Kosem
Concepts
Early access: these docs cover the concepts, with guides and the API reference on the way.

Isolation, network rules and vaults

How Kosem limits what each agent can reach, and keeps a record of what it does.

Every agent is isolated, identified and limited by rules your team sets, enforced outside the agent's reach.

Isolation

Each agent works in its own microVM, with its own kernel, wherever it runs. Agents don't share machines with each other or with your files.

Network rules

Each agent reaches only the destinations its badge names. Everything else is blocked, and blocked attempts show up in its activity.

Vaults

Secrets and network credentials stay in the vault. When an agent needs one, the vault issues a short-lived key scoped to that task and destination. The real key never enters the microVM.

Audit, SSO and SOC 2

Every agent's actions and every change to its access are recorded in an audit log you can export to your own tools. Your team signs in through your identity provider, and we share our SOC 2 report on request.

On this page