RESOURCES

Everything you need to deploy Spctre with confidence.

References for engineering and compliance teams: how Spctre works, what it produces for auditors, and how it protects your data.

FAQ How Spctre works AGT The governance model Compliance What auditors get Security How your data is protected Compare Tool and platform comparisons Glossary Agent governance definitions
FAQ

Common questions

Do we need to change our agent framework?

No. Spctre is stack-neutral. You can start with CLI hooks, SDK ingestion, REST calls, MCP tools, or framework adapters without migrating to a new runtime. Start in observe mode to build confidence, then move selected agents to enforcement when your policy workflow is ready.

How long does integration take?

Most teams have audit log ingestion running within a day. Start in observe mode, then move selected actions to gateway enforcement after validating policy impact against real traffic.

What does enforcement actually block?

Spctre evaluates the agent, connector, action, environment, and runtime context against your active policy bundle. A DENY halts the action and records the decision. A REVIEW pauses the workflow and routes it to a human approver before the action can proceed. An ALLOW records the decision and lets the agent continue.

What audit records are kept for each decision?

Every decision record includes the agent identity, connector, action, environment, runtime target, matched policy references, reviewer state, decision status, timestamp, and artifact hash of the active policy bundle. Review decisions additionally store the approver identity, rationale, and resolution time.

Can Spctre support human review before an agent acts?

Yes. REVIEW decisions pause the workflow, route the action to a named approver, and preserve the full claim, resolution, reviewer identity, rationale, and policy references in the operations ledger. Approvers can act from the Spctre UI or via API.

What does Spctre not do?

Spctre governs agent actions — it does not train models, route LLM traffic, or manage cloud infrastructure. It also does not replace your provider invoices: cost and token figures in the dashboard are directional governance telemetry, not billing records.

AGT

The governance model

Stack-neutral

Spctre brings agent activity into a normalized surface called the Agent Governance Target (AGT). Adapters, gateways, and configured evidence integrations map reported activity to the same structure: agent, connector, action, environment, runtime target, and policy context, so policies and audit logs stay consistent across your fleet.

Decision gateway

A low-latency enforcement point that evaluates each action against your active policy bundle and returns ALLOW, DENY, or REVIEW with policy references and trace IDs. Designed to sit inline without adding meaningful latency to your agent workflows.

Details

A low-latency enforcement point that evaluates each action against your active policy bundle and returns ALLOW, DENY, or REVIEW with policy references and trace IDs. Designed to sit inline without adding meaningful latency to your agent workflows.

Policy bundle

A versioned, hashed artifact containing the rules a runtime enforces. Every bundle is linked to a branch, revision, reviewer, and simulation log — so you can prove which policy was active at the time of any decision.

Details

A versioned, hashed artifact containing the rules a runtime enforces. Every bundle is linked to a branch, revision, reviewer, and simulation log — so you can prove which policy was active at the time of any decision.

Blueprint

An agent's operating envelope: the tasks, tools, connectors, budgets, approvals, and runtime targets one agent is permitted, bound to a specific policy revision. Blueprints are reviewed and published like policy, and the gateway stops connector or tool actions a published Blueprint never declared.

Details

An agent's operating envelope: the tasks, tools, connectors, budgets, approvals, and runtime targets one agent is permitted, bound to a specific policy revision. Blueprints are reviewed and published like policy, and the gateway stops connector or tool actions a published Blueprint never declared.

Observe to enforce

Start with framework watch mode or a mapped evidence integration to capture real activity without blocking. Move individual runtimes to gateway enforcement or human review as your confidence grows at your own pace.

Details

Start with framework watch mode or a mapped evidence integration to capture real activity without blocking. Move individual runtimes to gateway enforcement or human review as your confidence grows at your own pace.

Human review queue

REVIEW decisions pause the agent workflow and route the action to a named approver. The approver sees the full decision context, approves or rejects, and the outcome is recorded in the operations ledger with their identity and rationale.

Details

REVIEW decisions pause the agent workflow and route the action to a named approver. The approver sees the full decision context, approves or rejects, and the outcome is recorded in the operations ledger with their identity and rationale.

Supported runtimes

AWS Bedrock, Google ADK, Azure AI, OpenAI Agents, LangChain, CrewAI, AutoGen, Strands, the Claude Agent SDK, MCP, REST, and custom agent infrastructure — most with a zero-code spctre watch adapter. Agent CLIs are covered by hooks and skills for Claude Code, Codex, Gemini CLI, and Antigravity. Existing systems can also map JSON events, CloudEvents, NDJSON, or OTLP logs into Spctre.

