Supervisory Control Plane
SCP delivers your policies to every AI agent at the moment it acts, enforces them where the agent reaches models and tools, and keeps a record of what each agent knew and did.
Built on the open Structured Context Specification. Runs inside your boundary.
The gap
Today's models are good at the work. What they lack is your organization's rules, and a way to show afterward that they followed them.
A model can explain HIPAA or ISO 13485. It doesn't know how your organization applies them, which exceptions you allow, or who signs off.
Prompts drift, teams copy and edit them, and the same question gets different handling depending on which agent answers it.
Auditors, regulators, and customers increasingly expect evidence: which rules were in effect, which version, and what the agent did with them.
How it works
The agent doesn't change. The context it works within does, and SCP is where that context is governed.
Write your policies, boundaries, and procedures as versioned SCS bundles: structured, reviewable, and approved before anything uses them.
SCP selects the context each agent needs for its role and the task at hand, and delivers it at runtime. Change a policy once; every agent gets the update.
Gateways in front of models and tools apply the rules: which tools a role can use, which data may go to which model, and when to stop an agent that drifts.
Every request is logged with the agent, its role and intent, the exact context version delivered, and what happened next.
Agents reach models and tools only through gateways that SCP controls. Every step is recorded.
What changes
| Without a control plane | With SCP |
|---|---|
| Agents improvise from training data and copied prompts | Agents work from your approved, versioned policies |
| Behavior varies from one agent and team to the next | One source of governance for every agent |
| Changing behavior means changing each agent | Change the context once; every agent picks it up |
| Any agent can call any model or tool it can reach | Models, tools, and data access follow role and data classification |
| Little evidence of what the agent knew | A record of the context, version, and outcome for each request |
Capabilities
For teams that need to validate the architecture. SCP is in active development; here is what exists today and what the next release adds.
Regulation
The Digital Omnibus on AI, in force since July 27, 2026, pushed back the high-risk obligations. Organizations using the extra time to build evidence and oversight will be in a far better position than those waiting for the date.
Transparency obligations for AI systems (Article 50) apply on the original schedule.
High-risk obligations for stand-alone Annex III systems, such as credit scoring and employment decisions.
High-risk obligations for AI in regulated products under Annex I, including medical devices.
SCP supports your compliance program; it doesn't replace legal or regulatory advice. Dates reflect Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI.
Where it fits
Prior authorization, clinical documentation, and PHI access, governed by your policies with a record of every decision.
Design controls, complaint handling, and quality records, where AI assistance has to fit the quality system.
Your credit criteria, risk tolerance, and escalation rules, applied consistently rather than reinvented per prompt.
Your privilege protocols, conflict checks, and retention policies, not general best practices.
The stack
SCP works on its own, and it's designed to run inside your security boundary alongside the rest of the Ohana stack.
Open specification
The open format for machine-readable governance context: bundles, documents, and the relationships between them.
structuredcontext.dev →Runtime
Delivers, enforces, and records governance context for every agent, model, and tool call.
Request a demo →Platform
Models and agents running on infrastructure you control, so sensitive data never leaves your boundary.
ohana-tech.com →Let's look at which rules they're working from, and what it would take to make those rules yours.
Request a demo