VegaDūta

Platform · Trust

Governance: who approved it, what it cost, where it is logged

Governance on VegaDūta answers three questions about any agent action: did a person have the chance to stop it, was its cost bounded, and is there a record. A confirmation gate sits in front of sensitive tools, budgets cap spend per user and per run, and an audit log records what happened.

These controls are platform settings, not prompt instructions, so they hold whether or not the model follows its prompt.

By the VegaDūta team · Last updated

In short

  • VegaDūta asks for confirmation before an agent runs a tool classified as sensitive, even when the agent is otherwise set to act on its own.
  • Spend is bounded at three levels: a per-user daily budget, a cap on tool calls per turn, and a shared per-run budget for multi-agent delegation.
  • Every platform action is written to an audit log that workspace admins can read as a live tail, and LLM calls emit OpenTelemetry GenAI spans.

Confirmation before sensitive tools

Built-in tools are classified by what they can do. When an agent is about to call a tool classified as sensitive, the call waits for a person to confirm it, even on an agent set to act autonomously. Approval policies can also be set per tool, including tools that come from MCP servers, and pending approvals appear on the dashboard and in the admin console.

Budgets at three levels

A per-user daily budget caps what one person's conversations can spend. A limit on tool calls per turn stops a tool loop from running indefinitely. Multi-agent delegation draws on one shared budget per run, and the run stops with a stated reason when it is used up. Each turn's estimated cost is shown in the run graph.

Audit log and traces

Platform actions are written to an audit log, and workspace admins can watch it as a live tail in the admin console. LLM and tool calls emit OpenTelemetry spans that follow the GenAI semantic conventions, carrying the model and token usage, which is what feeds the platform's own tracing.

Workspace SSO and SCIM

A workspace can connect its own identity provider for single sign-on and use SCIM to provision and remove users. Both are available. They have not yet been validated against each identity vendor's product, so plan a test with yours before a rollout.

Frequently asked questions

Can I make an AI agent ask before it uses a tool?

Yes. Tools classified as sensitive wait for a person's confirmation by default, and approval policies can be set per tool. The agent proposes the call, a person approves or rejects it, and the decision is logged.

How do I cap what AI agents spend?

Set per-user daily budgets, and rely on the platform's limit on tool calls per turn and the shared per-run budget for multi-agent delegation. A run that reaches its budget stops with a stated reason.

Is there an audit log of agent actions?

Yes. Platform actions are recorded in an audit log, and workspace admins can read it as a live tail in the admin console.

Does VegaDūta support SSO and SCIM?

Workspace single sign-on and SCIM provisioning are available. They have not yet been validated against each identity vendor's product, so test with your provider before relying on them.

Sources

See it working in two minutes

The sandbox provisions a real tenant — describe an agent in one sentence and test it, no account, no card. Or browse ~90 industry workflow recipes to see what teams build.

Related

Explore VegaDūta