Cevanos
AI agent governance

AI agent governance for customer service.

Control what Cevanos can access, disclose and do. Set policies and approval limits, verify identity for sensitive requests and review the evidence behind each decision.

CCevanosAI agent · reviewing liveGoverned
Monitoring live requests…
Governed autonomy

Eight controls for accountable customer service AI.

Define what the agent can access, when it can act and how your team reviews the outcome.

Knowledge01

What can it know?

Sources are scoped per agent. Retrieval is inspectable: every answer lists the passages it used, and you can quarantine a source without deleting it.

Capability02

What can it do?

Actions are classified as reads, writes and money movers. An action is only a capability; a policy decides when it fires.

Conditions03

Under what conditions?

Order value, customer tenure, prior claim count, time since delivery, channel, verified identity. Written in English, compiled to deterministic logic.

Approval04

When does it need sign-off?

Above the ceiling, the decision becomes a queued approval with the full case attached, not a dead end for the customer.

Escalation05

When must it escalate?

Low confidence, conflicting policies, unverified identity, abuse signals, legal or safety language, or an explicit request for a human.

Explainability06

How was this decided?

Every decision writes a receipt: the policy that applied, the facts it matched, the action taken and the money spent against the cap.

Verification07

Was the outcome right?

Outcomes are checked after the fact: reopened tickets, reversed refunds, repeat claimants, all fed back as policy suggestions.

Reversal08

Can we roll it back?

Restore earlier policy versions and review available corrective actions. Reversing a completed action depends on the connected system and whether the action can still be undone.

Above every policy

Enforce permissions outside the model.

Policies define when an action is allowed. Guardrails restrict actions and data access beyond those permissions. Cevanos checks proposed actions against these controls before execution.

Order of precedenceChecking
Guardrails · set once, outrank everythingNever touch: payroll, admin panels, other customers' records
Policies · what you grantedRefunds, waivers, returns, account changes
Agent · what it wants to do nextLook up this customer in the payroll system
payroll.employee.read

The model proposes an action. The control layer checks whether it is permitted. Outcome reviews help identify mistakes even when a decision passed its policy checks.

Identity and proof

Verify identity before sensitive access or actions.

Require verification appropriate to the information or action involved. Apply access controls to lookups as well as changes.

1State 1

Unknown

No identity has been established. Public information only.

2State 2

Matched

An identifier matches a record. This does not establish ownership.

3State 3

Claimed

The customer has stated that the account is theirs. This alone does not authorize access to private information.

4State 4

Confirmed

A configured verification check has passed. Action-specific permissions still apply.

5State 5

Verified

The customer is authenticated through your identity system. Role permissions and transaction checks still apply.

Policy engine

Define policies and approval limits in plain English.

Write the rule, review the conditions and limits, then test the policy before activation.

What your ops lead typesDraft

Waive a late fee of up to $50 when the customer has paid on time for the last six months and has received no waiver in the last 12 months. Require the configured identity check. Send requests above $50 to our team for approval.

PWritten by a CX lead. No engineer involved.
What the agent will checkpolicy #9

When all of this is true

Fee waiver, up to $50amount checked against the policy limit
Six months of on-time paymentsfrom billing history
No waiver in the last 12 monthsstops repeat waiver harvesting
Configured identity check has passedthe check your workspace requires for this action

How much it may spend

$50per decision
$25$300

Above $50 the agent stops and queues it for a person. A workspace cap of $2,000 a day sits over every policy, and the lower of the two always wins.

It does this

Otherwise it hands over

Above $50, route for approvalwith the payment record attached
Explore policy testingReview results
before activation

Hover any condition to see the words it came from. One decision is bounded by one policy. No stacking, no silent composition. When two policies could apply, the lowest ceiling wins and the conflict surfaces in the simulator, not in front of a customer.

Policies can use information from your connected business systems. Explore supported integrations

Decision records

Every decision leaves evidence. The refusals too.

Review the policy version, supporting information, action or handoff, and resulting status in one decision record.

