Authorise every model call.
Put any model provider behind the Authorisation Layer. The AI Gateway runs model calls through the same enforcement as any other action, so what an agent asks a model to do is authorised, not just logged.
Point your agents at the gateway and their model calls are evaluated against your Charter, whichever provider they use.
The gateway applies identity, delegation, context and charter to model calls, and can pause high-impact calls for a human.
Run in observe mode to see what would be caught, then switch to enforce when you are ready.
Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.
Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.