What oversight toolkits are good at
An inventory of agents and their owners. Central configuration across teams. Dashboards, anomaly detection and reporting over what agents did. Mapping activity to internal control frameworks. Answering someone who asks what runs in production. These are real problems, they are organisational rather than per-call, and CTRLRun does none of them.What they do not do
When to use both
A fleet needs both kinds of answer. Use the toolkit for the inventory, the reporting and the organisational questions, and put CTRLRun in the path of the actions that cannot be undone. The receipts are portable JSON and go wherever your reporting lives; the OpenTelemetry sink puts each action in the same traces your platform already collects.What CTRLRun will not claim
CTRLRun makes no standards claim and does not map itself to a control framework as a product feature.controls: in a policy lets you name the house control an action satisfies and cites
it on the receipt, uninterpreted. The reading of the OWASP Top 10 for Agentic Applications in
this repository names the four entries it does not address. Enforcement in the path and evidence
out of it is what is on offer; the argument that this satisfies a given framework is yours to
make.
Next
- Receipts and evidence · Policy YAML reference.
- How this is built: what the guarantees rest on.
- Get started · Why.