Supervisory Control Plane

Governance for AI agents doing regulated work

SCP delivers your policies to every AI agent at the moment it acts, enforces them where the agent reaches models and tools, and keeps a record of what each agent knew and did.

Built on the open Structured Context Specification. Runs inside your boundary.

Capable agents, missing context

Today's models are good at the work. What they lack is your organization's rules, and a way to show afterward that they followed them.

They know the regulation, not your policy

A model can explain HIPAA or ISO 13485. It doesn't know how your organization applies them, which exceptions you allow, or who signs off.

Each agent improvises a little differently

Prompts drift, teams copy and edit them, and the same question gets different handling depending on which agent answers it.

Someone will ask what the AI knew

Auditors, regulators, and customers increasingly expect evidence: which rules were in effect, which version, and what the agent did with them.

Define once. Deliver, enforce, and record everywhere.

The agent doesn't change. The context it works within does, and SCP is where that context is governed.

1

Define

Write your policies, boundaries, and procedures as versioned SCS bundles: structured, reviewable, and approved before anything uses them.

2

Deliver

SCP selects the context each agent needs for its role and the task at hand, and delivers it at runtime. Change a policy once; every agent gets the update.

3

Enforce

Gateways in front of models and tools apply the rules: which tools a role can use, which data may go to which model, and when to stop an agent that drifts.

4

Record

Every request is logged with the agent, its role and intent, the exact context version delivered, and what happened next.

Your governance Policies, procedures, boundaries as versioned SCS bundles Supervisory Control Plane Select context by role + intent Deliver at runtime Drive enforcement Record everything AI agents Chat assistants Coding agents Agent workflows LLM gateway MCP / tool gateway Models private or frontier, by policy Tools and data context

Agents reach models and tools only through gateways that SCP controls. Every step is recorded.

From improvising to operating inside your rules

Without a control planeWith SCP
Agents improvise from training data and copied promptsAgents work from your approved, versioned policies
Behavior varies from one agent and team to the nextOne source of governance for every agent
Changing behavior means changing each agentChange the context once; every agent picks it up
Any agent can call any model or tool it can reachModels, tools, and data access follow role and data classification
Little evidence of what the agent knewA record of the context, version, and outcome for each request

Under the hood

For teams that need to validate the architecture. SCP is in active development; here is what exists today and what the next release adds.

Core platform Today

  • Versioned bundles. Governance as immutable, semantically versioned SCS artifacts.
  • Bundle registry. Publish, approve, and pin the context agents are allowed to use.
  • Selection by role and intent. Graph-based selection gives each agent the relevant context, not everything.
  • Runtime delivery. Agents request context as they work; policy updates take effect without redeploying agents.
  • Audit trail. Which agent, which role and intent, which context version, when.

Next release In development

  • Gateway enforcement. SCP drives an LLM gateway and an MCP gateway, so rules apply even to agents you didn't build.
  • Data-classification routing. Sensitive data stays on private models; frontier models only where policy allows.
  • Tools and skills by role. Deploy the right tools to the right people and agents from one place.
  • Usage and intervention. Telemetry across every agent, and the ability to stop one that goes off policy.
  • Governance console. A web interface for compliance teams to review policy, usage, and evidence.

The EU AI Act timeline moved. The work didn't.

The Digital Omnibus on AI, in force since July 27, 2026, pushed back the high-risk obligations. Organizations using the extra time to build evidence and oversight will be in a far better position than those waiting for the date.

August 2, 2026

Transparency obligations for AI systems (Article 50) apply on the original schedule.

December 2, 2027

High-risk obligations for stand-alone Annex III systems, such as credit scoring and employment decisions.

August 2, 2028

High-risk obligations for AI in regulated products under Annex I, including medical devices.

Record-keeping (EU AI Act Art. 12)SCP logs each agent request with the context and policy version in effect.
Technical documentation (Art. 11)SCS bundles are structured, versioned documentation of how the system is meant to behave.
Human oversight (Art. 14)People define and approve the rules in the control plane, and can intervene when an agent drifts.
HIPAA audit controls (ยง164.312(b))Requests are logged with agent identity, role, intent, and the policies delivered.
Quality systems (ISO 13485, 21 CFR 820)Versioned, approved context and a request-level record support controlled processes and traceability.

SCP supports your compliance program; it doesn't replace legal or regulatory advice. Dates reflect Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI.

Your industry. Your rules.

Healthcare

Prior authorization, clinical documentation, and PHI access, governed by your policies with a record of every decision.

Medical devices and life sciences

Design controls, complaint handling, and quality records, where AI assistance has to fit the quality system.

Financial services

Your credit criteria, risk tolerance, and escalation rules, applied consistently rather than reinvented per prompt.

Legal

Your privilege protocols, conflict checks, and retention policies, not general best practices.

One part of a private, governed AI platform

SCP works on its own, and it's designed to run inside your security boundary alongside the rest of the Ohana stack.

Open specification

Structured Context Specification

The open format for machine-readable governance context: bundles, documents, and the relationships between them.

structuredcontext.dev →

Runtime

Supervisory Control Plane

Delivers, enforces, and records governance context for every agent, model, and tool call.

Request a demo →

Platform

Private AI

Models and agents running on infrastructure you control, so sensitive data never leaves your boundary.

ohana-tech.com →

Your agents are making decisions today.

Let's look at which rules they're working from, and what it would take to make those rules yours.

Request a demo