Skip to main content
Use case · Defense Contractors

Controlled & Classified Data-Handling Governance

Govern AI agents that read, summarize, and move controlled unclassified information (CUI) across a defense program: an unregistered agent is held to read-only, every authorized agent is scoped by tier, and every touch is provable to an assessor.

The risk

What an ungoverned agent gets wrong here.

The everyday work of a defense program produces a flood of controlled unclassified information (CUI, the category of sensitive-but-unclassified data the government requires contractors to protect). AI agents are perfect for reading, summarizing, and routing it. That is exactly the risk. An agent that summarizes a controlled document and drops the result into an uncleared tool has spilled CUI just as surely as a person would have. Without a governance layer, there is no enforced boundary on where an agent may send controlled data, no tie from an agent's action to a cleared operator, and no record that a CMMC assessor will accept as proof the boundary held.

Without governance

Where it goes wrong.

01

A summary that leaves the boundary

An agent summarizes a CUI document and tries to post the result to an uncleared collaboration tool. Tier-gated authorization refuses an agent that was never granted that action, and logs the denial with a plain-English reason.

02

Controlled data pulled into a prompt

An agent pulls CUI into a request bound for an unapproved external model endpoint. The reach outside its usual pattern is flagged against the agent's behavioral baseline and written to the tamper-evident record, so an unapproved route is visible rather than silent.

03

An agent that starts reading everything

A document agent drifts from its baseline and begins pulling far more controlled files than its task requires. Behavioral monitoring flags the anomaly and auto-quarantines it before it becomes an exfiltration.

04

The assessor wants proof the boundary held

A CMMC assessment asks the contractor to show how controlled data was accessed and where it went. A tamper-evident, hash-linked trail attributes every read and write to a cleared operator, exportable as assessment evidence.

With Agentomy

How Agentomy governs it.

01

Least-privilege on controlled data

An unregistered agent falls back to read-only, and every authorized agent is scoped to exactly the controlled data and actions its task requires. Nothing moves CUI without an explicit authorization tier.

02

Cap how far one session can reach

The number of distinct systems a single session may traverse is capped by a server-registered limit, so an agent that starts reaching across the program is refused at the cap rather than reviewed after the fact. The cap is not something the agent can raise: a limit sent on the request is dropped and recorded, and the denial is written to the chain with a plain-English reason.

03

Detect drift and halt fast

Per-agent baselines flag an agent reading or moving more than its pattern, with auto-quarantine, and one switch halts every agent in under a twentieth of a second, surviving a restart.

04

Prove it to a CMMC assessor

A tamper-evident, hash-linked log records every access to controlled data (which agent, which record, under whose authorization, and where it went), exportable as readiness evidence mapped to the controls an assessment requires.

Frameworks

Maps to what you answer to.

Agentomy does not certify you. It gives you the enforcement and the audit trail these frameworks ask for, so readiness is something you can show rather than assert.

CMMCthe Cybersecurity Maturity Model Certification the US Department of Defense requires of its contractors; Agentomy provides enforcement and evidence you can map toward its requirementsNIST 800-171the National Institute of Standards and Technology controls for protecting controlled unclassified information (CUI) in nonfederal systems; governance maps to its access-control and audit requirementsNIST 800-53the federal security and privacy control catalog; capabilities map to its access-control and audit-logging controlsITARthe International Traffic in Arms Regulations governing defense-related technical data; access controls and the audit trail give you the boundary and the record these require
See it in the record

Every action, logged and provable.

A tamper-evident, hash-linked trail of every governance decision for this workload: what an agent did, under whose authorization, and why. Plain-English reasons for every allow and deny, exportable to the framework your auditors care about.

Agentomy Command CenterFilter Controlled & Classified Data-Handling Governance
  • 100% Integrity
  • 43,782 Blocks
  • SHA-256 hash-linked
Audit trail: one tamper-evident block per governance decision, hash-linked to the one before it
BlockTimestampAgentActionTierHash
43,782Today 12:42:08threat-research-agentdata_access_requestEvaluator1f1064073783b827
43,781Today 12:41:54request-triage-agentoutput_validationAnalysteab4f2542a12e61b
43,780Today 12:41:37supplier-clearance-agentpolicy_checkBuilder6f4562719ff4688b
43,779Today 12:40:58export-control-agentbehavior_driftOperator9d91790e5c66a17b
43,778Today 12:40:21classification-draft-agenthalt_initiatedStrategist82e24b3707aeadeb
43,777Today 12:39:46readiness-report-agentprompt_reviewEvaluatorc3112b42133d0ae1
Governance events today: 12,842Demo environment
Illustrative interface with sample data, in the shipped Command Center’s structure. Not a customer environment and not a live feed.

Ready to govern your agents?