Let agents do more.
Keep control of
what happens.
Help employees delegate safely. Give security teams company-wide policy, connected evidence, and focused investigations.
Explore Defense for AIProtect your business from mistakes, misuse, and unintended actions. Strengthen your defenses with autonomous discovery and verified remediation.
Built on UC San Diego
Read why Two Small FishGensee builds AI agent safety and security tools for enterprises: Defense for AI safeguards employee and agent work. AI for Defense brings autonomous discovery and verified remediation to cyber defense.
Help employees delegate safely. Give security teams company-wide policy, connected evidence, and focused investigations.
Explore Defense for AIBring autonomous discovery, repair, and verification to existing software and agent-generated code.
Seeking design partners
Explore AI for DefenseDelegate the ambitious task. Explore another approach. Keep routine work moving inside clear company boundaries.
Set the boundaries, connect the evidence, and focus review on consequential exceptions. Give your team context to act.
Follow one finance-file change through the actual product. Every screen has a job to do.
Scroll to follow the investigation
1
2
3
01 / Activity
See what the harness reported, including its stated outcome.
A finance-file change sits alongside ordinary project work.
Source labels distinguish runtime reports from independent OS observations.
1
2
3
02 / Policy & alert
The finding names the company condition and policy revision.
Inspect the reported write to forecast.csv and its source context.
Carry the finding and its supporting evidence into an investigation.
1
2
3
03 / Investigation
The saved case links back to the original detection.
Review the resource, reported outcome, and matched condition together.
Preserve a record of changes and assessments as the investigation develops.
1
2
3
04 / Employee context
Ask about the relevant action and task, with supporting context.
Retain the response alongside the investigation evidence.
Document the decision. An explanation does not automatically change policy.
Actual product · synthetic demonstration. The console and evidence workflow are real; source reports and the employee explanation are simulated. These screens demonstrate investigation, not preventive blocking.
Silent walkthrough with on-screen captions. The annotated screens above provide a text alternative for the workflow.
Human mistakes, agent errors, and malicious inputs can meet in the same workflow. Build protection around the work itself.
The same discipline that governs an agent’s work can govern an agent’s defense: understand the action, bound its authority, verify the result.
Bring together supported agent reports, system observations, policy context, and outcomes. Keep the source and its limits visible.
Scope resources and temporary permissions. Isolate exploration and control consequential changes at the relevant boundary.
Check the exact output, inspect the evidence, and promote accepted changes. Keep a record of what was authorized and what happened.
Founded by UC San Diego professor Yiying Zhang and former Google engineering leader Shengqi Zhu, Gensee brings systems research to agent safety. Meet the team
How live workspace branches return useful results—and where their boundaries end.
Read the research ↗ LONG-HORIZON AGENT SAFETYWhat real incidents teach us about shared services, persistent state, and control over time.
Read the analysis ↗Answers for the people doing the work—and the people protecting it.
Gensee helps businesses manage the safety and security of work delegated to AI agents: human mistakes, agent errors, malicious instructions, unintended changes, and company data crossing the wrong boundary. Defense for AI brings together company policy, connected evidence, and focused investigations. Explore the customer scenarios.
Defense for AI helps employees use agents safely and gives security teams control over that work. AI for Defense is our enterprise design-partner initiative for discovering vulnerabilities, validating findings, and preparing and verifying fixes. Both serve enterprise teams; Gensee Crate Personal serves individual developers.
No. The approach is to let routine work proceed within reusable company policies and reserve review for consequential exceptions. Policy enforcement, security alerts, and employee notifications are separate choices. An evaluation should measure both unnecessary interruptions and missed issues against your own workflows.
First, screen incoming findings for likely noise using policy and task context. Next, enrich the remaining findings with related actions, evidence, and potential impact. Finally, send consequential exceptions to a human reviewer with the context needed to decide. High-risk evidence should not be dismissed on model confidence alone. See the screening approach.
Start with the tools your employees already use. The current demonstration includes the company console and managed Mac evidence workflows, with supported Claude Code and Cowork sources. Coverage and enforcement depend on the integration, platform, and configured release. We scope an evaluation around your actual environment and acceptance criteria.
Supported isolated workspaces let developers explore alternatives, review changes, and discard unwanted state. Rollback cannot unsend an email, recall leaked information, or reverse arbitrary external transactions. External effects need their own controls. Read how workspace rollback works.
Tell us which product line interests you and what you want to evaluate. Defense for AI uses custom pricing based on deployment and integration needs. AI for Defense is seeking design partners, and Personal is free. Compare the options or contact us to discuss a demo, partnership, or another question.
Tell us what your team is working on.
Let’s find the right place to start.
See Gensee in action, or help shape what comes next. Start with the work your people and agents actually do.