Guardrails as procedures, not prompts
Agents run standard operating procedures: typed steps with checkpoints, versioned like code. Not arbitrary commands against your cloud, and not a system prompt hoping for the best.
For platform & security teams in regulated Europe · AI agents in production
Bugz is the control plane between your AI agents and your cloud. Every change runs a procedure, passes compliance checks and waits for an approver who is never the requester. Self-hosted, in your jurisdiction.
procedure provision_vm v4 · requester claude-code@platform
checkov ✓ · trivy ✓ · blast radius: 3 resources, 1 subnet
A person who is not the requester reviews the plan and approves. Until then, nothing applies.
waiting for approval · recorded · self-hosted
The problem
— Traficom & National Emergency Supply Agency, agent-security guidance 5/2026, January 2026
53%
of organisations have had AI agents exceed their intended permissions. Only 8% say it has never happened. — Cloud Security Alliance, n=445, Apr 2026
35%
of scope violations slip past human approvers who review raw diffs. — 409,000 approve/deny decisions, Aug 2026
“I decided to do it on my own… when I should have asked you first.”
Also: 0% of one model’s AI-generated configs passed Checkov while 77.8% applied cleanly · Vargas, Mansilha & Kreutz · arXiv:2608.02672 · Aug 2026
How it works
Agents run standard operating procedures: typed steps with checkpoints, versioned like code. Not arbitrary commands against your cloud, and not a system prompt hoping for the best.
Framework controls run against every proposed change before an approver ever sees it.
Who proposed, who approved, what applied: every step recorded, in order, with the diff.
Claude Code, Copilot or any MCP agent — they all come through the same gateway with the same rules.
Regulated Europe
Works with
Where it runs
Self-hosted, managed, or air-gapped. Agent traffic never has to leave the EU.
Your cloud, your keys.
Run by Bugz, in your region.
No outbound traffic at all.
Proof
Public sector · Government of Karnataka
We forward-deployed a cyber-resilience platform for Karnataka’s government and its digital public infrastructure — built and shipped alongside the state’s teams, guided by CySecK and IISc, where the cost of failure is measured in public trust, not just downtime.
Autumn 2026
Landing in Helsinki.
Bengaluru and Helsinki. Working with Finnish platform teams and managed-cloud partners on DORA and NIS2 agent readiness.
Thirty minutes, your cloud or ours, no slides.
Bugz Services
We also run it with you: forward-deployed engineers operate your agents through the same control plane. Start with a DORA / NIS2 agent-readiness assessment.