Today · Tuesday6 decisions
retention set by your plan
Receipt#8f21e

Hover any line to see what it means

decisionreplacement approvedThe outcome, in the customer’s terms, not a confidence score.
policy#14 lost_package · v3Which rule applied and which version of it. Roll the version back and every decision it produced is listed.
identityconfirmed · one-time codeHow sure the agent was about who it was talking to. Money needs confirmed proof, sent only to the email already on file.
facts$84.00 · delivered 51h ago · 0 claims/180dThe bounded set of values the decision could read. Nothing outside this list could influence it.
sourcesshipping-policy.md §4 · orders APIThe passages and systems behind the answer, quotable in a dispute.
actionshopify.replacement_order.createWhat actually executed, keyed so a retry can never double-refund.
spent$84.00 of $2,000 todayWhat it cost against the daily cap. Exposure is a number you can read at any moment.
handled byagent · deep model tierMoney decisions are routed to the most careful tier automatically.
reversal depends on the connected system · opened by 2 people

Refusals write receipts for the same reason approvals do: the customers you turned away are the ones most likely to appear in a chargeback, a review, or a regulator’s question. A tool that only logs its wins can’t answer any of them.

Permitted is not the same as right

Improve policies with evidence from real outcomes.

A decision can satisfy every control and still be the wrong call, and no amount of permission checking will notice. Cevanos watches what happened after the decision, not only whether it was allowed.

Review decisions that need attention.

01 · Reopened

The ticket came back

A resolution the customer reopens within a week was not a resolution. Cevanos traces every reopen to the policy and version that produced it, so a rule that looks efficient in a dashboard and annoying in real life has nowhere to hide.

Flaggedpolicy #7 · v214 of 61 reopened in 7 daysdrafted fix: extend window to 45 days
02 · Reversed

A human overturned it

Every time someone on your team reverses the agent, that is a vote that the rule is wrong. One reversal is noise. Three against the same policy in a month is a signal, and it arrives as a proposed change rather than as a complaint in a retro.

Signalpolicy #14 · v33 reversals this monthreview queued · Priya notified
03 · Refused wrongly

The ones you turned away

Refusals get audited too. When your team keeps overriding the same declines by hand, the rule is too tight and it is quietly costing you customers who never complained. That pattern is invisible in a resolution rate and obvious in a decision log.

Patternpolicy #33 · v122 declines, 17 later approvedproposed: raise settlement to 30%

Find opportunities for more automation.

47escalations

Tracking says delivered, customer says missing, over your $100 ceiling

Your agents approved 39 of 47 anyway. Median order $138. Raising the ceiling to $150 would have covered all of them.

Proposedceiling change · simulated
31escalations

Damage reported after the 30-day window

Your returns page says 30 days. Your team honoured 24 of 31 past it. One of those two is wrong, and the page is what customers read.

Conflictpolicy vs published terms
22escalations

Partial refund requested, customer keeps the item

Median settlement 25% of order value. Policy #33 is drafted and simulated, not live until you say so.

Draftawaiting approval

Every reopen, reversal and overridden refusal is routed back to the policy version that caused it and turned into a proposed change, and everything the agent escalates is clustered against what your team actually did about it. Recommendations remain drafts until your team reviews and approves them.

Security and data

Security and data handling.

Review the controls available today and the capabilities still in development.

Available todayin the product now
✓Encryption in transit and at restConnections are encrypted in transit and data is encrypted at rest, with secrets held in a managed key store. Ask for the current specification for your region.
✓Decision records and exportEvery decision and refusal is recorded and can be reviewed in the console. Retention periods and export formats depend on your plan — confirm both before you rely on them.
✓Roles and limit rightsChanging a limit is a privileged action and is recorded with who changed it and when.
✓Access controls on knowledge and actionsSources are scoped per agent, and each action carries the permissions, limits and approval requirements you assign to it.
Ask for the current written detail on any of these for your workspace and region.
In progressnot yet a commitment
·Model training and retention termsOur position and the provider terms behind it are being documented for publication. Ask for the current written statement covering your workspace.documenting
·Data residencyAvailable regions and what residency covers are being confirmed per region. Ask which regions can be offered for your workspace today.confirming
·Independent auditAudit scope and status are not published here until an assessor’s report supports the claim. Ask for the current status in writing.in progress
·Data-processing agreementDPA, subprocessor list and deletion and export commitments are being finalised. Ask for the current draft.in progress
·SSO and SCIMSAML and directory sync are in build for enterprise workspaces.in build
·Regulated-data supportWe will not sign an agreement covering regulated data before the scope, controls and contracts behind it have been reviewed.on request
Ask about a specific requirementWe would rather lose a deal than mis-state a certificate.

We are early, and we would rather say so than let you find out later. Nothing on this page is a certification, and a statement here is not a contractual commitment — ask for the current written position on anything your review depends on.

Questions

Questions about AI agent governance

Prompt instructions guide model behavior. Permissions and policy checks determine whether a proposed action is allowed to execute. Cevanos applies these controls outside the model for supported workflows.

Review the controls. Then test them on your workflows.

Use historical tickets to examine policy decisions and handoffs before enabling live actions.