AI agent governance. Govern what your teams' AI agents can do.
Control how your teams use AI agents across business systems, with security policies and audit logs in one place.
INV-2041NetSuite -
Lena OrtizFinanceChatGPT
Allowed Returns the vendor bill.Decided byConnector accessFinance shares this NetSuite account -
Priya ShahProcurementClaude
Masked Returns the bill with bank details hidden.Decided byPermission PoliciesProtect bank details · Enforce -
Sam RiveraOperationsClaude Code
Refused Sam left yesterday. The call is refused.Decided bySSO and SCIMDeactivated in Okta
AI agent governance case study. Nine business systems connected in under two weeks.
A US medical research organisation rolled out agents across IT and finance, with access set per connector and per account.
Healthcare · Customer story "The granular access at the account level for a connector is a huge help. So now I feel confident that we can create connectors to everything."
Configure access. Set access for teams and individual users.
Choose who can connect each system, who can use shared connections, and what their agents can read or change.
Connector profile
Connection setup and available actions
The new connection uses this profile's action selection.
Connected account
An existing connection to a business system
Account Members can run its available actions.
Policies apply when an agent acts for a member
Assign further restrictions to users or groups with account access.
Explore Permission PoliciesSync members and groups from your directory. Manage their access grants in StackOne.
Explore SSO and SCIMChoose accounts and available actions
Define actions through connector profiles. Share profiles for new connections, or grant access to accounts already connected.
Explore Connector AccessSet rules for member-based calls
Use Permission Policies to restrict tools, prevent changes to protected fields or mask returned data. API-key calls use separate access arrangements.
Explore Permission PoliciesAuthentication and response protection. Protect credentials and check tool responses.
StackOne authenticates calls to business systems. Enable Prompt Injection Guard to inspect returned content for prompt injection.
The leading prompt injection model checks responses before your agent reads them.
Explore Prompt Injection GuardObservability and audit. See what agents did and who changed the setup.
Find action outcomes, changes to StackOne and security activity in the relevant logs.
| User / Agent | System / Action | Outcome / Checks |
|---|---|---|
| Taylor Brooks | SAP S/4HANA | 200 2 Clean |
| Noah Patel | Jamf Pro | 200 2 Clean |
| Alex Morgan | Workday | 200 3 Clean |
| Lena Ortiz | Salesforce | 200 2 Clean |
| Priya Shah | Xero | 403 3 Not run |
| Sam Rivera | ServiceNow | 201 2 Clean |
| Alex Morgan | Workday | 200 3 Clean |
- User / Agent
- Taylor Brooks
via Copilot
- Account
- Supplier Admins
- User / Agent
- Noah Patel
via Claude Code
- Account
- IT Support
- User / Agent
- Alex Morgan
via Claude
- Account
- People Operations
- User / Agent
- Lena Ortiz
via Copilot
- Account
- Revenue reporting
- User / Agent
- Priya Shah
via Claude Code
- Account
- Finance
- User / Agent
- Sam Rivera
via Claude Code
- Account
- IT requests
- User / Agent
- Alex Morgan
via Claude Code
- Account
- People Operations
Use logs in your own reporting and investigations
Retrieve action and platform records through the Logs API and forward them through your pipeline.
Deployment and compliance. Choose the deployment that fits your requirements.
Compare managed cloud with regional projects, a dedicated account and self-hosting.
Plan residency and operations
Discuss where StackOne runs, who operates it and how encryption keys are managed.
Explore DeploymentSOC 2 Type II security review. Evidence for your security review.
"As a company rooted in security assurance, we needed a partner sharing our priorities. StackOne's approach gave us confidence to scale without compromise."
SOC 2 Type II
Request the report, and review subprocessors and security information, in our trust centre.
Visit the trust centreFAQ. Questions about AI agent governance
See how StackOne fits your AI rollout.
Talk through the systems your teams use and the controls your rollout needs.