Tegrix control plane
Inventory, External Graph context, Policy & Controls, approvals, decisions, and evidence are operated from Tegrix.
Architecture
Tegrix connects to existing agent platforms and enterprise systems, builds the agent inventory and External Graph, applies Policy & Controls at runtime, returns a decision, and keeps the evidence.
Architecture fit
Where Tegrix runs
Inventory, External Graph context, Policy & Controls, approvals, decisions, and evidence are operated from Tegrix.
Microsoft, AWS, Google, SaaS tools, identity systems, logs, and business systems continue to run in place.
Controls are added only where an agent action needs a decision before execution continues.
Hosted SaaS is the default evaluation path. Stricter customer-cloud or hybrid boundaries can be evaluated where required.
How Tegrix connects
Start by bringing in inventory, identity, ownership, configuration, tool, and event signals.
Normalize platform-specific agent records into a common operating view.
Use SDK calls when customer-built agents need a Tegrix decision before a governed action.
Place controls around high-impact tools without replacing the agent platform.
Use only when the workflow needs an inline traffic or tool-invocation boundary.
What data Tegrix requires
Agent name, provider, environment, owner, status, source, and last-seen signals.
Team, business owner, technical owner, identity, service principal, and approval path.
Tools, systems, data classes, workflows, policies, controls, and runtime events.
The action requested, relevant facts, matched controls, decision, and execution state.
The retained record needed to explain what was attempted, decided, invoked, prevented, or approved.
Runtime characteristics
A governed action is sent to Tegrix, evaluated against context and controls, then returned as allow, deny, hold, redact, or approval required.
The provider still executes the action when allowed. Tegrix decides whether the action should continue.
Fail-open or fail-closed behavior should be chosen per governed path based on business impact and risk.
Runtime paths should be designed with the customer's resilience requirements before enforcement is enabled.
Decision records are retained for governed actions so review does not depend on screenshots across tools.
Tegrix should receive the fields required for a decision and evidence record, not a full copy of every source system.
Canonical flow
Connectors build visibility. External Graph adds enterprise context. Policy & Controls return a runtime decision. The provider executes only when the decision allows it, and Tegrix keeps the evidence.
Architecture FAQ
Adapter placement
Tegrix can start read-only, then add SDKs, adapters, wrappers, governed tools, or gateways where a workflow needs a runtime decision.
Latency
Decision timing should be measured on the governed path during evaluation. Do not enforce a path until the business owner accepts the decision window.
Availability
Fail-open or fail-closed behavior should be chosen per governed action before enforcement goes live, based on business impact and risk.
Data boundary
Tegrix should receive the fields needed for inventory, context, policy decisioning, approvals, and evidence, not a full copy of every source system.
Policy deployment
Controls are packaged, assigned, tested, and published to the governed path selected by the customer.
Evidence integrity
The evidence record should retain the action, evaluated facts, matched controls, decision, provider invocation state, approval, and final outcome.
Integration scope
Existing Microsoft, AWS, Google, SaaS, and custom agent platforms remain in place. Tegrix connects where visibility, context, evidence, or runtime control is needed.
Authority
Tegrix can evaluate owner, requester, runtime identity, service principal, policy assignment, approval path, and business context before a decision is returned.
Graph freshness
Connectors and runtime events refresh inventory, ownership, tools, policies, data relationships, and evidence as the environment changes.
Not gateway-only
Gateways operate traffic and routing. Tegrix is focused on the enterprise action: context, policy, decision, approval, provider state, and evidence.
Review the connection model, deployment boundary, runtime behavior, and evidence record before expanding enforcement.
Open white paper