Decide what every AI agent can see, do and spend
The Selfic control plane sits between AI and your enterprise. Before any agent touches data or takes an action, it checks who is asking, what they are allowed to do, which rules apply, whether it fits the token budget and whether a person must approve. Then it records everything.
For CIO, CISO, security, AI governance and platform teams
Read open invoicesChecking
- Agent
- ChatGPT Enterprise
- User
- finance.analyst
- Tool
- erp.get_invoices
Nine controls, one place to manage them
Select a capability to see what it does, or let the tour play.
Know every agent that touches your enterprise
Agents are registered with an owner, a purpose and a risk tier. Anything unregistered is blocked at the door.
Verify the person behind every request
Users sign in through your identity provider with MFA. Selfic issues a short-lived token scoped to exactly what they may do.
Access that follows role, department and group
Define access once for each role. It applies in every agent your people use.
✓ allowed M masked A approval to change – no access
Rules applied on every request
Policies are written in plain language and evaluated in real time, before data leaves a system.
Govern which tools agents can use
Every MCP server and tool is approved before agents can see it. Risky tools are off or need approval.
sap.get_invoiceReadsap.post_paymentApproval requiredcrm.read_accountRead, maskedcrm.export_allNot approvedhr.read_salaryNot approvedAgents never hold your keys
System credentials live in the Selfic vault. Agents receive a capability, never a password, so there is nothing to leak.
People decide where it matters
High-impact actions pause and wait for the right owner, with the full context in front of them.
Release payment run of $184,200 to 12 suppliers
Requested by AP agent for finance.analyst. All 12 invoices matched to purchase orders.
Central control of all AI spending
Set token budgets for every department, group and user on every agent. Consumption is tracked on each request, and limits are enforced before the spend happens.
A complete record of every decision
Every request, decision, approval and outcome is logged. Export it to your security tools or hand it to auditors.
One place to control every AI token your enterprise spends
Decide how many tokens each user, department and group can spend on each agent. Watch consumption as it happens, and restrict spending automatically, before it becomes a surprise invoice.
- Budgets at every level
Set limits for the organization, each department, group and individual user.
- Limits for each agent
Give Finance 5M tokens a month on ChatGPT and 3M on Claude, and set something different for every team.
- Automatic restrictions
Warn owners at 80%. At 100%, pause, require approval, or route to a lower-cost model.
- Real-time monitoring and chargeback
See who spends what, on which agent, and allocate AI cost back to each department.
| Department | Claude | ChatGPT | Copilot | Internal agents |
|---|---|---|---|---|
| FinanceFP&A, AP | 1.8Mof 3.0M | 4.1Mof 5.0M | 2.6Mof 3.0M | 1.3Mof 2.0M |
| RiskERM, compliance | 2.2Mof 4.0M | 1.4Mof 3.0M | 0.9Mof 2.0M | 1.6Mof 3.0M |
| OperationsClaims, service | 3.1Mof 4.0M | 5.6Mof 6.0M | 2.2Mof 3.0M | 3.6Mof 4.0M |
| HRPeople ops | 0.4Mof 1.0M | 0.8Mof 1.5M | 0.6Mof 1.0M | 0.4Mof 1.0M |
| ITEngineering | 3.9Mof 6.0M | 2.7Mof 5.0M | 2.4Mof 4.0M | 2.4Mof 5.0M |
Rules your security team can read, and your auditors can check
Examples of policies you can set in the control plane.
When an external agent reads personal data
Then mask national ID, bank and contact fields
When any agent tries to change a payment
Then require approval from the finance owner
When a contractor uses any agent
Then allow published policies and documents only
When a department reaches 80% of its token budget
Then notify the owner and route to lower-cost models
Illustrative policies. Rules are configured to your organization.
From scattered controls to one control plane
| Without a control plane | With the Selfic control plane | |
|---|---|---|
| Agent inventory | Unknown, spread across teams and vendors | One registry with owners and risk tiers |
| Credentials | Shared accounts and personal tokens inside agents | Held in the vault, never exposed to agents |
| Access | Configured separately in every tool | Defined once by role, department and group |
| Sensitive data | Depends on each vendor's settings | Masked by your policy before it leaves the system |
| High-impact actions | No consistent approval step | Approval gates with recorded decisions |
| AI spend | Spread across vendor invoices, with no limits per team | Budgets by user, department, group and agent, enforced in real time |
| Evidence | Vendor logs, app logs and chat histories | One audit trail across every agent |
The control plane decides. The execution plane delivers.
Every request passes through both. Governance without execution stops at "no". Execution without governance never reaches production. Selfic gives you both in one platform.
Any AI
Claude, ChatGPT, Copilot, your own agents, vendor agents and workflows.
AI control plane
Who may act, on what data, with which tools, and when a person must approve.
AI execution plane
Connectors, context, tools, agents and workflows that complete the work.
Explore the execution planeResult: real business work completed in your systems, with every decision recorded.
Every Selfic solution runs on this plane
Controls which risk data agents may read and routes incidents and action plans for approval.
Explore Selfic ERM →WSelfic EISGoverns every step of automated processes, from scoped reads to approval gates.
Explore Selfic EIS →GSelfic EAGThe foundation of AI governance: identity, access, token budgets and audit for every agent.
Explore Selfic EAG →Built for the way regulated enterprises operate
Put every AI agent behind one control plane
See how Selfic governs identity, access, policy, approvals and audit for every agent in your enterprise.
