Platform overview

The evidence layer for AI systems and agents.

Gamut helps security, risk, legal, governance and AI teams discover what AI exists, classify risk, control agentic workflows and produce evidence that boards, buyers, auditors and reviewers can actually use.

Book a call Explore the sprint Start free

AI has moved faster than the evidence around it.

Most organisations now have AI in SaaS products, internal copilots, business experiments, vendor platforms and emerging agentic workflows. The problem is not only whether AI is being used. The problem is whether the organisation can prove what exists, who owns it, what it can do, what controls are in place and what evidence supports the risk position.

AI inventory is incomplete

Teams often cannot see all AI systems, GenAI tools, vendor AI features, pilots and agentic workflows in one governed register.

Governance is too document-heavy

Policies exist, but the operational records, control decisions, approvals, evidence and remediation history are scattered.

Agents change the risk model

AI systems are no longer just producing outputs. They are starting to call tools, touch data, trigger workflows and act.

What Gamut is

Gamut is a Trustworthy AI Operating Platform. It gives organisations a structured operating layer for AI assurance, from discovery and risk classification through control evidence, agent governance, audit review and leadership reporting.

System of record

Maintain AI system records, owners, suppliers, lifecycle status, use cases, risk context, model cards, evidence and findings.

Control workflow

Route assessments, approvals, control expectations, evidence requests, exceptions, findings and remediation through a repeatable process.

Assurance evidence

Produce reviewable evidence packs for boards, buyers, internal audit, external reviewers, insurers and governance teams.

How the platform works

1. Discover and record

Capture AI systems, GenAI tools, vendor AI, internal use cases and agents in a governed register with ownership and context.

2. Assess and classify

Assess purpose, users, impact, data exposure, supplier involvement, human oversight and risk classification.

3. Route controls and evidence

Turn risk decisions into control expectations, evidence requests, findings, remediation actions and reviewable records.

4. Report and improve

Give leadership a clear view of AI exposure, evidence quality, open gaps, remediation progress and decisions required.

Built for AI systems and AI agents

Gamut covers the full AI assurance lifecycle, but its strongest edge is agentic AI: the ability to govern AI-enabled action before it affects data, systems, customers or operations.

Agentic CISO

Record agents, owners, autonomy, access, tools, data flows, approvals, incidents, tests and assurance evidence.

Gamut Gateway

Evaluate proposed AI actions before execution, including tool use, connector calls, model invocation, data class and approval requirements.

Gamut Claw

Execute approved AI tasks inside defined limits, without becoming the policy authority, database owner, secret holder or direct connector client.

Explore agentic AI governance · View the 30-day sprint · See Gateway · See Claw

What Gamut produces

AI inventory

A structured register of AI systems, agents, use cases, owners, suppliers, data context and lifecycle status.

Risk classification

Consistent classification based on business purpose, impact, data exposure, oversight, users and operating context.

Model and system cards

Clear records explaining purpose, usage, risks, ownership, limitations, controls and assurance status.

Risk registers

Findings, residual risk, treatment decisions, remediation ownership, priority and status.

Evidence packs

Evidence requests, artefacts, quality ratings, decisions, approvals, control records and review notes.

Board reporting

Leadership summaries showing AI exposure, readiness, evidence quality, open gaps and decisions required.

Operationalise NIST AI RMF without turning it into shelfware

Gamut helps teams translate AI risk management into records, owners, controls and evidence across the NIST AI RMF functions.

Govern

Policies, ownership, accountability, approval rules, risk appetite, governance roles and leadership reporting.

Map

AI inventory, business purpose, context, users, affected groups, data exposure, suppliers and operational dependencies.

Measure

Risk classification, controls, testing, evidence quality, findings, exceptions and residual risk.

Manage

Remediation, escalation, approvals, monitoring, evidence refresh, review cycles and continuous improvement.

View the NIST AI RMF evidence readiness page

Why reviewers, boards and buyers care

They do not only want your policy

They want to know what AI exists, who owns it, how risk was assessed, what controls were applied, what evidence exists and what gaps remain.

They need a defensible record

Gamut turns AI assurance from a narrative into traceable records: system to risk decision, risk decision to control, control to evidence, evidence to finding, finding to remediation.

Who Gamut is for

CISOs and security teams

Understand shadow AI, SaaS AI risk, agent access, tool use, data exposure and control gaps.

Risk, legal and compliance

Convert policy obligations and buyer expectations into structured assessments, approvals and evidence.

AI product and platform teams

Prepare for buyer assurance, board scrutiny, model/system documentation and ongoing risk review.

What makes Gamut different

Deep assessment base

GTSAF gives Gamut a broad control foundation, with 358 controls across 17 domains, supporting practical assessment depth rather than light-touch checklist theatre.

Agentic control model

Gamut connects Agentic CISO, Gateway and Claw so teams can govern AI-enabled action, not just document AI systems after the fact.

Founder-led assurance

Gamut was created by Arinze Okosieme, a cybersecurity and AI assurance practitioner with 27+ years' experience and CISSP, CCSP, CCZT and TAISE credentials.

Platform plus judgement

Buyers can start with a focused assurance sprint, use Gamut as the delivery engine, then continue with platform access and advisory support.

Start with a focused assurance sprint

The fastest buying path is not a long platform evaluation. It is a focused sprint that produces useful evidence quickly and configures Gamut around real AI systems or agents.

30-Day AI Agent Assurance Sprint

  • AI system and agent inventory
  • Autonomy and tool-access map
  • Human oversight model
  • Control gap report
  • Board-ready evidence pack
  • Gamut workspace configured for ongoing assurance

View sprint details

How buying works

  • Book a call
  • Agree the first assurance target
  • Run the focused sprint
  • Review the evidence pack and gaps
  • Continue with platform subscription, retained advisory support or both

Run the Gamut

Move from AI governance claims to AI assurance evidence.

Use Gamut to see what AI exists, understand what it can do, control what agents are allowed to access and produce evidence that leadership, buyers and reviewers can trust.

Book a call Explore the sprint Start free

Use Gamut as your client delivery layer.

AI governance consultants, auditors, security specialists and implementation firms can build repeatable client services through the Gamut Assure Partner Network.

Explore the Partner Network