Aureon AI Control Plane · SAFR-aligned

Runtime governance for AI agents in finance.

A governance checkpoint between every agent decision and its execution. Aureon implements the four SAFR components — Agent Identity, Controls Repository, Disposition Engine and Audit Log — so every autonomous action is authorised, evaluated and recorded before it reaches your bank's systems.

SAFR — Safeguards for Agentic Finance at Runtime — is an industry reference framework. Aureon is a productized implementation, deployable on-prem or in your VPC.
Why runtime governance

Existing frameworks weren't built for agents.

Model risk management assesses the model before it goes live. Audit reviews sampled transactions hours after execution. Neither catches a problematic agent decision before it executes. When agents move from recommendation to autonomous action, governance has to move to runtime.

Pre-execution assurance is missing

MRM is calibrated to pre-deployment. Audit is retrospective. By the time an issue appears in the log, the action has already occurred.

Human-in-the-loop is ad hoc

No standard for when a human should decide. Notifications, email alerts, dashboard flags — no defined deadline, no audit record. Oversight without substance.

Guardrails aren't governance

Content filters and prompt defences reduce error classes at the model's output. They don't enforce structural, numerical or policy constraints on financial actions.

The SAFR framework

A governance checkpoint between every agent decision and its execution.

Four components. One Governance Envelope. Four defined outcomes. No agent action reaches execution without being declared, authorised, evaluated and logged.

Agent Identity

Binds every proposed action to a registered agent. Verified against the registry before any other evaluation proceeds. Cryptographic identity, short-lived, tied to version and environment.

Controls Repository

The institution's configurable rulebook. Authority. Exposure limits. Rate limits. Evidence quality. Regulatory constraints. Mandate-based delegation from the human principal.

Disposition Engine

Evaluates each proposed action deterministically. Resolves to one of four outcomes. Deterministic controls first — LLMs may assist interpretation but do not become the final authority.

Audit Log

Tamper-evident, append-only record of every governance decision. Reconstructs any action, any decision, without relying on the agent's account of what occurred.

Action lifecycle

Every action, packaged and evaluated.

Before an agent can execute, the proposed action is packaged in a Governance Envelope — action, action trace, context metadata. The envelope carries what the agent intends to do, how it reached that proposal, and the state of the world when it did.

Governance Envelope — inbound to Disposition Engine
ACTION

Type: payment.initiate
Value: USD 45,000
Counterparty: registered vendor
Purpose: Q3 invoice

ACTION TRACE

Tool calls: vendor.lookup, invoice.verify
Data: invoice_v3.pdf
Checks run: duplicate scan, sanction screen

CONTEXT METADATA

Agent: treasury-payments-v2
Principal: CFO
Mandate: AP-2026-089
Balance: USD 1.2M

Every action arrives at the Disposition Engine as a signed, structured envelope — no reconstructable-after-the-fact governance.

Four dispositions. One per action.

The Disposition Engine resolves every in-scope action to one of four outcomes, calibrated to the action's reversibility, materiality, customer impact, regulatory sensitivity and novelty.

Deny

Violates a hard regulatory or policy constraint, or exceeds a defined risk threshold. Rejected before execution. Reason recorded.

Escalate

In scope, below hard constraints, but above the threshold for autonomous execution. Held pending human review — with a deadline, a record, and a defined reviewer.

Auto-Execute

Within scope, below hard constraints, within risk thresholds. Proceeds without human intervention. Fully logged.

Observe

Permitted to proceed but flagged. Executes while a structured observation is logged for subsequent review. Used for signals worth watching without blocking.

The control panel

Every agent. Every action. One view.

Not a log dashboard. A live control layer with intervention authority — revoke tools, reduce limits, escalate, activate kill switch.

Aureon Runtime · Live Control Panel
All agents operational
Agent Risk Tier Hallucination Refusal Kill
Treasury PaymentsHigh0.02%3.1%
Underwriting AssistantHigh0.08%1.4%
AML TriageHigh0.01%2.7%
Customer Q&A (RAG)Med0.31%8.2%
Doc SummarisationMed0.12%4.9%
Complaint ClassifierLow0.04%0.9%

Illustrative dashboard · Every disposition, escalation, override and kill-switch event is logged and reviewable.

Two ways to integrate

Native for new agents. Gateway for existing ones.

SAFR supports two integration patterns. New builds get tighter governance; existing agents can be brought under governance without re-engineering them.

Pattern 1 · Native Integration

For new agent builds.

The agent emits a Governance Envelope before each proposed action. Aureon Runtime evaluates and returns a disposition before the agent takes any action. Tightest integration, most granular record, cleanest audit trail.

  • SDK for Python, TypeScript, Java, .NET
  • Emit envelope pre-action, receive disposition, act accordingly
  • Any modern-API agent instrumented in a day
  • Recommended for greenfield deployments
Pattern 2 · Gateway Integration

For existing and third-party agents.

The Aureon gateway intercepts outbound API calls at the infrastructure layer, wraps each call in a Governance Envelope, and evaluates it — without any changes to agent code. Bring existing agents under governance without re-engineering.

  • Zero-code integration for legacy agents
  • Establishes coverage first; native follows for new builds
  • Works for vendor-supplied AI and fintech partner models
  • Recommended when modifying agent code isn't feasible
SAFR in production

Industry patterns you'll recognise.

