Control · Imperium

Control the intelligence running your organization.

Imperium gives your people one workspace for the AI they are allowed to use, and gives the organization one control plane for every model, agent and tool. Each request is checked for identity, data, policy, budget and risk before it runs, and every consequential action leaves evidence.

  • For employeesa better way to work with AI
  • For managersvisibility, cost and productivity
  • For security and ITpolicy, identity, enforcement, evidence

Illustration: gold concentric governance rings. A request enters from the left, passes eight checks (identity, trust, data, policy, budget, model, risk and execution rights) and is routed to a permitted model, or stopped.

The problem

AI did not enter the organization through one door. It arrived through hundreds.

Chat assistants in the browser, coding agents on laptops, local models on a spare server, automations wired to MCP tools. Each one has its own login, its own history, its own provider key and its own idea of what it may do. Nobody set out to build that estate, but most organizations now have one.

  • Which models and agents are actually running, and who owns them?
  • What confidential information has already left the building?
  • Who authorized that agent, and what can it touch right now?
  • What is all of it costing, and for which team?

You cannot control what you cannot see.

Illustration: a scan passes across scattered AI tools. Each unmanaged tool it reaches is identified and given an owner and a policy.

What Imperium is

One workspace for people. One control plane for the organization.

Imperium sits between everything that asks and every AI that answers. Employees get a single, better place to work with approved models, agents and documents. The organization gets one place to discover, govern, decide, control, observe, verify, optimize, protect and execute. Both are the same platform, so the rules people work under are the rules the organization set.

The workspace

Work with AI without losing control.

  • Approved models in one place. OpenAI, Anthropic, Google, Microsoft, local and internal models. Ask once, compare answers, or let Imperium pick a permitted model.
  • One history across every model. Search your own AI work by project, agent, model, document or date. The model can change; the session does not.
  • Memory and instructions you can see. Your preferences extend the organization's policy but never override its mandatory controls.
  • Documents, scans, voice and messages. Everything enters through the same boundary and is classified before any model sees it.
  • Policy that guides, not only blocks. When something is not allowed, the answer says why and what will work instead.

The control plane

Every model, agent and tool call becomes a governed request.

  • Who is asking. Every human, agent, sub-agent, service and workflow has an identity with an owner, a scope and a budget.
  • What it may touch. Data is classified and its origin travels with it into every answer.
  • Where it may run. Policy decides the route: local, private or external. Not the prompt, and not whichever key a developer had.
  • What it may do afterwards. Consequential actions stop at a gate that allows, blocks or waits for a person.
  • With evidence. The request, the decision and the reason are recorded as it happens, not reconstructed later.

Imperium is not an AI proxy, a model router, an API gateway, a cost dashboard, an agent inventory or a policy engine on its own. It is the organizational AI control plane those things belong to.

How it works

Every request takes the same governed path.

Whether it comes from a person in the workspace, a coding agent in a terminal or an automated workflow, a request is understood, checked against the organization's controls, executed inside that boundary, and checked again before it can act on the world.

  1. Understand

    Who is asking, what the task is, and which information it needs. Documents, images and voice are extracted and classified at the same boundary as typed text.

  2. Apply controls

    The models, information and actions this person and this agent are allowed to use, under the organization's policy, budget and data rules.

  3. Execute

    The work runs inside that boundary on an approved model and approved tools. Provider credentials stay with the organization and are brokered per request.

  4. Check the action

    Before anything consequential happens (an email leaves, a system changes, a payment starts) the action gate decides: allow, block, or require approval.

  5. Preserve evidence

    The request, the decision, the reason and the sources are kept, so anyone entitled to can follow the chain from intent to outcome.

The eight checks

What Imperium establishes about a request before it is allowed to run. This is what is checked, shown in a readable order; it is not the internal evaluation sequence.

Identity

A verified person, agent, service or workflow, resolved by Imperium and carried on every hop. Never taken from the client's word.

Trust

Where the context came from. Web pages, tool output and unverified documents lower the trust of everything derived from them.

