Teams / Compliance
The auditor now askswhat your agents did.
ISO 42001, SOC 2, and the EU AI Act ask for a record of what AI systems were given, produced, and did. Most organizations cannot produce one. Speakeasy logs every agent session and tool call under a named person and exports the record to the compliance platform you already run.
01 / The problem
Agents create compliance events at machine speed. Your stack sees almost none of it.
Every prompt an agent sends carries data handling and retention obligations. Every tool call it makes against a system of record carries the obligations that govern changing it. Both happen thousands of times an hour, and three gaps keep them off the record.
Blind spots
The current stack records almost none of it
GRC platform connectors for AI vendors sync user rosters for access reviews and nothing about usage. Coding tools state in their documentation that they log no prompts, responses, or generated code. No vendor sees the tool call into your systems.
Unidentified agents
The log names the account, not the agent or the person
Agents act on credentials delegated from a person, often through a shared service account. Where a record exists, it names the key. It cannot say which agent acted, on whose behalf, or separate a human decision from an agent's.
Dark usage
Personal licenses sit outside all of it
Personal Claude and ChatGPT plans and free-tier coding tools have no admin console, no compliance API, and no audit export. The evidence an organization can produce stops at the licenses it centrally manages.
02 / The shift
Your GRC platform runs the program. Speakeasy runs the control.
The two are complementary. One maps the frameworks, collects the evidence, and drives the audit. The other sits in the path an agent's actions travel and produces the evidence the first one cannot collect.
Your GRC platform
Proves the controls exist
- Maps ISO 42001, SOC 2, and the EU AI Act to controls, owners, and policies
- Polls connected systems on a schedule and collects evidence out of band
- Runs the audit workflow and hands the auditor the package
- For AI, its vendor connectors sync user rosters and nothing about what agents did
Speakeasy
Is the control
- Sits in the path every agent tool call travels, across every agent and license
- Evaluates each call against policy before it runs. A disallowed call never executes
- Records the decision with the action, under a named person, as it happens
- Exports that record into the GRC platform and the SIEM as evidence of enforcement
03 / The control plane
Audit-grade evidence, as a byproduct of enforcement
Speakeasy sits between every agent and every system it touches. Policy runs on each tool call before it executes, every session is captured under a named person, and the record streams into the compliance stack you already run.
- 1. Enforce
- Policy evaluated before execution, not after
- Guardrails for PII, financial, and healthcare data on every payload
- Blocks and flags become findings with the rule that raised them
04 / The mapping
The controls you are audited against, and what produces their evidence
Most of ISO 42001 is a management system. A handful of its Annex A controls describe what has to be true while the AI runs, and they resolve into evidence only at runtime. The same is true of the monitoring criteria in SOC 2 and the record-keeping article of the EU AI Act.
Event logs
ISO 42001 A.6.2.8 · SOC 2 CC7 · EU AI Act Art. 12
A reconstructable record of system operation: what the model was given, what it produced, and what it did.
Every prompt, response, and tool call passes through the control plane, so the log records each action with its arguments, its result, the identity behind it, and the policy decision, uniformly across agents.
Agent sessions docsOperation and monitoring
ISO 42001 A.6.2.6 · SOC 2 CC7
Continuous monitoring of the deployed system while it operates in production.
Tool-call monitoring covers actions against internal systems that a chat product's admin console never sees, with findings raised in the request path and exported as they happen.
Risk events docsIntended use
ISO 42001 A.9.4
The system is used the way it was approved to be used, demonstrably.
Access follows team and role from your identity provider, and every grant, change, and revocation is an audit-log event with the actor and the diff. A call outside the grant never executes.
Audit log docsData handling
ISO 42001 A.7 · SOC 2 CC6 · GDPR
Defined controls over the data flowing through the system.
Guardrail policies for PII, financial data, government identifiers, and healthcare data run on every session, with matches redacted by default and exports stripped of sensitive content unless explicitly enabled.
Data export docsBecoming AI-native meant that we needed an entirely new governance & observability stack. You can't use old tools to cover your team's new way of working.

Shreyas Kumar
Co-founder, Fermat
05 / How it works
From agent action to audit evidence in four steps
The decision comes first and the record follows from it. An audit becomes a filter over evidence that already exists in your own systems.
01
Intercept
Every tool call from every agent in use crosses the control plane before it reaches a system, on enterprise seats and personal plans alike.
02
Decide
The call is evaluated against policy bound to the person's identity and grant. Allowed calls continue. Disallowed calls never execute.
03
Record
The decision, the action, the actor, and the transcript land in one append-only record, redacted by default.
04
Export
Every record streams as OpenTelemetry to the destinations you choose, where the SIEM and the GRC platform already read.
Results
When AI is governed, adoption grows
Numbers from teams running the control plane in production: full-company rollouts, MCP servers shipped in days, and usage that grows because governance stops being per-project work.
Read the MoonPay story100%
Employee AI rollout
rolled out governed AI to the whole company.
60K
agent sessions governed per week
enforces policy across every agent.
200%
MCP usage growth
customers are now agent-based.
Questions
We already run a GRC platform. Why add this?
Our AI vendors have compliance APIs. Isn't that enough?
Why not ban unapproved AI?
Does this make us compliant?
What does the platform itself hold?
Go deeper