RULE47
Agents and Robots Identity Management · AI Cybersecurity

Your AI agents can spend, send and delete. Who approved that?

Rule47 gives every agent a verified identity, an approved purpose and limits it cannot break. Consequential actions routed through Rule47 get a verdict before they run.

See a Live Agent
R47-AGENT-001
VERIFIED

Why now

The risk moved from what agents say to what agents do.

4 layers of agent control

Four layers. Every agent. No exceptions.

Rule47 binds every governed agent to a verified identity, approved purpose, enforced limits and runtime control.

01

IDENTITY

Every agent gets a verified, unique identity bound to a named human owner. No anonymous agents operate in your systems.

Why it matters

The foundation. Without identity, nothing is enforceable or auditable.

02

PURPOSE

An approved scope of work in plain language. The agent carries its approved purpose: it knows what it may do, what it must refuse and when it needs a human.

Why it matters

This is policy as identity. The rules travel with the agent, not only in a policy document.

03

RIGHTS & LIMITS

Approved tools, targets, spending caps, data access scopes. Limits are enforced at runtime, not as guidance in a PDF.

Why it matters

Prevents overreach at the moment of action, not in a post-incident review.

04

CONTROL

Consequential actions routed through Rule47 get one of four verdicts: ALLOW, ASK HUMAN, BLOCK or PAUSE AGENT. Every decision becomes evidence.

Why it matters

For high-risk AI systems, EU AI Act Article 14 requires effective human oversight. Rule47 helps create operational evidence of that oversight.

The Rule47 constitution

7 rules. The minimum every AI agent needs.

4 Layers + 7 Rules = Rule47. The minimum controls for any AI agent in production.

  1. 01Every agent has an identity.
  2. 02Every agent has a named human owner.
  3. 03Every agent knows its own purpose.
  4. 04Every agent has enforced limits.
  5. 05Every action routed through Rule47 gets a verdict.
  6. 06Every change is detected: a modified agent pauses itself.
  7. 07Every decision is evidence: exportable, auditable, regulator ready.

The four verdicts

Every action. Four possible answers. Always.

The reason is written in plain language. Your team and your auditor read the same thing.

ALLOW

Inside purpose, rights and limits. The action runs.

ASK HUMAN

Over the limit or something changed. A person decides.

BLOCK

Outside the approved purpose or scope. The action never runs.

PAUSE AGENT

The agent was changed without approval. It stops itself.

How it's different

Control, not another dashboard.

Your identity provider establishes who the agent is. Rule47 determines whether this specific action is permitted within its approved purpose.

01

Pre-action enforcement

Before the action runs

Other tools list your agents and replay what happened. Rule47 decides whether the action happens at all.

02

Self-aware agents

No external watchdog

Each agent carries its approved profile. It can explain its own rules. If it is changed without approval, it pauses itself.

03

EU-native

Hamburg, Germany

Built in Hamburg, Germany. Designed for EU AI Act, GDPR and data sovereignty from day one. Not a US product with a European region.

Compliance

Ready for the rules that govern AI.

Article 50 transparency duties of the EU AI Act are live since 2 August 2026. High-risk system obligations arrive in December 2027. And the AI Act is only one of them: GDPR, ISO standards, SOC 2 and internal AI policies all demand the same thing. Rule47 produces the evidence each of them asks for, while your agents work, not after an auditor asks.

Human oversight

A named person approves scope and decides on every held action. (Art. 14)

Risk management

Purpose and limits are versioned. Unapproved changes pause the agent. (Art. 9)

Transparency and audit

Complete, exportable record of every decision and approval. (Art. 12, 50)

Living documentation

Agent profiles stay current as living system records, not static PDFs. (Art. 11)

Beyond the AI Act

GDPR

Purpose limitation, data minimisation and a records trail for every automated decision. (Art. 5, 22, 30)

ISO/IEC 42001

Agent inventories, approved purpose and versioned controls map to AI management system requirements.

ISO/IEC 27001

Access control, change detection and logging aligned to information security management controls.

SOC 2

Decision records and approval evidence map to security, availability and processing integrity criteria.

NIST AI RMF

Identity, evaluation and governance of agents support the Govern, Map, Measure and Manage functions.

EU data residency

Built and hosted in Germany. Agent data stays in the EU under your control.

How it works

Register. Approve. Control. Prove.

01

Register

Add an agent in minutes, or let it register itself.

02

Approve

A named owner approves purpose, rights and spending limit.

03

Control

Each action is checked against the approved profile in real time.

04

Prove

Every decision becomes exportable evidence.

Illustrative prototype workflow

invoice-run · n8n workflowIllustrative

Trigger

Schedule

Weekdays 07:00

Agent

Invoice Agent

Entra IDOkta

Rule47 check

Identity · Limit

ALLOW

Action

Send payment

ERP · SAP

Designed to integrate with

Orchestration

  • n8n
  • Make.com
  • Zapier

Identity

  • Microsoft Entra ID
  • Okta
  • AWS IAM

Agents

  • MCP-native
  • Custom agents
  • REST API

See Rule47 live.

Fifteen minutes with your own agentic workflow.

Open the Console