000
// issuing credentials…
TRUST LAYER · AGENT ERA · BY PRIMETHOUGHTS ↗

Identity & Governance for your AI Agents.

Know every agent. Prove every action. Stop any of them. Nothing inside your agents changes.

Take the ten-question passport check

verified — admitted unknown — turned away
THROUGH THE GATE
Admitted —
and on the record.
keep scrolling
01 · THE PROBLEM

Four questions your company
can't answer about its AI agents.

Q1

Who is this agent?

Agents borrow human credentials and share API keys. Impersonating one is trivial — and nobody can prove which agent did what.

Q2

What may it do?

Access is all-or-nothing. An agent allowed to read can often also write, delete, and spend. Delegation hands over far too much.

Q3

What did it do?

No tamper-evident record exists — nothing that would satisfy your security team, let alone a regulator asking questions.

Q4

What did it cost — and was it worth it?

Agent sessions burn orders of magnitude more tokens than chat, and each vendor caps spend inside its own account. Nobody ties spend to a job, an outcome and a person across all of them.

And six more your auditor will ask. → The ten-question passport check

JUL 2026

OpenAI evaluation agents ran inside Hugging Face production systems for days — nobody could say which caller to cut. Two disclosures, one lesson: agents without identities cannot be stopped one at a time.

Hugging Face disclosure, Jul 2026 ↗
JUL 2025

A coding agent deleted a production database during an explicit code freeze, then reported the change as successful. It had one credential for everything, so it could touch everything.

The Register, Jul 2025 ↗
FEB 2024

Moffatt v. Air Canada: the airline was held liable for its chatbot's invented refund policy. "A separate legal entity" was not accepted — your agent's word is your word.

2024 BCCRT 149 ↗

// none of these was a model failure — each one is an identity and authorisation failure

WHICH TRAVELLER ARE YOU?
69%
of security leaders say security concerns are slowing their AI-agent adoption
Okta / AlphaSights, Jan 2026 · n=150
65%
had at least one security incident caused by an AI agent in the past year
CSA & Token Security, Apr 2026 · n=418
109:1
machine identities per human employee — 79 of those are AI agents
Palo Alto Networks, May 2026 · n=2,930
only30%
have audit logging of what their AI agents actually did
Palo Alto Networks, May 2026 · n=2,930
02 · THE ANSWER

Now you can answer all four.
One trust layer.

L1

Passport

Every agent gets a verifiable identity anchored in your own domain — who built it, who runs it, and what it's trusted to do. Bound to the agent's own key, so a stolen copy is useless. Your systems check it in milliseconds; you revoke it in one click.

VERIFIED IN MILLISECONDS · REVOKED IN ONE CLICK
L2

Gateway

A doorman in front of the systems you already run. Your rules on every call: least privilege, human sign-off where it matters. Delegation only narrows — suspend a parent and every helper it sponsored stops within minutes.

YOUR RULES, ON EVERY CALL · DELEGATION ONLY NARROWS
L3

Proof

A tamper-evident record of every action — who, on whose authority, under which rule. Each entry fingerprints the one before it, so the past can't be rewritten quietly. Built to become a regulator-ready evidence pack — in design with EU auditors now.

EU AI ACT ART. 12 · DESIGNED FOR, NOT YET SHIPPED
L4

Budgets

What every agent costs you, before the invoice arrives — one number across every vendor and account. The budget belongs to the job, not the vendor. Walk into a renewal knowing what your estate actually consumes.

A BUDGET PER JOB · SPEND BY TEAM, AGENT AND TASK
03 · HOW IT WORKS

Install once.
Then watch the whole estate come into view.

▶ Watch the 2-minute tour · 1:56 · light and dark cuts

  1. 01 · INSTALL

    One command. Nothing else to deploy.

    Run the installer on a machine you own. It puts a local gateway — a door your agents call through — in front of the tools they already reach. Point a program at it and its calls flow through KnowMyAgents. Nothing inside your agents changes.

    terminal
    $ curl -fsSL https://knowmyagents.com/install.sh | sh
    where should it live? → a folder you choose
    registration token from your console → ••••••••
    ✓ gateway online · appears in your console
  2. 02 · SHADOW AGENTS

    The agents you didn't know you had.

    Shadow Agents. Every unidentified caller KMA sees — the crew inside your app, the script nobody remembers — surfaced the moment it makes a call, before it has a passport. Including the ones nobody authorised.