Data

The classification of what the request carries, attached before a model is chosen: public, internal, confidential, restricted.

Policy

The organization's rules, inherited from organization to department, team and user, applied to this actor in this context.

Budget

The quota and spend for the department, project, person, agent and session this work belongs to.

Model

Which approved models may take this work, given its data, location and cost. Local, private or external.

Risk

What could go wrong: an external destination, a production system, money moving, an unknown tool.

Execution rights

Whether this actor was actually given the authority to take this action here, now. If not, it stops or waits for a person.

See it decide

Watch one request move through Imperium.

Pick a situation. The request carries its metadata through each check, and policy, not the prompt, decides where it may go.

Scenario
Legal · a person

“Summarize the risks in this acquisition contract.”

  1. Identity—
  2. Trust—
  3. Data—
  4. Policy—
  5. Budget—
  6. Model—
  7. Risk—
  8. Execution rights—
Local modelon-premise Approved cheaper modelwithin budget External modelapproved provider Stoppedbefore execution
Waiting

Choose a scenario to send the request.

Illustrative scenarios with fictional data.

Capabilities

What Imperium does, in depth.

Each capability works on its own, and each makes the others stronger: policy decides the route, the route decides the cost, the cost is attributed to an identity, and every step is evidence.

Policy engine

AI does not decide what it is allowed to do. Policy does. Set organization-wide boundaries, then delegate appropriate controls to departments, teams and applications. Local flexibility stays inside the limits the organization set.

  • Organization → department → team → user inheritance
  • Personal preferences never relax mandatory controls
  • Guides the user to an allowed path instead of a bare “denied”

Model routing

Policy defines what is permitted; Imperium selects an appropriate permitted path. Confidential work can go to an approved private or local model, public questions to an external one, all from the same workspace.

  • Choose a model, compare several, or let Imperium select
  • A request may use a private model, wait for capacity, ask for approval, or stop when no safe path exists
  • The user is told when and why a request was rerouted

Cost control

Every token has an owner. Usage and cost belong to a department, a project, a person and a piece of work, and can be reduced without weakening controls.

  • Quotas at every level: global, department, project, user, agent, session
  • Context optimization and cheaper compliant routes suggested before the bill arrives
  • Employees see their own usage as awareness, not punishment

Data protection

Classification is attached before a model is chosen, and it travels with the information into every answer. Sensitive content meets the boundary before it can leave.

  • Restricted data never reaches an external model; secrets never enter prompts
  • Prompts and context inspected for secrets, personal data and injection
  • Outbound checks on email, tickets, repositories and payments
  • Every execution records whether it stayed in-house, private or external

Agents, authority and approvals

Every agent acts with an identity, a defined purpose and bounded authority. Authority narrows as it is delegated, access is granted for a task and withdrawn afterwards, and high-risk actions stop for a person.

  • What can this agent see? What can it do? Answered per agent
  • Unknown agents do not get to act
  • Approvals from the console or a phone; decisions expire and are evidence

Audit and the flight recorder

Don't just know that something happened. Know how. Imperium records the request through the agents, models and tools to the action, and can replay an execution through time.

  • Read the same timeline by execution, authority, data, trust, policy, cost or risk
  • Expected versus actual flow: the deviation is the finding
  • Append-only audit and sealed evidence packages

Behavioral assurance

Models and agents drift. Imperium measures hallucination, agreement bias and drift per model, agent and version, and can reduce autonomy, require review, or roll instructions back when behavior moves.

  • Answers show which sources they used and how trustworthy they are
  • Compare two answers and get a second opinion, as evidence for a human decision

Durable, governed workflows

A decision is not the end. Approved outcomes continue as workflows that survive waiting, approval, failure and rollback: check, approve, act, verify, recover, record.

  • A fix an AI found once can be reviewed and reused as a runbook
  • A person decides whether it earns that, not the system

Imperium Sentinel

Who watches the control plane? Sentinel is an independent integrity layer, deliberately separate from what it watches. It detects unauthorized change and preserves security evidence even when the primary platform is disrupted.

