DAMN / Governance

How far the control actually goes.

The failure modes it covers, the mechanism underneath, and the exact point where each control stops.

Failure modes

Real failures need a real system.

AI agents move fast. Mistakes, drift and attacks move just as fast.

Leaked keys & access

Keys resolve server-side and access is enforced there, never on the agent.

Destructive actions

Payments, deletions and production writes are gated: refused, or held for a human.

Runaway spend

Cap monthly cost per agent, team or workspace. Cross the cap and the key stops working.

Audit gaps

Every action on a tamper-evident, hash-chained trail.

Access drift

Enterprise

Every agent tied to your identity provider through SSO, SAML and SCIM.

Data exfiltration

Enterprise

Outbound limited to the hosts you allow. Everything else has no route out.

No inventory project

The map draws itself.

You do not map your systems for us. Connect an agent in observe mode and Damn builds its access map from real activity: what it reached, which credentials it used, and who ran it. Over-broad access gets flagged with the fix attached.

Scoping stops being a project and becomes a review.

The Systems reachability graph: native agents reaching governed APIs, and connected agents reaching APIs nobody governs

The control layer

One control layer for every agent.

One registry, one identity for each worker, one policy engine, one approval pipeline, one tamper-evident audit trail. Built in-house or connected from outside, every agent answers to the same five.

Built here

Ops agents

LegalFinanceOps

Connected

Coding agents

Claude CodeCursorCodex

Connected

Vendor agents

AgentforceServiceNow

One control layer

RegistryIdentityPolicyApprovalsAudit
Runs on your infrastructure.Your data never leaves.

The mechanism

Hold the keys, not the conversation.

We govern the access: credentials, network destinations, execution, files. We do not read the prompts, the code, or your data. That is a design choice, not a limitation, and it is why this runs in places a content-inspecting product structurally cannot.

Default reads nothing. An optional tier can inspect, and it runs on your box behind your own certificate authority. Content never reaches us either way. We enable inspection. We never perform it.

Governed by Damn
Keys
APIs
Databases
Internet
Execution
Never read by Damn
Prompts
Code
Data

The work stays private.

Control the access. Not the content.

Guardrails

Hard rules, checked first.

Block or ask, evaluated before anything else, even for an agent you trust. Change a rule once and it applies immediately, with no redeploy and no rollout.

And you can fire them on demand to prove they still hold, including with the connection cut.

Guardrails: block-or-ask rules, and a check that fires each one to prove it is enforced

Governance model

Detected, observed, gated, contained.

The product tells you exactly which tier each agent is in. We never blur the line between what we observe and what we enforce.

Detected

The agent exists and has an owner. Not yet reporting, not yet gated. The gap the registry surfaces first.

Observed

Its activity is attributed and recorded, on a trail nobody can rewrite.

Gated

A key, a destination, a file or an action is decided before it is used. Refused, or held for a human.

Enterprise

Contained

The execution environment enforces the boundary. Keys short-lived, outbound limited to hosts you allow.

Contained mode

When the boundary has to be the environment.

On the Enterprise tier the agent runs inside a box we provide. Credentials injected short-lived, outbound limited to the hosts you allow, everything else with no route out. No change to how your developers work.
Damn-governed boxfail-closed
🤖Coding agentworking normally
keys
via Damn · short-lived
internet
via Damn · allowlist
No standing keys. The only door out is Damn.

Sovereignty

On your servers. Never ours.

Your agents, their permissions, and their audit trail stay inside your boundary. Your machines, your models, your data. Nothing leaves your perimeter.

Outside your control

ChatGPT
Claude
Copilot
Public cloud
Data never crosses this line

Your perimeter

Your agents
Your data
Your models

Everything runs here. Nothing leaves.

Your agents. Your rules. Your data.

Damn secure.