One of them will be something it shouldn't. Aegara records every one, so you know which and when. Never the contents.
Draft a reply to this support ticketREAD crm.tickets
Summarize last quarter's board deckREAD drive.documents
Who owns this account?READ crm.contacts
Pull everything we have on this employeeREAD hr.compensation
Clean up this spreadsheetTRANSFORM finance.forecast
What is our refund policy?READ docs.policies
Send this summary to the partner channelWRITE slack.external
Find similar past incidentsREAD vector.incidents
Remember this customer prefers emailSTORE memory.thread
Compare these two candidatesREAD hr.applications
Escalate this one to legalROUTE agent.legal
Rewrite this in plainer languageTRANSFORM docs.draft
The red ones are worth a look.
Every action any AI system takes is one of six. That is the whole vocabulary, and it holds whether the work happens in OpenAI, Bedrock, a LangChain agent or something you wrote yourself.
Something invokes a model. Aegara records which one, which service asked for it, how many tokens it took and how long it ran. Not a word of the prompt.
The record holds the field names, never the values. email and plan are ordinary. This is an agent reading from a system it is meant to use.
A support agent reaching into salary_band is the moment worth catching, and the field name alone is enough to catch it. The number inside never left your environment, so there was nothing for us to see and nothing for us to lose.
Summaries, translations, reformatting, redaction. The record says a transformation happened and what went into it, which is how you tell a rewrite from a rewrite that quietly dropped a restriction.
Anything written to memory, a cache or a vector store outlives the conversation. Restricted data read once is an incident. Restricted data remembered is a standing one.
Files, emails, records, API calls, other agents. This is the only step where the data actually leaves, which is why it is the one you want a name and a timestamp on.
No prompt, no response, no file and no value reaches Aegara. The record is built inside your own environment and only the record is sent.
Anything that reads a value runs on your side of the line. When our detectors inspect a field they do it inside your process, and what comes back is a verdict: which detector matched, on which field, how confident. The values stay with you.
The alarm is the product. The record behind it is the evidence, and it is waiting the moment you go looking.
gpt-4o0.00ssalary_band from the HR system0.31s
Restricted. Nobody asked this agent to look there.Auto-instrumentation for seven providers, thirty more through LangChain, and a direct API for everything else.