  • Separate trust domain, credentials and runtime
  • No AI model is consulted to decide whether the control plane is intact

The product

Inside the console

The real Imperium console: what the organization is running, what it costs, and what needs a human decision, on one screen.

Imperium Command Center: prompts, success rate, estimated cost, active users, response time and tokens, with the siren, pending approvals, open incidents, daily usage and usage by model.

Before anything happens

Nothing privileged executes until the gate says allow.

Before an agent takes a consequential action, Imperium checks whether the actor has the authority to perform it in the current context. The action proceeds, stops, or waits for a person, and the decision and its reason are recorded.

Authority should narrow as autonomy expands.

Action gatereading a customer record
Who is acting
—
Authority
—
Context
—
Action
—
Awaiting evaluation

Illustrative scenarios with fictional data.

Capability architecture

Nine capability domains. One control plane.

A way to evaluate organizational AI control, ours or anyone's. These are domains, not processing stages: discovery and verification run continuously, protection is cross-cutting, execution is durable.

  1. DiscoverContinuously find the models, agents, clients, tools and connected systems in use, and give each an owner and a policy.
  2. GovernApply organizational policy to people, teams and agents, with controlled delegation.
  3. DecideSelect an appropriate permitted path for a task, within the organization's constraints.
  4. ControlBroker access to models, tools and credentials so no one holds uncontrolled authority.
  5. ObserveRecord what AI actually did, from the request through to the action.
  6. VerifyCarry origin and classification with information, and watch for behavioral change.
  7. OptimizeAttribute what AI work consumes, and reduce it without weakening controls.
  8. ProtectCheck consequential actions before they execute, not after.
  9. ExecuteCarry approved outcomes through durable, governed workflows.

Deployment

Run it where your data lives.

Imperium is deployed inside your infrastructure or your private environment. There is no mandatory Tracston cloud, no required external control plane, and no customer AI traffic has to pass through Tracston infrastructure.

Appliance

A single node running the control plane, gateway, console and local state. Installed from an autoinstall ISO or packages, with no container runtime required.

High availability

A clustered control plane with an external database and dedicated gateways.

Private cloud

Your tenancy, your keys, your network.

Air-gapped

Offline models, offline install, and signed updates carried in. No telemetry home.

Multi-site

A control plane per site or region sharing one policy bundle. Evidence stays where it was produced.

Guided installation

A bootstrap on an approved workstation validates the environment and deploys a dedicated appliance, every step visible and approvable.

Deployment boundary Inside your infrastructure: users, agents and clients reach Imperium (gateway, policy, vault, evidence), which keeps local models, sessions and audit local. Only the external providers you configure are reached, and each such execution is recorded. Tracston cloud is never in the path. YOUR INFRASTRUCTURE Users · agents Clients · IDEs IMPERIUMgateway · policy · vault · evidence Local models Sessions · auditstay local AI provideronly if you allow itrecorded every time Tracston cloudnever in the path

Supported platforms

VMKubernetesK3sBare metalVMwareProxmoxPrivate cloudAWSAzureGCP

Integrations

It governs the AI you already have.

Imperium is not another chatbot to migrate to. It connects to the providers, clients, agents and systems already in use, and puts one policy and one record across all of them.

Model providers

OpenAIAnthropicGoogleMicrosoftInternal modelsSpecialized models

Local and private AI

OllamavLLMLocal modelsOffline modelsGPU scheduling

Clients and agents

ChatGPTClaudeCopilotGeminiVS CodeTerminalCoding agentsRAG

Tools and code

MCP serversGitHubGitLabAutomationWorkflows

Communication

EmailTeamsSlackWhatsAppTelegramChatVoice recordings

Identity and operations

SSO / OIDCMFAOpenTelemetry exportSIEM exportBring your own key

Communication integrations work where the organization has authorized them. With bring your own key, the key enters the Imperium vault and quota, policy, audit and data protection still apply before a request reaches the provider.

Who it is for

Same control plane. Different work.

