Self-hosted deployment Model agnostic

Know Every Agent
You're Running.

Govern Every Call It Makes.

Forgebench agent inventory dashboard
Forgebench organisation overview dashboard

Self-hosted &
Model Agnostic

ISO 27001 certified
ISO 9001 certified
AICPA SOC 2 compliant

Six Capabilities That Fence
Your Agents

Forgebench Gives Every Agent Its Own Credential, Its Own Ceiling
And Its Own Record — So You Can See, Live, Every Call It Makes,
Who Owns It, And What It Costs.

Coverage

One Governed Path

Every call routed through Forgebench, on the agent's own credential. No agent holds a provider key.

Registry

An inventory of every agent

Owner, state, version, tools, spend against ceiling — registered before its first call.

Policy

Permissions and guardrails, set centrally

The tools and MCP servers an agent may reach, and what may leave your perimeter. Bound at registration, enforced on every call.

Control & Attribution

A ceiling before the spend

Caps per model, agent and key, enforced before the round-trip. Whichever cap is reached first refuses the next call.

Guardrails

Input-output safety reviews

PII, secrets and denylist checks off the response path. Flagged against the agent, never blocking.

Auditability

Tamper-evident audit record

Every call and every operator action, hash-linked. Editing an entry is detectable.

Forgebench agent inventory and registry dashboard

Registry · How an agent gets governed

One Short Form, Before The Agent’s First Call

01

Register

Name the agent, name its owner, and tag it to the features it serves.

02

Provision

A unique agent identity is minted, and tool bindings are added to its allowlist.

03

Inventory Row

The agent appears with owner, tags, state, version and last seen. Listed, but not active.

04

Governed On First Call

The first call flips it live; there's no separate path for an agent.

Deployment & Implementation

Runs In Your Environment.
Proved And Signed-Off In 4 Weeks.

Where it runs. Your infrastructure, your identity provider, your policies.

Integration

Host-provisioned. Change an endpoint.

Developers and agents keep working exactly as they do now; the only change is which key they hold.

Identity & Tenancy

Dedicated instance on Forgebench cloud.

Or self-hosted in your Kubernetes cluster with your identity provider, WAF, and network policies.

Security

Single sign-on against your existing provider.

With a fully visible working set. Four roles: CTO, engineering manager, platform operator, developer.

Three phases, each exiting on evidence.

Week 1

Planning & Setup

Scope one live workflow and a pilot group of 10–25 developers. Lock identity and SCIM sources, provider accounts, 2–8 agents and MCP servers, guardrails, data-policy defaults, and access both ways.

EXIT: Pilot plan signed.
Planning & Setup
Weeks 2–3
Build & Govern
Weeks 3–4
Review &
Sign-off

Next steps

Prove It On Your Own Workload.
Four Weeks, And Every Phase
Exits On Evidence.

A fixed four-week pilot in your own environment — 10 to 25 developers,
and the two or three agents already running in production.

You don't commit to a platform to run it.