USE CASES

Put AI agents to work —
without unchecked access.

Custos sits between AI agents and enterprise tools, enforcing identity, policies, approvals, controlled execution, and auditability.

AI agentIntent to act
CUSTOS CONTROL PLANE
IdentityPolicyApprovalCredentialsAudit
Enterprise toolsMCP · APIs · internal services

THE CORE IDEA

AI can act.
Custos sets the boundaries.

A governed path turns agent intent into an explainable tool decision.

WITHOUT CUSTOS
Agent↓Tool↓System

Direct access makes permissions and outcomes difficult to control.

WITH CUSTOS
Agent↓CustosIdentity · Policy · Approval↓ALLOW / APPROVAL / DENY↓Tool + audit

Every request is evaluated before it reaches the upstream tool.

GOVERNED ACTIONS

Whatever the agent needs to do,
your policies stay in the path.

Custos governs actions through connected APIs, MCP servers, and internal tools. It is a control layer—not a native integration catalog.

Agent wants to…Custos can govern it through a connected tool
📧 Send an emailConnected API / MCP tool
🎫 Create a Jira ticketConnected Jira API / MCP tool
👤 Update SalesforceConnected Salesforce API / MCP tool
💰 Issue a refundApproval policy before execution
🧾 Create a purchase orderConnected procurement API
👥 Access customer dataGoverned customer-data tool
🗄️ Modify a databaseConnected DB / API tool
🚀 Deploy softwareConnected deployment API
🔄 Restart infrastructureConnected infrastructure API
☁️ Create cloud resourcesConnected cloud API
🗑️ Delete recordsDeny or require approval
🔌 Call an internal APIDirectly aligned with Custos

WHERE CUSTOS FITS

Useful wherever
AI needs to act.

Use the same governance layer across financial, customer, engineering, and internal business workflows.

01

FINANCIAL OPERATIONS

Let AI handle financial actions safely.

Govern refunds, billing actions, and financial APIs while keeping high-value decisions with an authorized reviewer.

AGENT REQUEST“Refund $10,000 for Order #123.”HIGH RISK
  1. 01Request received
  2. 02Identity and arguments verified
  3. 03High-value action requires approval
  4. 04Reviewer approves; action executes and is recorded
High-value actions→Human approval→Controlled execution→Audit
02

CUSTOMER SUPPORT

Give AI controlled access to customer systems.

Agents can retrieve orders, update records, or issue refunds without receiving unrestricted access.

Read orderALLOW
Update customer addressALLOW
Issue high-value refundREQUIRE APPROVAL
Delete customer accountDENY

Access is controlled at the tool and action level.

03

ENGINEERING & DEVOPS

Let AI operate infrastructure with guardrails.

Govern access to internal infrastructure APIs while sensitive operational actions remain controlled.

Restart a serviceQuery deployment statusInspect logsTrigger an operational workflow
Example policy AI can restart development services automatically, but production changes require approval.
04

ENTERPRISE APIS & INTERNAL TOOLS

Connect AI agents to the tools your business already uses.

Custos provides one governed path between agents and MCP servers, APIs, and internal tools.

MCP serversCRM APIsOrder systemsFinance APIsSupport systemsInternal developer tools

No native SaaS integration is required: Custos governs supported tool calls at runtime.

SENSITIVE OPERATIONS

Not every agent should
perform every action.

AGENT A

Read customer data ALLOW

Modify customer data REQUIRE APPROVAL

AGENT B

Administrative operation DENY

Every decision follows policy.

AI GOVERNANCE & AUDIT

Know what your AI agents
are doing.

Every important action should be explainable from request to result.

  1. Request received
  2. Identity verified
  3. Tool selected
  4. Policy evaluated
  5. Approval requested
  6. Approved
  7. Tool executed
  8. Result recorded
AUDIT EVENT
Agentsupport-agent
Toolissue_refund
Arguments$10,000 / Order #123
PolicyHigh Value Refund
DecisionREQUIRE_APPROVAL
Approved byfinance-reviewer
ResultSUCCESS

WHAT CUSTOS CONTROLS

The controls that keep
agent actions accountable.

Identity

Know which user, agent, or client is making the request.

Tool access

Control which tools agents can discover and use.

Policies

Allow, deny, or require approval based on the action.

Human approval

Route risky actions to an authorized reviewer.

Credentials

Protect upstream credentials from direct agent exposure.

Execution & audit

Validate governed requests and record important outcomes.

HOW CUSTOS WORKS

Autonomous where safe.
Controlled where risky.

AI agent
↓
CUSTOSIdentity → Tool & argument validation → Policy
↓
ALLOWREQUIRE APPROVALDENY
↓
Enterprise tool / API
↓
Audit

WHO USES CUSTOS

One control layer.
Different teams.

PLATFORM TEAMS

One governed path for AI integrations.

SECURITY TEAMS

Policy, approvals, and audit around agent actions.

ENGINEERING TEAMS

Give AI access to tools without rebuilding every integration.

COMMON QUESTIONS

Good questions.
Clear answers.

What is Custos?

Custos is the control plane between AI agents and the tools they use. It governs supported tool calls with identity, policy, approval, controlled execution, and audit.

Where does Custos sit in an AI architecture?

Agents send supported MCP or API tool calls through Custos before they reach enterprise tools, internal services, or upstream APIs.

Does Custos replace IAM?

No. IAM establishes identity and access controls. Custos governs what an AI agent is allowed to do through connected tools at runtime.

How does human approval work?

A policy can require a separate reviewer before a sensitive tool call proceeds. Approval is bound to the request and can be used once.

Does Custos work with MCP and APIs?

Custos supports HTTP JSON MCP servers, supported OpenAPI specifications, and configurable REST APIs. Compatibility should be checked during integration.

What gets audited?

Custos records request context, policy decisions, approval outcomes, and execution results so important actions can be understood later.

CONTROL THE NEXT ACTION

Give your agents access.
Keep control.

Connect your tools, define your policies, and let AI operate within the boundaries your organization defines.