Skip to content
Policy-as-code

Lyra

Agent policy-as-code

The capability-brokered, information-flow-aware policy engine.

APG · PreventionAgent Policy Governance
What it does

One policy language and one signed audit log govern what every agent may do: which tools, MCP servers, models, data, and egress. Written once, enforced at the endpoint by Beacon and across the mesh.

  • Capability-brokered, information-flow-aware policy-as-code.
  • Authored once; enforced deterministically at the endpoint, no cloud round-trip.
  • One signed audit chain covers OWASP ASI and NIST AI RMF / ISO 42001 alike.
The problem

“Allow all” is your current AI-agent policy.

Today an agent that authenticates can invoke any tool, reach any MCP server, and touch any data its session allows, with no record of what it did. Auditors want a written policy; NIST AI RMF and ISO 42001 want evidence that it is enforced. Right now you have neither.

What Lyra does about it

The questions your reviewers will ask.

“I can’t scope what an agent may do.”

Lyra is capability-brokered: grant agent X the capability to call tool Y against resource Z, and nothing more.

“Per-call allow or deny isn’t enough.”

It is information-flow-aware, so policy follows the data across tools, not just one call at a time.

“I can’t roll out enforcement safely.”

Run any policy in monitor mode first to see what it would decide before it blocks anything.

“I run four different AI vendors.”

One policy, authored once, governs Claude Code, Cursor, Codex, and whatever ships next quarter.

“I need audit evidence, not a slide.”

Every decision lands in one signed, tamper-evident chain that maps to OWASP ASI and NIST / ISO.

What you can show

Evidence, not assurances.

What a security leader walks away able to demonstrate to a board or an auditor.

  • A written, enforceable policy you can hand an auditor.
  • One signed audit chain over every agent decision, mapped to the frameworks you report against.
  • Evidence that enforcement was proven in monitor mode before it went live.
For your security team
Model
Capability-brokered, information-flow-aware
Enforcement
Local at the Beacon, deterministic
Rollout
Monitor-first
Audit
Signed, hash-chained
Standards
OWASP ASI, NIST AI RMF, ISO 42001
Where it fits

One module of the Alyria platform.

Lyra works alongside the rest of Alyria — prevention and detection for every AI agent your people run, tied together by one policy engine and one signed audit chain.

See how the whole platform fits together

Put Lyra to work.

Deploy Beacon read-only and see how Lyra fits at the endpoint, under your keys.