill switch that revokes every open permit
  • Replayed, late or copied permits are refused by your systems
Mission drift · one session
Paused automatically above the threshold
Evidence

Prove what happened, and why.

Every decision records the exact mandate, delegation and policy versions it used, so it can be replayed and explained months later. Across organisations, both sides sign the same receipt.

  • Append-only decision record
  • Replay any decision against its original rules
  • Signed cross-organisation receipts that reveal any tampering
  • Exports for auditors and regulators
Receipt · supplier invoice
totalAED 94,000✓ both copies
remit_tocopies differHELD
Illustrative: a compromised supplier agent signed a different account
Fits your stack

Model-neutral, framework-neutral.

Any agent that can make an HTTP request can ask Elanter first. Enforcement runs through adapters for the gateways, identity systems and runtimes you already use.

Decision API

One call before any consequential action. Structured request in, verdict with reasons and permit out.

Enforcement adapters

API and MCP gateways, identity and access management, agent sandboxes, Kubernetes. Elanter decides; they enforce.

Operator console

Agents, mandates, delegations, approvals, live sessions, permits and audit, in one place.

Solutions

Start with the workflow that would hurt most if an agent got it wrong.

Financial services

Let agents move money, safely.

Servicing, payments, lending and customers’ own assistants.

Give servicing agents real autonomy on routine work, keep maker–checker on large amounts, and admit customers’ AI assistants without opening a fraud channel.

Refunds up to a set amount on the agent’s own ticketALLOW
Larger refunds and credit-limit increasesAPPROVE
New beneficiary or payee, from any agentCHALLENGE
Payment details changed because of an emailBLOCK
A customer’s assistant trying to raise its own limitBLOCK
Government

Faster services, with authority kept where it belongs.

Licensing, permits, inspections, complaints and disbursements.

Agents can prepare and process; officials decide what the law says officials must decide. Businesses’ own agents and service providers can transact, but only for the companies that authorised them.

Routine renewal: active licence, no changes, compliance clearALLOW
Adverse decisions, large event permits, published classificationsAPPROVE
Contact or manager changes on a licenceCHALLENGE
Signatory change instructed by an uploaded documentBLOCK
A service provider’s agent reading another company’s fileBLOCK
Enterprise

Autonomy in operations, without losing control of spend.

Procurement, suppliers, ERP and finance operations.

Give each agent a mission and a budget. Elanter keeps it on mission, escalates judgement calls and stops the classic frauds before they reach your ERP.

Purchase orders with approved suppliers, within mission budgetALLOW
Onboarding a new supplierAPPROVE
Supplier bank details changed from an inbound emailBLOCK
Agent drifting far from its missionSESSION PAUSED
Between organisations

When agents do business with agents.

Customers, suppliers, partners and other authorities.

Each side verifies the other’s agent independently, and both sign the same record of what was agreed. If a counterparty’s agent is compromised, the difference shows immediately.

Mutual verification before any exchangeALLOW
Counterparty agent changes where money is sentCHALLENGE
Receipts that don’t match on both sidesHELD
Security & trust

A control layer has to be more trustworthy than what it controls.

Deterministic decisions

No language model sits in the decision path. The same request, under the same rules, always gets the same answer, and every answer can be replayed.

Fails closed

If Elanter can’t evaluate a request safely, or can’t record the decision, the answer is no. It never defaults to allowing.

Least authority by default

Agents get only what their mandate or delegation grants. Anything not listed is refused, and policies can only narrow it further.

No bypass on protected paths

Allowed actions carry a signed, single-use, seconds-long permit bound to one agent’s key. Your systems verify it themselves.

Agents’ claims are claims

What an agent says about itself is recorded as agent-asserted. Hard limits rely on your own records and signed credentials, not on the agent telling the truth.

Deployed where your data must stay

Designed to run as a managed service, in your private cloud or on premises, including in-country deployments for data-residency requirements.

Being straightforward

Where we are today.

Elanter is in its design-partner phase. The decision engine, mandates, policies, approvals and decision records run today; enforcement adapters, external-agent federation and cross-organisation receipts are being built with partners. We’ll always tell you which is which.

Company

Trust, whenever an autonomous agent acts.

Regardless of who owns the agent or where it operates.

Why we exist

Agents are becoming economic actors.

When software can act on someone’s behalf, every organisation needs a reliable way to decide which agents to trust, whose authority they carry and what they may do. That can’t be rebuilt inside every system, by every company, for every counterparty.

Where we’re going

  • Now: govern the agents organisations run themselves
  • Next: admit agents that customers and partners send
  • Then: neutral trust infrastructure for agents transacting between organisations
Global, with a regional start

Built for regulated institutions everywhere.

We’re starting with banks, government entities and regulated enterprises in the Gulf, where demand for sovereign deployment and high-assurance controls is strong, and building for customers worldwide.

Coming soon · Design partner programme

Bring us your riskiest agent workflow.

Elanter isn’t generally available yet. We’re working closely with a small number of organisations before launch. Register your interest and we’ll be in touch.

What you get

  • Your workflow modelled as mandates, delegations and policies
  • A working environment where your agents ask Elanter first
  • Every decision explained and replayable for your risk and audit teams
  • Direct influence on the roadmap and early access pricing

What we ask

  • One high-consequence workflow and its owner
  • A few hours a month from risk, security and the business
  • Honest feedback