Overview
SightHelm is a deployment-agnostic AI agent governance and control platform for heterogeneous enterprise estates. It is designed to run in your chosen cloud or data centre and govern AI agents across Microsoft, Google Cloud, AWS and Salesforce without making the hosting platform determine the sources in scope.
Today’s implemented baseline uses read-only collectors across Microsoft Graph and Entra, Defender XDR, Power Platform and Copilot Studio, Microsoft Foundry, optional Purview and Application Insights evidence, plus an optional fail-closed Salesforce Agentforce inventory connector. Google Cloud and AWS connector packs are planned against the same evidence contract. SightHelm maps reach, evaluates deterministic policy, coordinates accountable decisions and governed remediation, and can perform explicitly enabled containment for supported targets.
Why we built it
Agents now get created across cloud and SaaS platforms faster than any security or governance team can track by hand — a Copilot Studio flow here, a Foundry deployment there, an Agentforce automation or an agent runtime in another cloud that nobody remembers approving. Clients kept asking the same questions: what AI agents actually exist, what can they touch, who signed off on them, and who is accountable if something goes wrong? We built SightHelm so those questions have a straight, evidenced answer — and a governed path to fixing what they turn up.
What it does
- Discover with evidence. Read-only collectors surface agents and record freshness, confidence, limitations and failures. Missing or stale evidence becomes a visible coverage gap, never a clean assumption.
- Map reach and responsibility. A content-free graph connects agents to identities, permissions, owners, resources, tools, MCP servers, users, departments and governed data domains.
- Evaluate deterministic policy. A bounded policy-as-code engine uses independently approved, immutable versions and keeps an LLM out of the decision path.
- Make accountable decisions. Business sponsors and technical owners carry explicit responsibility, while exceptions require justification, expiry and maker-checker approval.
- Govern and enforce action. Remediation plans move through approval, dispatch and execution. Separately enabled worker credentials can disable a supported Microsoft Entra service principal when policy pre-authorises containment.
- Prove the outcome. Append-only activity, digest-protected exports and reports, Azure Monitor and Sentinel delivery, and signed event integration preserve attributable evidence.
- Separate hosting from coverage. Run one customer-controlled appliance in the approved hosting location, then connect independently authorised provider estates without requiring the host cloud and source cloud to match.
Platform components
- Console and control API. One operational surface for inventory, agent detail, coverage, policy, exceptions, remediation, evidence, deployment and governed commands.
- Provider connector packs. Source-specific collectors retain provenance while the correlation engine resolves a canonical inventory and materialises relationships across provider boundaries.
- Risk, policy and governance. Deterministic scoring and policy evaluation feed accountability, disposition, recertification, exception and notification lifecycles.
- Remediation and enforcement. Durable workers run maker-checker plans, external runbooks and the narrowly scoped, opt-in containment actions SightHelm supports.
- Evidence and integrations. PostgreSQL holds inventory, immutable history and transactional queues; evidence can flow to reports, exports, Sentinel, Azure Monitor and allowlisted signed endpoints.
- Customer-controlled appliance. The signed OCI image and Helm package target AKS, EKS, GKE, OpenShift and conformant private Kubernetes through explicit database, registry, secret, ingress, OIDC and telemetry contracts. AKS is the currently accepted reference profile.
Provider and deployment direction
- Microsoft — implemented baseline. Entra Agent ID and Graph, Defender/Agent 365, Power Platform and Copilot Studio, Microsoft Foundry, Purview and Application Insights.
- Salesforce — inventory baseline. Agentforce inventory is available now; identity, permissions, actions, data reach and tracing remain gated follow-on layers.
- Google Cloud — planned connector pack. Vertex AI Agent Engine with service-account, IAM, Cloud Asset Inventory and content-free audit evidence.
- AWS — planned connector pack. Amazon Bedrock AgentCore and Agent Registry with IAM, CloudTrail, CloudWatch and resource metadata.
- Hosting — portable by contract. The host platform supplies compute, PostgreSQL, image registry, secrets, ingress, OIDC and operations; provider collectors receive separate worker-only credentials.
Want to see SightHelm in your environment? Tell us where you need it to run and which Microsoft, Google Cloud, AWS or Salesforce estates are in scope. We’ll map the available connector coverage, the remaining gaps, and the governed path from finding to action.
Get in touch