RESOURCES

Everything you need to deploy Spctre with confidence.

References for engineering and compliance teams: how Spctre works, what it produces for auditors, and how it protects your data.

FAQ How Spctre works AGT The governance model Compliance What auditors get Security How your data is protected
FAQ

Common questions

Do we need to change our agent framework?

No. Spctre is stack-neutral. You can start with CLI hooks, SDK ingestion, REST calls, MCP tools, or framework adapters without migrating to a new runtime. Start in observe mode to build confidence, then move selected agents to enforcement when your policy workflow is ready.

How long does integration take?

Most teams have audit log ingestion running within a day. Gateway enforcement requires a policy bundle and a gateway endpoint — typical rollout is one to two weeks depending on how many runtimes you're connecting. Spctre's observe mode lets you test policies against real traffic before any enforcement goes live.

What does enforcement actually block?

Spctre evaluates the agent, connector, action, environment, and runtime context against your active policy bundle. A DENY halts the action and records the decision. A REVIEW pauses the workflow and routes it to a human approver before the action can proceed. An ALLOW records the decision and lets the agent continue.

What audit records are kept for each decision?

Every decision record includes the agent identity, connector, action, environment, runtime target, matched policy references, reviewer state, decision status, timestamp, and artifact hash of the active policy bundle. Review decisions additionally store the approver identity, rationale, and resolution time.

Can Spctre support human review before an agent acts?

Yes. REVIEW decisions pause the workflow, route the action to a named approver, and preserve the full claim, resolution, reviewer identity, rationale, and policy references in the operations ledger. Approvers can act from the Spctre UI or via API.

What does Spctre not do?

Spctre governs agent actions — it does not train models, route LLM traffic, or manage cloud infrastructure. It also does not replace your provider invoices: cost and token figures in the dashboard are directional governance telemetry, not billing records.

AGT

The governance model

Stack-neutral

Spctre evaluates agent actions through a normalized surface called the Agent Governance Target (AGT). Regardless of which framework, model, or cloud your agents run on, Spctre maps each action to the same structure — agent, connector, action, environment, runtime target, and policy context — so policies and audit logs are consistent across your entire fleet.

Decision gateway

A low-latency enforcement point that evaluates each action against your active policy bundle and returns ALLOW, DENY, or REVIEW with policy references and trace IDs. Designed to sit inline without adding meaningful latency to your agent workflows.

Policy bundle

A versioned, hashed artifact containing the rules a runtime enforces. Every bundle is linked to a branch, revision, reviewer, and simulation log — so you can prove which policy was active at the time of any decision.

Observe to enforce

Start with audit log ingestion and framework watch mode. Policies run against real traffic without blocking anything. Move individual runtimes to gateway enforcement or human review as your confidence grows — at your own pace.

Human review queue

REVIEW decisions pause the agent workflow and route the action to a named approver. The approver sees the full decision context, approves or rejects, and the outcome is recorded in the operations ledger with their identity and rationale.

Supported runtimes

AWS Bedrock, Google ADK, Azure AI, OpenAI Agents, LangChain, CrewAI, AutoGen, Claude, Codex, Gemini, MCP, REST, and custom agent infrastructure. If a runtime can describe its agent, tool, action, and environment, it can be mapped into Spctre.

Custom targets

Internal tooling and proprietary agent frameworks can be integrated via REST or the SDK. Spctre's normalized AGT model means your internal agents get the same audit and enforcement coverage as off-the-shelf runtimes.

Compliance

What auditors get

Audit-ready exports

Spctre produces exportable compliance packets containing policy references, runtime targets, artifact hashes, reviewer chains, timestamps, and decision records. An auditor can inspect exactly how any agent action was governed — who approved it, which policy applied, and what the outcome was.

HIPAA

Spctre records which policy permitted access to a PHI-adjacent connector, who reviewed exceptions, and what redaction or retention rules applied. Decision records are scoped per tenant and exportable for covered-entity audits.

SOC 2

Policy change history, reviewer decisions, bundle artifact hashes, and gateway outcomes export directly as evidence for access control, change management, incident response, and monitoring trust service criteria.

ISO 27001

Audit logs covering access management, change control, supplier integrations, and operational review are structured, timestamped, and exportable — ready to map against Annex A controls.

GDPR

Spctre logs the connector scope, data access context, and policy reference for every agent action. Retention windows are configurable per workspace, and audit records can be purged on request without breaking the structural log.

PCI DSS

Spctre records connector scope, environment boundaries, and reviewer state for payment-adjacent actions. Compliance packets confirm that sensitive card data boundaries were enforced at the policy layer, not just assumed.

NIST AI RMF

Traceable policies, monitored runtime decisions, human review paths, and operating logs satisfy Govern, Map, Measure, and Manage functions — giving risk teams documented evidence that AI controls are active and auditable.

FedRAMP and public sector

Spctre enforces strong tenant isolation, configuration provenance, and credential scoping. Audit logs and compliance packets are exportable in formats suitable for regulated public-sector review.

Compliance packets

Export a structured packet for any decision window: policy refs, runtime targets, artifact hashes, reviewer chains, timestamps, and outcomes — everything an auditor needs to verify how your agents were governed without requiring direct system access.

Encryption

How your data is protected

  • All audit logs and policy records are transmitted over TLS and encrypted at rest using managed database encryption.
  • Policy bundle artifact hashes are stored and surfaced to customers — policy provenance is independently verifiable without trusting Spctre's internal state.
  • API tokens and service account credentials are never logged or included in audit records.
  • Tenant data is fully isolated — no cross-tenant access is possible at the query or storage layer.
Data privacy

What Spctre stores — and what it doesn't

  • Spctre captures decision context — agent, connector, action, policy match, outcome — without storing action payload data unless you explicitly configure payload capture.
  • Sensitive values in action context can be redacted at the gateway before the record is written, preserving the structural log without retaining the sensitive content.
  • Audit records are scoped by tenant, workspace, environment, and runtime target — reviewers only see the records their role permits.
  • Retention windows are configurable per workspace and connector risk model, with deletion applied at the record level on schedule or on request.