The governance plane
The governance plane supervises AI agents while they work. You decide what each agent is allowed to touch. Any agent you already use, in any harness you want, anywhere a server can exist. Bring your own AI, your own storage, your own systems. The plane is the plumbing and the logbook, and what flows through them is yours. Built for government and enterprise.
Moonwalker builds AI software for any mission, from command, control and communications software and agentic software to private AI models and digital twins, and the governance plane they can run on. The plane applies zero trust to the AI itself. Every agent action is checked against policy where it happens, at the file, the command, the browser and the API. An action beyond granted authority is denied. Sensitive actions wait for a human. Every action is recorded outside the agent in a tamper-evident record. It installs air-gapped or connected, on Windows and Linux, and the customer keeps full data sovereignty, with your AI provider, your storage and your keys.
DecidePolicy decision point for every agent action
EnforceEnforcement at the application, API, data and endpoint
AccessLeast privilege and privileged-activity control for agents
RecordData integrity, audit and compliance evidence
WatchMonitoring of agent actions and central policy management
Works with the agents you already use
- Claude Code
- Claude.ai
- Codex CLI
- ChatGPT
- Any MCP client
The four promises
Every part of the governance plane keeps four promises.
01Any AI, no lock-in.
Bring the agent, the harness and the model you already use, or have us build them. The plane attaches no model of its own.
02You know who is acting.
Every action is tied to the person or system that asked for it and the agent that carried it out.
03The agent does only what you allowed, and you can stop it.
Authority is checked at the point of action. Risky steps meet a warning, an approval or a hard stop. Changes are backed up before they happen.
04You hold the proof, and it has a price.
Every action lands in a tamper-evident record on your storage, under your keys. That record makes agent work reviewable, defensible and insurable.
The product
This is what a governed action looks like.
Two records from a Moonwalker session. One action the policy allowed, one it refused. The allowed record is real. The refused one is shown against a sample path. Both were written the same way.
● Allowed · recorded
- action
- web_fetch
- target
- https://moonwalkercorp.com
- capability
- read
- scope
- single target
- reversible
- trivially
- credentials
- none touched
- risk
- 0 · green
- friction
- audit only
- audit id
- 5fd643f9-35b9-4227-b55b-053d1a6dafa9
● Refused · recorded
- action
- read
- target
- C:\Payroll\2026\direct-deposit.csv
- policy
- path is denied by security policy
- result
- nothing returned to the agent
- recorded
- the request, the rule, the refusal
Allowed or refused, read or write, every call is recorded the same way. Whether a step outside its permissions is refused, flagged, or only logged is a setting you control.
How it works
Nothing to migrate. Nothing leaves.
01 / Runs where you are
One process wherever the agent works
A desktop, a phone, a laptop, inside your app, in your cloud, on a disconnected network, in a robot. Anywhere a server can exist. No kernel module. No rewrite of the agent. It sits between the agent and the machine.
02 / Plugs into the agents you have
The open tool protocol they already speak
Your agents connect to Moonwalker and get files, shell, browser, desktop, scheduled jobs, and worker agents through it. Bring your own model, or one we build for you. The plane attaches none of its own.
03 / Writes to storage you chose
The record lands on your side, never ours
Write-once storage you picked. Opening it takes a person you designated, and the opening is itself recorded. We see none of it.
What Moonwalker governs
One authority plane for the messy places agents actually work.
Governance that stops at the model boundary governs nothing. Moonwalker sits where autonomous work becomes real: local machines, project vaults, browser sessions, worker agents, scheduled jobs, and the evidence they leave behind.
Local workspaceFiles, shells, browsers, and desktop
Read and write access, shell execution, code workers, and browser sessions, each bound to an explicit scope, a backup posture, and policy the customer owns. Governed database access runs on the same contract, scope and evidence over the query, with the data never leaving your systems.
Agent operationsWorkers, packets, jobs, and closeouts
Long-running autonomous work becomes reviewable: a task packet, a bounded dispatch, a required artifact, run history, review, and a closeout that says what actually happened.
Human authorityRisk friction where it matters
Routine actions flow without ceremony. Consequential, credential-bearing, outward-facing, or hard-to-reverse actions meet warning, attestation, approval, or a hard stop.
Evidence layerA flight recorder for autonomous action
Because instructions, task context, and available evidence all cross the control plane, the record preserves what the agent was told and what it knew at the moment it acted, context that otherwise vanishes the instant the action completes.
Built on the plane
Products that share one authority and one record.
The plane is the foundation. Each product on it uses the same authority checks and writes to the same record, under plain names.
Browser and webMoonwalker Governed Browser
A governed browser kept on your machine. Several agents can drive it at once, each identifiable in the record, and one latch stops every agent's work at once.
Record and reconstructionMoonwalker Evidence Recorder
Every call written outside the agent, hash-chained, on your storage under your keys, and rebuilt afterward in order, by agent and by authority.
AgentMoonwalker Agent Harness
Bring your own agent or use ours. Every call it makes goes through the plane, so approvals, takeover, policy and the record come with it.
Stop and roll backMoonwalker Recovery
Stop an agent, seize its work and roll back its changes, from a phone if need be. Changes are backed up before they happen.
MemoryMoonwalker Agent Memory
Memory with retention, purge, key control and legal hold, so an agent remembers what you allow and forgets what it must.
SecretsMoonwalker Credential Broker
Agents use credentials by reference, without ever holding them, and every use is attributed in the record.
OperationsMoonwalker Command Center
Every agent's work, its authority and its record in one view, with voice control under the same authority.
Evidence captureMoonwalker Sealed Capture
A governed web crawl that captures every page it visits into the record, so what an agent read becomes evidence.
RiskMoonwalker Risk Score
A per-action risk read taken before the action runs, kept in the record, and ready to share with an underwriter. Insurability →