    Shadow Agents3
    • portfolio-crew / leadunidentifiedfirst seen · just now
    • portfolio-crew / analystunidentifiedfirst seen · just now
    • nightly-report.pyunidentifiedfirst seen · 4 min ago
  3. 03 · DOORS

    Doors discover themselves.

    The places your agents reach appear on their own. Approve or refuse each one — no allow-lists to maintain.

    Doorsdiscovered from traffic
    • Model API doorapprovedseen · 128 calls
    • Market-data doorapprovedseen · 41 calls
    • Web-search doornewapproverefuse
  4. 04 · PASSPORTS

    Shadow becomes identified.

    Give each agent a passport — a verifiable identity it presents at the gateway on every call. Shadow becomes identified. No passport, no access — if you say so.

    PASSPORT · SIGNED
    portfolio-crew / lead
    did:web:agents.example.com:portfolio-lead
    issueryour own domainoperatortrading platform teammayread market data · write reports
    sealed ✓
    • portfolio-crew / leadshadowidentified
    • portfolio-crew / analystshadowidentified
    • nightly-report.pyshadowidentified
  5. 05 · GUARDRAILS

    Two kinds of guardrail. Rules for structure. Charters for intent.

    New rulepickers · code · or say it in words
    Or say it in words
    Only agents with a passport may call the Market-data door. Cap spend at $200 a day.
    Draft with AICreate rule
    ✓ Drafted — passport required · per-door allow · daily spend cap

    Rules — exact and fast.

    "Only agents with a passport may call." Per-door allow or refuse. A daily spend cap. Write it in plain words and KMA drafts it for you — Draft rules with AI.

    New charterplain English
    Conduct rule
    Never trade defense-sector stocks.
    whoevery agentwhereMarket-data dooron breachrefuse
    Save & publish

    Charters — plain-English conduct rules.

    "Never trade defense-sector stocks." Judged for intent by an AI judge on every call it covers — so it catches what a hardcoded list can't.

    Rules decide access deterministically. Charters add a judged conduct check on top and never widen access.

  6. 06 · OBSERVE → ENFORCE

    Watch first. Then flip the switch.

    Watch first: every decision recorded as "would allow" or "would refuse", nothing blocked. Then flip to enforce — allowed calls pass, breaches are refused, and every decision is written down with its reason.

    Decisions
    portfolio-crew / analyst → Market-data door quote · defense-sector stock (XYZ) charter: no-defense — this request concerns a defense-sector company, which the charter prohibits.
    would refuse
    portfolio-crew / lead → Model API door completion · within budget rule: passport present · door approved · 12% of today's cap
    would allow
  7. 07 · PROOF

    Every decision, with its reason.

    Proof. Every decision recorded, tamper-evident, with the reason — including why the judge refused. One click to an evidence pack for your security review or a regulator.

    Rule & charter hitsExport evidence pack
    • #9f2c…e1 ← #7c21…a4refuseportfolio-crew / analyst · Market-data doorcharter: no-defense — the judge's reason, recorded
    • #7c21…a4 ← #b3d0…58allowportfolio-crew / lead · Model API doorrule: passport present
    • #b3d0…58 ← #12e7…9crefuseunknown caller · Web-search doorrule: no passport, no access
    each entry fingerprints the one before it — change the past and the chain visibly breaks
  8. 08 · YOUR DATA

    Your data stays yours.

    Your data stays yours. The full audit record — every request and reply detail — lives on your own machine, in the Local Viewer. The hosted console sees only metadata: who called, which door, allowed or refused, why, what it cost. The content never leaves your network.

    LOCAL VIEWER
    Stays on this machine — your full audit record
    • every request
    • every reply
    • full detail
    HOSTED CONSOLE
    Synced to the console — metadata only
    • who called
    • which door
    • allowed or refused
    • why
    • what it cost

Enforcement never depends on the console. If it goes dark, your gateways keep working.

THE CONSOLE IS A WINDOW · THE GATEWAY IS THE DOOR
THE WORDS ON THIS PAGE
Doorman · gateway
The same thing. The small service the installer puts on your machine. Your agents' calls go through it, and it applies your rules.
Door
A place an agent calls — a model API, a data feed, a tool. Doors appear on their own as agents use them.
Shadow Agent
Any caller the doorman has seen but can't identify yet. Seen, not proven.
Passport
A verifiable identity for one agent, issued by you. Presented at the door on every call. Shadow becomes identified.
Rule
An exact guardrail: who may call which door, spend caps, approvals. Fast and precise.
Charter
A conduct rule in plain English, judged for intent by an AI judge on every call it covers.
Observe · enforce
Observe records what would happen and blocks nothing. Enforce makes it real.
Local Viewer · console
The Local Viewer is on your machine and holds the full record. The hosted console shows every machine from metadata only.
04 · THE TOUR · 1:56

The whole product,
in two minutes.

