Governance
Promptev governance means an AI agent asks a person before any action you mark, masks sensitive data such as e-mail addresses and card numbers before the AI model reads it, and records every run and decision in an audit trail.
SOC 2 Type II
Maya asksRefund order 1042 and file the receipt.
Tool result · Orders
Customer[EMAIL]
Card[CARD]
Masked before the model
AI modelreads [EMAIL] and [CARD] only
ProposesGoogle Drive: create folder “Refund 1042”
Approval required
Create folder · Google Drive
ApproveReject
Approved by Sam Lee · folder created
How it works
Step 1
For each tool an agent can use, you choose when it must stop and ask: every time, once per conversation, or only when a condition you set is met, such as an amount over 1,000.
Nothing is sent, filed or changed except by the rule you set.
Sensitive values are dealt with before the model reads them.
Step 2
Masking rules find e-mail addresses, phone numbers, card numbers, bank account numbers, social security numbers, API keys and any pattern you add. They apply to the documents an agent finds and to what its tools return, before the AI model reads any of it.
The model works with [EMAIL], not the address.
And everything that happens is written down.
Step 3
The audit trail lists every run: who started it, which agent and version answered, where the request came from and what it used. Approval decisions and settings changes are recorded with the person who made them.
You can answer “who did this, and when?” without asking around.
Approvals
The agent stops and shows an approval card with the tool and the exact details it will use. Nothing runs until someone chooses Approve or Reject.
Access
Example
A support agent looks up an order. The record comes back with the customer’s e-mail address and card number, and the model sees [EMAIL] and [CARD] instead. Its refund tool is set to ask only when the amount is over 200.
A 40 refund goes through on its own. A 900 refund waits for the finance lead, who approves it from an e-mail. The audit trail shows who approved it and when.
Questions
Yes. Promptev is SOC 2 Type II. Inside the product, the audit trail records every run, every approval decision and every settings change, so you can show who did what and when.
Only if you allow it. For each tool you choose: no approval, ask every time, ask once per conversation, or ask only when a condition is met. An action that needs approval waits for a person, and the request expires if nobody answers in time.
Not from your documents and tools, where your masking rules cover it. Promptev masks matching values in what an agent finds and in what its tools return, before the model reads them. What a person types into the chat is passed on as written.
Yes. Promptev supports single sign-on over OpenID Connect or SAML 2.0, with providers such as Microsoft Entra ID, Okta and Google, and SCIM 2.0 to add and remove people from your directory. You can require it for everyone, or for everyone except viewers. Owners keep an e-mail sign-in, so a broken identity provider cannot lock you out.