Govern AI-assisted work at scale.

Lornian gives large organisations the controls needed to trust autonomous AI agents: a risk-tiered policy router, an immutable Co-Sign audit ledger, fine-grained RBAC, and local-first architecture.

Autonomous AI work requires verification, not blind trust.

Enterprise engineering teams want the velocity of autonomous AI coding agents, but compliance and security teams cannot tolerate unverified writes or ungoverned tool executions.

Lornian enforces a risk-tiered AI policy router across all agent runs. Low-risk operations execute freely with undo logs, while high-risk writes automatically pause execution and route through an immutable Co-Sign ledger for human-in-the-loop sign-off.

Governance you can see, not just claim

Passkeys instead of secrets, an append-only ledger, and permission scopes that gate every role — rendered as the mechanisms they are.

AUTH

No secret to phish

WebAuthn passkeys replace the password outright. There is nothing memorized to leak, because nothing memorized exists.

LEDGER

Written once, kept forever

Auth, workspace, and Co-Sign events land in separate append-only Postgres tables — queryable by your own tooling, not an export you request.

SCOPE

Roughly twenty gates, not one switch

Granular RBAC scopes decide what any role can touch, down to the workspace, project, or knowledge base.

Four ledgers, all in your Postgres

Separate append-only tables per domain, queryable by your own tooling — not an export you request from a vendor.

Risk-Tiered Policy Router · Co-Sign Audit Ledger
Append-only
Pick a tool. See what the router does.

trigger_deployment · high

🔒 Waits for a human
Try:
The run stops here until someone signs:
Parked state is written to Postgres, so a restart does not lose it. The reviewer sees the tool, its arguments and the Agent’s rationale. Approve and the run resumes at this exact step; reject and it continues without it.
[AUDIT] auth · workspace · cosign · ai_run_steps — append-only, in your Postgres
[18:42:01.09]cosign_requestsREVIEW_APPROVED · publish_knowledge_doc · signer: Alex Rivera · run resumed at step 4
[18:42:04.44]workspace_auditCUSTOM_ROLE_ASSIGNED · role: Compliance Auditor · 6 scopes granted
[18:42:09.12]webhook_deliveriescosign.request_approved → HMAC-signed payload dispatched (200 OK)
  1. Every authentication

    Logins with source IP, token rotations, revocations, passkey registrations, password resets. WebAuthn passkeys mean the phishable secret is absent from the table because it does not exist.

    Auth
  2. Every permission change

    Role assignments, invitations and revocations, and custom-role definitions across roughly twenty permission scopes. Who could do what, on which date.

    Workspace
  3. Every AI decision

    The requested action, its arguments, the Agent’s stated rationale, the human who decided, and whether the run began in a chat, a schedule, a background scan, or an accepted proposal.

    Co-Sign
  4. Every reversal

    Medium-risk writes persist their own inverse, so the record answers what was undone, by whom, and against which original step.

    Undo

Governed AI work, not just visible dashboards

Without governance

No accountability trail for AI-assisted decisions or agent tool calls

The “visibility paradox”: dashboards everywhere, clarity nowhere across engineering teams

Fragmented access control across disconnected project and documentation tools

Compliance teams wary of ungoverned autonomous agent activity and data leaks

With Lornian Enterprise

Risk-tiered AI policy router halts high-risk writes for human review

Immutable Postgres audit trail for Auth, Workspaces, and Co-Sign

Granular RBAC (~20 scopes) with custom role definitions

WebAuthn passkeys, device-aware sessions, and one-click revocation

29%

baseline trust in AI for complex enterprise tasks

Industry research, 2026

100%

immutable Postgres audit trail across Auth, Workspace & Co-Sign

Lornian Governance Engine

20+

granular RBAC permission scopes with custom role definitions

Enterprise Access Control

Bring governed AI work to your organisation

Deploy autonomous AI agents with immutable audit trails and enterprise access control.