{"schema":"agentomy.service/v1","name":"Agentomy","definition":{"what":"A vendor-neutral governance layer between AI agents and the systems they act on. A layer, not another agent framework.","where":"Between the agent (any model, any framework) and the consequential resource: tools, MCP servers, APIs, data, workflows.","controls":"Whether each action is permitted before it runs: identity, tier-based authorization, behavioral baselines, quarantine, halt (one agent or the fleet).","produces":"A hash-linked, tamper-evident record of every governance decision, exportable to the framework you report against."},"taxonomy":{"public_category":"AI agent governance","architecture_category":"autonomous authority governance","product_class":"control_plane","note":"The public description is the human vocabulary; the architecture category is what the layer does: decide and prove the authority an autonomous system has at the point its intent becomes consequence."},"hosts":{"human":"https://agentomy.com","machine":"https://getagentomy.com"},"discovery":{"llms":"https://agentomy.com/llms.txt","llms_full":"https://agentomy.com/llms-full.txt","pricing":"https://agentomy.com/pricing.json","tiers_matrix":"https://api.agentomy.com/api/tiers","sitemap":"https://agentomy.com/sitemap.xml","source":"https://github.com/getagentomy","security_txt":"https://agentomy.com/.well-known/security.txt","research_guidelines":"https://agentomy.com/research-guidelines"},"acquisition":{"free":{"plan":"free","key_tier_ceiling":"Evaluator","agent":{"open":true,"challenge":"https://agentomy.com/api/agent/signup/challenge","signup":"https://agentomy.com/api/agent/signup","method":"POST","proof_of_work":{"hash":"sha256","leading_zero_bits":20,"challenge_ttl_seconds":600}},"human":"https://agentomy.com/signup"},"paid":{"plans":["pro_99","fleet","enterprise","self_hosted"],"machine_checkout":false,"human_approval_required":true,"human":"https://agentomy.com/pricing","contact":"https://agentomy.com/contact"},"escalation":"Every refusal carries an escalation object naming the human paths; insufficient authority is an escalation, not a failure."},"trust":{"asks_of_agents":["proof of work bound to a signed, expiring challenge","agent name","principal email and organization","rate limits: 3 signups per address per hour, a daily cap, a kill switch"],"offers":["open benchmarks runnable against Agentomy itself","hash-linked audit record for every governance decision","published research and disclosure policy","readiness mapping to frameworks, not certification"],"key_handling":"API keys are shown once; the control plane stores only a hint. Model provider keys you add to a hosted workspace are encrypted at rest and used only to call your model; self-hosted deployments keep them in your environment.","tier_model":"A plan sets the ceiling tier its keys can carry; policy decides each action."},"govern":{"agent_sdk":{"npm":"agentomy-agent","license":"MIT","standalone_score":"3/6","connected_score":"6/6"},"mcp_gateway":{"npm":"agentomy-mcp-gateway","license":"Apache-2.0","behavior":"interposes on tools/call, refuses before the upstream server executes, fails closed"},"benchmarks":{"governancebench":"npx governancebench run --target <url>","vigil":"npx agentomy-vigil run --target <url>"},"governance_api":"https://api.agentomy.com","environment":{"AGENTOMY_API_URL":"https://api.agentomy.com","AGENTOMY_API_KEY":"<from signup>"}},"compatibility":{"protocols":["MCP"],"environments":"any MCP-compatible environment","sdk_languages":["TypeScript","Python"]},"links":{"human_site":"https://agentomy.com","agents_page":"https://agentomy.com/agents"}}