Imperium understands different organizational flows without becoming a department-specific product. Each role sees what is relevant to it, and nobody is shown enterprise-security noise they do not need.

Employees

One governed workspace instead of five AI products. Approved models, memory, documents, agents and a single history, with transparency about what is inspected and why something was blocked.

Managers and finance

Who is using which AI, for what, and what it costs, attributed to departments, projects and agents, with dashboards and approvals on desktop and mobile.

Security, IT and the CISO

Discovery of shadow AI, identity for every agent, policy enforcement, the action gate, data protection and sealed evidence for every important action.

Developers

Approved coding models and agents, repository context, MCP and GitHub or GitLab, with visible agent actions and a clear reason when something is not allowed.

Legal and HR

Contracts and candidate data handled under their classification, sources attached to answers, and approval before anything is sent outside.

Platform and AI teams

Model registry, routing, local models, GPU placement and durable workflows, all under one policy instead of one key per team.

Where it matters most

Banking
payments · personal data · financial data · approvals
Insurance
claims · personal data · actuarial models
Government
air-gap · data sovereignty · evidence
Defense
offline models · classification routing
Gaming
regulatory evidence · player data
Healthcare
health data · consent · local inference
Enterprise IT
coding agents · MCP · GitHub · cloud

Start passive. Become useful. Become the control plane.

Deployment does not have to begin with enforcement.

  1. ObserveDiscover and observe the AI already in use. Nothing is blocked.
  2. Give valueGive employees a better governed workspace: approved models, memory, instructions, documents, agents.
  3. GovernAdd policy, budgets, identity and agent controls.
  4. Enforce and automateEnforce high-risk boundaries and automate approved workflows.

Questions

Frequently asked.

Is Imperium an AI gateway or a proxy?

A gateway is one part of it. Imperium is the control plane around the gateway: identity for people and agents, policy, routing, credentials, approvals, cost attribution, the action gate and evidence, plus a workspace for employees. A proxy decides where traffic goes; Imperium decides what each actor is allowed to do and keeps the record.

Does our AI traffic pass through Tracston?

No. Imperium runs inside your infrastructure or private environment. There is no mandatory Tracston cloud, and no customer AI traffic has to pass through Tracston infrastructure. Requests reach only the external providers you configure, and each such execution is recorded.

Which models can we use?

Approved models from OpenAI, Anthropic, Google and Microsoft, local models through Ollama or vLLM, and internal or specialized models. Your policy decides which of them each person, agent and type of data may use.

What happens when a request is not allowed?

Wherever possible Imperium guides instead of just refusing: it can route to an approved internal model, redact sensitive fields, or ask for approval, and it tells the user why. When there is no safe path, the request stops, and the attempt and its reason are recorded.

Is this employee monitoring?

No. Imperium governs AI; it does not imply or default to screen recording, keystroke monitoring or secret profiling. Employees can see what is inspected, what is retained, which policy applies and why something was blocked. Inspection and retention are separate controls, and retention is configurable from metadata-only to full text.

How are provider keys handled?

Provider keys are held in the Imperium vault and brokered per request. Clients and agents never see them and they never enter prompts. You can also bring your own key, and all controls still apply.

Can it run air-gapped?

Yes. Imperium supports offline installation, offline models and signed updates carried in, with no external control plane and no telemetry home.

Do we need Otopia or Observatory to use Imperium?

No. Imperium stands on its own. Otopia is where people and agents collaborate on work and Observatory shows operational impact on services and infrastructure. They are separate products that work with Imperium when connected.

How do we start?

There are three ways in: an AI discovery and visibility engagement to find the AI you already have, a governance pilot for one department or business unit, or a full organizational control plane deployment. Pricing is discussed against your estate in a discovery session.

Where is the technical detail?

Evaluation logic, the policy model, credential handling, connector internals and deployment topology are covered in a technical discovery session with our architects, not on a public page. The product site at tracston.ai has the architecture, security and deployment overviews and an interactive demo.

Work with AI. Without losing control.

One workspace for people, one policy for the organization, and one evidence trail for every important action, running inside your own infrastructure.