Roadmap
Prove one complete control loop, then expand
The first year should prove a narrow but complete control loop, earn enterprise trust, then expand breadth. Resist building every detector or connector before the core identity-policy-enforcement architecture is reliable.
Twelve months
Phased delivery
Months 0-3
Foundation: tenant security, canonical schemas, agent registry, initial discovery, identity binding, policy engine, generic API gateway, audit events and developer docs.
Months 4-6
MVP: OpenAI/Anthropic or equivalent model integrations, Entra/Okta, GitHub/cloud discovery, MCP gateway, human approvals, kill switch, policy simulation and first design-partner pilots.
Months 7-9
Enterprise: DLP, secrets broker, incident cases, SIEM exports, FinOps attribution, compliance mappings, stronger data residency/retention, first SaaS business-system connectors.
Months 10-12
Scale: anomaly detection, advanced delegation, broader connectors, policy-as-code maturity, enterprise reporting, partner program and repeatable sales/implementation motion.
Milestones
- Month 3: internal dogfood and architecture security review complete.
- Month 6: production MVP with first governed customer workflows.
- Month 9: enterprise evidence/FinOps expansion live.
- Month 12: repeatable enterprise sale + implementation + expansion motion.
Success metrics
- Production agents governed
- Paid enterprise tenants
- Protected actions/day
- Net retention / expansion pipeline
Launch and commercial gates
- Launch checklist: production threat model; tenant-isolation tests; incident response plan; backup/restore test; gateway failover test; key rotation; privacy/retention controls; trust center; terms/DPA; support escalation; billing; status page; customer runbooks; security contact; vulnerability disclosure.
- Commercial gates: 5-10 design partners, 3+ paid references, repeatable POV, measurable enforcement value, pricing validated, implementation under target duration.
- Product gates: protect at least two agent ecosystems and two enterprise tool categories; every critical action attributable; policy replay works; kill switch meets SLA.
REFERENCE BASELINE
NIST AI RMF 1.0 and 2026 revision work; NIST SP 800-207 Zero Trust Architecture; NIST 2026 concept paper on software/AI-agent identity and authorization; ISO/IEC 42001:2023 AI management systems; OWASP Top 10 for Agentic Applications 2026; European Commission AI Act guidance for GPAI obligations and 2026 enforcement.