Bring Your Own Agent
Bring your agent. Keep control.
Use the agents, orchestration frameworks, model providers, tools and data sources that fit your organisation. Gamut adds the governance and runtime control layer that determines what each agent may do, requires approval where needed and records what actually happened.
Discuss your integrationYour architecture does not need to become our architecture.
Bring Your Own Agent is for organisations that already have an agent, are building one, or need freedom to choose the right runtime and providers. The reasoning loop can remain in your environment. Gamut becomes the independent control plane and, for consequential actions or protected resource access, Gateway becomes the enforcement point.
Keep your agent and runtime
Integrate an existing managed agent, internal service, orchestration framework or approved third-party runtime without replacing its reasoning layer.
Keep your technology choices
Use approved model providers, MCP servers, APIs, repositories, retrieval systems and enterprise data sources under explicit policy.
Centralise control
Define agent identity, ownership, purpose, autonomy, tool access, data boundaries, approvals, budgets and lifecycle in Gamut.
Produce consistent evidence
Capture decisions, approvals, denials, execution results and security events across otherwise different agent stacks.
What you can bring
| Component | How Gamut governs it |
|---|---|
| Your agent | The agent receives a distinct identity and is registered with an owner, approved purpose, lifecycle state, risk profile and permitted autonomy. |
| Your runtime or orchestrator | The runtime may plan and reason independently, but it cannot create its own authority. Governed actions are evaluated at Gateway. |
| Your models | Approved model-provider access can be routed through governed egress with provider, model, purpose, data and usage restrictions. |
| Your tools and connectors | MCP servers, APIs, webhooks, repositories and enterprise tools are registered and constrained by exact actions, resources and environment. |
| Your data sources | Retrieval and data access remain subject to tenant boundaries, classification, purpose, redaction, retention and response controls. |
| Your credentials | Production integrations use approved secret stores or environment-backed references. The agent does not receive unrestricted raw credentials from Gamut. |
How a BYO agent connects to Gamut
1. Register
Record the agent, owner, tenant, purpose, runtime, model, tools, data access and accountability context in Agentic CISO.
2. Define authority
Create active Runtime Access Policies for the exact tool, action, resource, purpose, data class and environment combinations the agent needs.
3. Route actions
Send consequential tool calls and protected resource access through Gateway using authenticated, tenant-bound service and agent identity.
4. Enforce
Gateway independently allows, blocks or requires approval and issues short-lived execution authority only when every required control passes.
5. Execute
Your approved backend or Gamut Claw performs the bounded operation and returns the required outcome, state and verification evidence.
6. Review
Decisions and outcomes become tamper-evident records for operations, assurance, incident response and continuous improvement.
The non-negotiable security contract
BYO does not mean bring your own trust. Integration remains safe only when the controls that matter cannot be bypassed.
- Every agent and calling service has a verifiable, tenant-bound identity
- Consequential actions and protected resource access pass through Gateway
- Prompt content and model output are treated as untrusted input, never authority
- Runtime permissions stay within the agent's approved purpose and exact capability tuple
- Human approval is cryptographically bound to the exact action parameters
- Execution authority is short-lived, request-bound and resistant to replay
- State-changing operations verify current target state at the moment of use
- Delegation can only reduce authority and preserves parent-to-child lineage
- Credentials remain outside the agent's reasoning context wherever possible
- Missing, stale, altered or unverifiable control evidence fails closed
Supported integration patterns
| Pattern | Best fit | Control boundary |
|---|---|---|
| Gateway-mediated agent | An existing agent retains its reasoning and orchestration stack. | All consequential tools and protected resources are exposed only through Gateway-controlled paths. |
| BYO runtime with Gamut policy | An organisation runs the worker in its own environment. | Gamut evaluates authority; the runtime executes only with valid, bounded Gateway authority and returns verifiable evidence. |
| Gamut Claw execution | The organisation wants Gamut's bounded worker for governed tasks. | Claw plans and executes within task limits while Gateway remains the independent policy decision and enforcement point. |
| Governed model egress | Agents need approved access to internal or external model providers. | Provider, model, purpose, data class, usage and response handling are constrained at the egress boundary. |
| Read-only assurance integration | A team wants inventory, assessment and evidence before enabling live execution. | The agent can be governed and assessed without receiving production action authority. |
What Bring Your Own Agent does not mean
No blanket access
Connecting an agent does not authorise every tool, resource or action available to its runtime.
No trust in prompts
A system prompt, user message, retrieved document or collaborating agent cannot expand runtime authority.
No approval bypass
Changing an approved payload, target, purpose or protected state invalidates the prior authority.
No hidden delegation
Child agents and handoffs need explicit, bounded grants with traceable lineage and revocation.
No credential hand-off by default
Agents should call governed connectors rather than receive reusable secrets inside prompts or working memory.
No evidence-free execution
Actions that cannot produce the required decision, execution and state evidence are blocked or kept outside production authority.
Shared responsibility stays explicit
| Your organisation | Gamut |
|---|---|
| Owns the agent, business purpose, deployment, source environment and the decision to expose enterprise systems. | Provides the governance record, policy evaluation, approval controls, execution authority and audit evidence. |
| Routes every in-scope action through the approved enforcement path and prevents alternate privileged routes. | Fails closed when required identity, policy, approval, state, connector or execution evidence is missing or invalid. |
| Operates approved connectors and backends to the documented security contract, including state preconditions and receipts where required. | Validates returned evidence, records control outcomes and supports assurance and incident review. |
| Maintains the agent runtime, model behaviour, application security and underlying infrastructure it controls. | Constrains runtime authority independently of what the reasoning model requests or claims. |
How BYO fits into Gamut
Agentic CISO records who the agent is and what it is meant to do. Gateway enforces whether a proposed action is permitted at runtime. Your approved backend or Gamut Claw executes within that authority. Gamut then connects the decision and outcome to a reviewable assurance record.
Explore Agentic CISO · See Gateway controls · See Claw execution
Integrate without surrendering control
Make your agent governable before it becomes powerful.
Bring the agent stack that works for you. Use Gamut to establish the identities, boundaries, approvals, enforcement and evidence needed for responsible production use.
Discuss your integration