Details

AWS Bedrock, Google ADK, Azure AI, OpenAI Agents, LangChain, CrewAI, AutoGen, Strands, the Claude Agent SDK, MCP, REST, and custom agent infrastructure — most with a zero-code spctre watch adapter. Agent CLIs are covered by hooks and skills for Claude Code, Codex, Gemini CLI, and Antigravity. Existing systems can also map JSON events, CloudEvents, NDJSON, or OTLP logs into Spctre.

Custom targets

Internal tooling and proprietary agent frameworks can be integrated via REST, the SDK, or configured evidence mappings. Bring existing JSON events, CloudEvents, or OTLP logs into the same governance model without building a bespoke runtime adapter.

Details

Internal tooling and proprietary agent frameworks can be integrated via REST, the SDK, or configured evidence mappings. Bring existing JSON events, CloudEvents, or OTLP logs into the same governance model without building a bespoke runtime adapter.

Compliance

What auditors get

Audit-ready exports

Spctre produces exportable compliance packets containing policy references, runtime targets, artifact hashes, reviewer chains, timestamps, and decision records. These evidence artifacts help teams collect proof and map controls for audit preparation:

HIPAA Evidence Support

Spctre records policy permissions, exception reviews, and redaction rules to support covered-entity HIPAA audit preparation. Decision records are scoped per tenant and exportable as evidence.

Details

Spctre records policy permissions, exception reviews, and redaction rules to support covered-entity HIPAA audit preparation. Decision records are scoped per tenant and exportable as evidence.

SOC 2 Evidence Support

Policy change history, reviewer decisions, bundle artifact hashes, and gateway outcomes export directly as evidence artifacts to map against SOC 2 Trust Services Criteria for access control and change management.

Details

Policy change history, reviewer decisions, bundle artifact hashes, and gateway outcomes export directly as evidence artifacts to map against SOC 2 Trust Services Criteria for access control and change management.

ISO 27001 Evidence Support

Structured, timestamped audit logs covering access management and change control provide evidence artifacts ready to map against ISO 27001 Annex A controls.

Details

Structured, timestamped audit logs covering access management and change control provide evidence artifacts ready to map against ISO 27001 Annex A controls.

GDPR Evidence Support

Spctre logs connector scope, data access context, and policy references for every agent action, providing explainability evidence to support GDPR transparency duties.

Details

Spctre logs connector scope, data access context, and policy references for every agent action, providing explainability evidence to support GDPR transparency duties.

PCI DSS Evidence Support

Spctre records connector scope, environment boundaries, and reviewer state for payment-adjacent actions to support PCI DSS evidence collection at the policy layer.

Details

Spctre records connector scope, environment boundaries, and reviewer state for payment-adjacent actions to support PCI DSS evidence collection at the policy layer.

NIST AI RMF Evidence Support

Traceable policies, monitored runtime decisions, human review paths, and operating logs supply documented evidence artifacts to support Govern, Map, Measure, and Manage functions.

Details

Traceable policies, monitored runtime decisions, human review paths, and operating logs supply documented evidence artifacts to support Govern, Map, Measure, and Manage functions.

FedRAMP & Public Sector Support

Spctre enforces strong tenant isolation, configuration provenance, and credential scoping. Audit logs and compliance packets are exportable in formats suitable for regulated public-sector audit preparation.

Details

Spctre enforces strong tenant isolation, configuration provenance, and credential scoping. Audit logs and compliance packets are exportable in formats suitable for regulated public-sector audit preparation.

Compliance packets

Export a structured packet for any decision window: policy refs, runtime targets, artifact hashes, reviewer chains, timestamps, and outcomes — everything an auditor needs to verify how your agents were governed without requiring direct system access.

Details

Export a structured packet for any decision window: policy refs, runtime targets, artifact hashes, reviewer chains, timestamps, and outcomes — everything an auditor needs to verify how your agents were governed without requiring direct system access.

Encryption

Your governance data stays protected in Spctre Cloud.

Keep policy, audit, and review records in a control plane designed for high-trust agent operations.

  • TLS in transit and managed encryption at rest protect audit logs and policy records.
  • Policy bundle hashes give your team verifiable provenance for the rules behind a decision.
  • Sensitive credential fields are redacted from governance records.
  • Tenant-aware access controls keep teams focused on the records they are permitted to review.
Data privacy

Control what governance data Spctre receives and retains.

Choose the integrations, mappings, redaction, and retention settings that fit your data-handling requirements.

  • Decision records capture governance context such as agent, connector, action, policy match, and outcome.
  • Gateway redaction and evidence mappings help limit sensitive data before it reaches the control plane.
  • Configured evidence integrations retain submitted source events alongside their mapped governance records.
  • Workspace retention settings govern how long records remain available. Read the full Privacy Policy for data-handling details.