The control plane for enterprise AI agents

Your agents are running everywhere. You don't have one place to govern them.

Across your org, engineers are running AI agents that spend real money and touch real systems — with no central budget, no policy, no audit trail. SLAW is the control plane you don't have yet: centralised governance and spend control over the agents you bring under it, with each instance fully self-hosted and sovereign.

Self-hosted only · no SaaS · open source · sovereign by design · for SMEs and Tier 1 enterprises

Bring the agents and tools your teams use under one control plane


The gap

Shadow AI is already in your org. Nobody owns the controls.

Agents run unattended on company laptops and CI runners, burning tokens and acting on your code, data, and tickets — with no central budget, no policy, no record. You have a runtime problem and a governance vacuum. SLAW gives you somewhere to bring that work: run agents through SLAW and they inherit central budgets, gates, and audit. It's the place to onboard agents under control — across teams and machines.

  • Centralised spend control. Set enterprise budget and token caps, push them to enrolled instances, and catch runaway cost early with alerts and circuit breakers.
  • Policy and approval gates. A named human approves anything irreversible — merge, deploy, spend, sign-off — enforced by the platform, not convention.
  • Centralised locks & revocation. Approve instances by rule, revoke a key to block future sync, and master the skill catalog the fleet runs.
  • An audit trail across the fleet. Who ran what, when, and at what cost — attributable per action, with retention windows you set.

One control plane, two layers

Govern from the centre. Run on the edge. Give up neither.

A control plane has to do two jobs that most tools conflate: govern the whole estate centrally, and run agents locally without leaking your data. SLAW separates them so you get both.

Botfather — the centralised control plane

The governance layer your fleet reports into. Fleet-wide visibility, cost caps pushed from the centre, policy and approval rules, alerts, and centralised locks and revocation — self-hosted only, with no hosted version, so it runs entirely inside your environment and no metadata leaves the enterprise.

SLAW — the governed runtime

The self-hosted runtime each team runs. It executes agents under the org chart, budgets, and gates the control plane sets — bringing any agent with an adapter (Claude, Codex, Cursor) under the same controls, with its actions logged and attributable.

The bigger picture

Built to a reference architecture, not just a roadmap.

SLAW and Botfather are our open-source implementation of the Agentic Control Plane — Layer 2 of the Enterprise Agentic Reference Architecture, our proposed seven-layer, nine-principle blueprint for running agents at enterprise scale.

  • The control plane is pluggable — never a lock-in. Swap the framework without rearchitecting governance.
  • Orchestration is not fleet governance — distinct concerns, distinct components. That's why there are two products.
  • A gate at every consequence; cost as a first-class control — enforced by the platform, not by convention.
enterprise-agentic-reference-architecture · v1.0
The Enterprise Agentic Reference Architecture — seven stacked layers with the Agentic Control Plane (SLAW + Botfather) highlighted.

Rollout

From shadow AI to a governed estate in three moves.

01

Stand up the control plane

Deploy Botfather on your own infrastructure — zero-config, embedded database. Set your enterprise budgets, policies, and approval rules once.

02

Bring teams under governance

Point each team's SLAW instance at the control plane. Approve by rule, and every agent they run through SLAW inherits central budgets, gates, and audit.

03

Govern continuously

Watch fleet spend and policy in real time. Cap, lock, or revoke from the centre. Prove control with an attributable, fleet-level audit trail.

Controls & sovereignty

Centralised control, with no hosted service to leak to.

Most "central visibility" means shipping your data to someone else's cloud. There is no hosted SLAW or Botfather — it's self-hosted software only. Instances and the control plane run on your own network, so the data used to govern has no external endpoint to reach. The only outbound traffic is the model provider you pick for your agents, which you can self-host too.

  • Set an enterprise budget and token cap, override per team — enforced by the platform.
  • Alerts on budget breach, offline, stale, 3× spend spikes, and version drift.
  • Centralised locks: approve by rule, revoke a key, and master the skill catalog the fleet runs.

For evaluators

The questions a buyer asks first

Where does it run, and what data leaves our environment?

Nothing leaves your environment, because there is no hosted version to send it to. Both the runtime and the control plane are self-hosted inside your own tenancy. Within that boundary, instances report governance metadata to the control plane over your own network: squad and agent names/roles, budgets, cost and token metrics, run status, and project/issue titles (titles are opt-out per instance). Config, secrets, issue bodies, and logs never leave the instance. The only traffic that exits your environment is the model provider your agents call — and you can run self-hosted or open-weight models to keep that inside your boundary too.

How do we control spend across teams?

Set an enterprise budget and token cap centrally, override per team, and the platform enforces it — soft or hard. Alerts fire on breaches and 3× spend spikes, and circuit breakers quiesce runaway work before it shows up on the bill.

Can we prove control for audit and risk?

Agent actions are logged and attributable with trace IDs, and anything irreversible passes a named human approval gate. The instance holds the detailed local record (issue bodies, logs); the control plane keeps fleet-level activity, cost, and status within retention windows you configure. You can lock or revoke any instance from the centre — note that enforcement is fail-open, so an already-enrolled instance keeps running if the tower is unreachable.

Are we locked into one vendor or model?

SLAW and Botfather are MIT-licensed and self-hostable (github.com/slaw-ai), which substantially reduces lock-in — you hold the code and run it yourself. Bring any agent with an adapter (Claude, Codex, Cursor, Gemini) and any model, frontier or self-hosted.

Bring your agents under one control plane.

Run agents through SLAW, governed by Botfather from the centre — self-hosted on your own infrastructure. Talk through an enterprise rollout when you're ready.