Sign-up, one-command install, doors, Shadow Agents, passports, rules and charters, observe → enforce, proof, and the Local Viewer — the eight steps above, on the real screens.

tour.mp4● light and dark cuts

Prefer to read? The eight steps above are the tour, in words. Want the case behind it? The argument ↓

05 · TRY THE DOOR

Two agents knock.
Only one gets in.

A simulation of the checks the doorman runs on every real call: is there a passport, is it genuine, is it revoked, what do the rules say.

Pick an agent and send its request to the doorman. Watch it work.

┌─ THE DOORMAN ── awaiting request…
06 · ADOPTION

Fifteen minutes to your first answer.

This is what the first afternoon looks like — no sales call needed.

YOU RUN AGENTS

Platform, DevEx and security teams. Your coding-agent rollout is stuck in security review, or your first surprise token bill just landed. Within a week you can answer who, what, and how much.

YOU BUILD AND SELL AGENTS

Agent platforms, ISVs and AI product companies. Your enterprise deals stall on one security questionnaire: what can your agents do, and how would you prove it? Give every agent you ship a verifiable passport, and hand your buyer a record instead of an assurance — without changing your product.

YOU WANT TO SEE FIRST

Point one coding-agent session at the doorman and watch what appears. Most teams find agents they never authorised inside the first hour.

01

Run the doorman

One command. Point a program at it. Nothing else to deploy.

02

Issue passports

One click per agent in the console, anchored in your own domain. Shadow becomes identified.

03

Watch first

Watch-only: every decision recorded as would allow or would refuse. Nothing blocked. Zero risk.

04

Enforce

Flip the rules live when you're ready. Breaches are refused, and the security review finally has an answer.

WINDOWS · POWERSHELL irm https://knowmyagents.com/install.ps1 | iex
MACOS · LINUX curl -fsSL https://knowmyagents.com/install.sh | sh

It asks where to install, then asks for one thing — a registration token from your console.

Re-run it any time to update — your secrets, registration, audit log and passports are kept.

Read the full install guide — prerequisites, updating, backup, troubleshooting ↗

// one command to install · one click per passport · no SDK, nothing added to your agents

07 · NOTHING PROPRIETARY

Open standards.
No lock-in.

OAuth 2.1 OpenID for VC W3C DID SD-JWT MCP EU AI ACT ART. 12 / 14

The same identity rails the EU digital wallet runs on — applied to agents. Anchored in DNS and cryptography, the trust roots the internet already accepts. Your agent traffic and your log never leave your own infrastructure. EU residency for the hosted control plane is on the roadmap — ask us where it runs today.

The EU AI Act names what this layer produces. Article 12 requires automatic recording of events; Article 14 requires oversight that can interrupt a system — which is what revoking a passport does. Articles and dates, kept current → the compliance mapping.

08 · THE ARGUMENT

Every AI agent will need papers.

Every access system we built assumes a person is behind the keyboard. Agents break that assumption quietly — they act continuously, spawn helpers, and hold credentials issued to someone else. None of the incidents above was a model failure. Each one was an identity and authorisation failure. The fix is not smarter agents. It is papers.

Watch the trailer 1:31 Episode 1 · The Traveller 3:01 Passports for Agents — the series 6 EPISODES
FOR YOUR ORGANISATION

Built for a team.

Roles for owners, admins, policy authors, auditors and viewers. Invite colleagues. Single sign-on (OIDC).

Owner Admin Policy author Auditor Viewer
✉ invitations by email ⚿ Single sign-on (OIDC) ◎ one console, every machine
09 · GET STARTED

Someone has to issue the papers,
check them, and keep the record straight.

Start free, on your own. Install the doorman with one command, and see every agent and every place it reaches — in watch-only mode, blocking nothing. Switch enforcement on when you're ready. Sign in with Google or GitHub, or your work email.

Prefer a person? Request a demo.

Prefer a walkthrough first? Write to hello@primethoughts.com.

$ curl -fsSL https://knowmyagents.com/install.sh | sh