SAFR patterns are already being deployed across financial services. Below: six representative implementations documented in the SAFR white paper — showing that the four-component model is not theoretical.

Ant International · Agentic Treasury Protocol

Digital Agent Passport for identity. Machine-readable mandates for authority. Circuit breakers at agent, principal or counterparty level. Ambiguous instruction → agent defaults to inaction.

Mastercard · Agent Pay

Agentic Token bound to consumer-granted scope (merchant, amount, timeframe). Cryptographic identity binding to operator and end-user. Verifiable Intent framework for tamper-resistant authorisation records.

Visa · Intelligent Commerce (VIC)

Passkey (FIDO biometric) confirmation → digital rule stored on the Visa network. Agent cannot modify limits; any excess is declined at the network layer. All key moments recorded by design.

Circle · Agent Wallet

Portable, verifiable identity on-chain (ERC-8004). Per-transaction and aggregate spending caps in policy layer. Compliance Engine screens against sanctions before execution. Append-only audit trail reconciled with on-chain settlement.

OCBC / Bank of Singapore · SOWA

Narrowly-scoped source-of-wealth memo agent. Documents assessed, plausibility check by human at critical decision point. Standardised structured memo as the institution's record of the assessment.

Manulife · GenAI Sales Enablement

Per-request adviser identity. Retrieval-controlled content. LLM-as-a-Judge evaluation against SME-curated answers. Out-of-scope or low-confidence → blocked or escalated. No autonomous execution into financial systems.

Source: SAFR white paper, July 2026. Aureon Runtime implements the same four-component pattern as a shipping product.

Where SAFR sits

Between the agent and the execution environment.

SAFR is not a replacement for guardrails or settlement compliance. It sits between them, at the runtime layer where the disposition happens.

LAYER 1 · AGENT

Content filtering, prompt defences, model-output guardrails. Governs what the model produces.

LAYER 2 · SAFR / AUREON RUNTIME

Pre-execution governance. Envelope, identity, controls, disposition, audit. Governs whether the action may proceed.

LAYER 3 · EXECUTION / SETTLEMENT

Payment rails, SWIFT, card networks, ACH, core banking. Governs how value actually moves once submitted.

Regulator-mapped

Aligned to the frameworks banks answer to.

SAFR (Industry Reference) MAS MindForge RBI MRM 2026 (AI Chapter) RBI FREE-AI IMDA MGF Agentic EU AI Act DORA NIST AI RMF FSB AI Systemic Risk ISO/IEC 42001

Aureon Runtime maps to SAFR component-by-component. See our SAFR explainer for details.

Under the hood

Four modules power the Control Plane.

Aureon Control Plane is not a single monolith. It is composed of four bank-grade modules, each addressing one part of the runtime governance problem.

MODULE

Aureon Core

AI Registry and Control Graph. Canonical inventory, authority model, dependency graph, shared platform objects. The identity substrate.

MODULE

Aureon Policy

Control Intelligence. Converts regulation, policy and risk appetite into testable, enforceable controls. This is the Controls Repository.

MODULE

Aureon Runtime

Financial AI Action Control. Real-time disposition, tool gateway, human-approval pause, kill switch. This is the Disposition Engine.

MODULE

Aureon Assure

Workflow and Recommendation Assurance. Inline control for copilots, workflow agents and semi-autonomous decisions — the mid-tier of oversight.

Design principles

Six choices that shape how the Control Plane behaves.

Control actions, not labels

A control applies according to the action, authority and customer impact — whether the system is called a model, copilot, workflow or agent.

Less transparency, less authority

Third-party or black-box services receive narrower permissions, stronger monitoring and compensating controls. Explainability degrades authority.

Deterministic controls first

Rules, policies, limits and approvals are enforced deterministically. LLMs may assist interpretation but do not become the final policy authority.

Evidence by design

Every evaluation, approval, runtime check, override and outcome is stored in a reconstructable evidence chain — not reconstructed after the fact.

Bank-controlled deployment

On-prem, bank VPC or hybrid. Production data does not leave the institution. No third-party AI calls in the control path.

Integrate rather than replace

Aureon consumes signals from model, observability, security and workflow tools — and converts them into financial action assurance.

How it's different

Not observability. Not MRM. Runtime governance.

Guardrails / LLM safetyAI observabilityTraditional MRMAureon Runtime
Where it actsModel outputPost-execution logsPre-deploymentPre-execution, at every action
Deterministic dispositionProbabilisticReactiveNot runtimeDeny / Escalate / Auto / Observe
Kill switch / interventionLogs onlyGraduated: revoke tools → suspend → kill
Agent identity bindingPartialCryptographic, per-action
Governance Envelope Signed and structured
SAFR-alignedComponent-by-component
Better together

Also running classical models?
Pair with Aureon MRM.

Runtime governance for AI agents. Lifecycle governance for classical models. Same audit trail, same evidence, same regulator-ready reporting fabric.

Explore Aureon MRM →
Free · No commitment

Try Aureon on your own portfolio.

Two ways to start. No sales-cycle overhead. On your premises or in your VPC.

No commitment On-premises or your VPC Results in days, not months