Gensee / Agent Execution Security

Let agents work.Keep control of what happens.

Protect what agents access, run, and change—from the first tool call to the final business action. One enterprise platform for safer work and focused security.

One task. Connected protection.

The task changes shape.
Its boundaries shouldn’t.

An ordinary business request can become a script, a package install, a subprocess, or a change in another application. Gensee connects those steps to the same task, authority, and evidence.

THE AUTHORIZED TASK

Your task. Your boundaries.

Approved data, tools, destinations, and actions.

  1. 01Read & reason

    Documents and tool calls

  2. 02Build & inspect

    Generated code and packages

  3. 03Run & delegate

    Processes and subagents

  4. 04Validate & act

    Outputs and application changes

Same authority. Connected evidence.Across supported tools, runtimes, and applications.

Illustrative workflow. An agent’s change of strategy should not become a change of permission.

Built for both sides of the business

Keep work moving.
Keep security in control.

For employees & engineering

Finish the work.
Skip the friction.

Let approved work proceed under reusable policy. Use safer alternatives when a risky step can be repaired, and involve people where the business consequence warrants it.

  • Fewer unnecessary interruptions and approval requests
  • Isolated workspaces for exploration and experimentation
  • Clear explanations when an action needs attention
For security teams

Clarity to make
the right call.

Screen routine findings first, enrich the exceptions with task context, and give analysts a focused brief. Tune for low false positives without losing high-risk evidence.

  • Reusable company policies and visible coverage
  • Related findings grouped into focused investigations
  • Tiered screening designed to reduce repetitive triage

One shared outcome: more useful AI work, with fewer unnecessary interruptions and better-informed security decisions.

Inside Gensee

From an agent’s action
to an informed decision.

Follow one finance-file change through the actual product. Every screen has a job to do.

Scroll to follow the investigation

Gensee activity screen using synthetic demonstration data. Numbered annotations explain the important evidence. 1 2 3

01 / Activity

See the work around the exception.

  1. The reported action

    See what the harness reported, including its stated outcome.

  2. The affected resource

    A finance-file change sits alongside ordinary project work.

  3. The evidence basis

    Source labels distinguish runtime reports from independent OS observations.

View full-size screenshot
Gensee policy & alert screen using synthetic demonstration data. Numbered annotations explain the important evidence. 1 2 3

02 / Policy & alert

Understand why the action matters.

  1. The matched policy

    The finding names the company condition and policy revision.

  2. The action and target

    Inspect the reported write to forecast.csv and its source context.

  3. The next decision

    Carry the finding and its supporting evidence into an investigation.

View full-size screenshot
Gensee investigation screen using synthetic demonstration data. Numbered annotations explain the important evidence. 1 2 3

03 / Investigation

Keep the evidence connected.

  1. The original finding

    The saved case links back to the original detection.

  2. The supporting action

    Review the resource, reported outcome, and matched condition together.

  3. The case history

    Preserve a record of changes and assessments as the investigation develops.

View full-size screenshot
Gensee employee context screen using synthetic demonstration data. Numbered annotations explain the important evidence. 1 2 3

04 / Employee context

Give both sides a voice.

  1. A focused question

    Ask about the relevant action and task, with supporting context.

  2. The employee explanation

    Retain the response alongside the investigation evidence.

  3. The analyst assessment

    Document the decision. An explanation does not automatically change policy.

View full-size screenshot

Actual product · synthetic demonstration. The console and evidence workflow are real; source reports and the employee explanation are simulated. These screens demonstrate investigation, not preventive blocking.

Watch the captioned walkthrough

Silent walkthrough with on-screen captions. The annotated screens above provide a text alternative for the workflow.

Preliminary benchmark results

More threats caught.
Fewer false alarms.

Existing evaluations of agent defense and detection. Assess protection and legitimate task completion together in your own supported workflow.

01 / AGENTCANARY

Higher defense rates.

Baseline and Gensee results across three evaluated threat categories. Higher is better.

About AgentCanary

Memory poisoning

Baseline75.0%
With Gensee93.8%

+18.8 percentage points

Long-horizon tasks

Baseline65.4%
With Gensee100.0%

+34.6 percentage points

Prompt injection

Baseline77.8%
With Gensee93.5%

+15.7 percentage points

Gensee’s internal evaluation using an adapted AgentCanary harness; these are not official leaderboard results.

02 / UBER ADR-BENCH

Better detection.
Less noise to investigate.

We achieve higher recall and accuracy with a lower false-positive rate on the Uber ADR-Bench dataset.

About Uber ADR
MetricBaselineWith GenseeChange
Recall Higher is better73.8%92.9%+19.1 pp
False-positive rate Lower is better13.8%11.5%−2.3 pp
Accuracy Higher is better84.5%89.1%+4.6 pp

Recall measures how many positive cases are detected. False-positive rate measures how often negative cases are incorrectly flagged. “pp” means percentage points. Baseline refers to the configuration recorded in Gensee’s internal evaluation, not Uber’s production system.

REPORTED RUNTIME OVERHEAD

Protection with workflow impact in view.

0.6%–1.2%runtime overhead

10–400 msper request

How Gensee protects the work

Protect the path
from request
to result.

Gensee connects task authority, artifact risk, and business effects. Keep useful work moving as agents switch tools, generate code, and delegate tasks.

Explore customer scenarios

Controls are scoped to your supported execution environment and application integrations.

  1. 01
    SCOPE ACCESS

    Start with the right permissions.

    Connect each task to its authorizing person, permitted resources, and action limits. Give security decisions the context of the work, with unrelated files, accounts, and credentials kept outside its scope.

    Approved work keeps moving.
  2. 02
    INSPECT & REPAIR

    Make risky steps safer.

    Connect code, dependency, and tool findings to the task and the artifact actually being used. Repair unsafe artifacts or choose a safer alternative, then independently validate the result.

    A risky step can have a useful path forward.
  3. 03
    RUN & DELEGATE

    Keep every process in bounds.

    Carry the original limits beyond the first tool call—through supported scripts, installs, subprocesses, and delegated agents. Contain failures and recover supported local state without expanding the task’s authority.

    Let agents explore without expanding their access.
  4. 04
    VALIDATE & ACT

    Control what changes the business.

    Validate the exact output and govern supported records, operations, recipients, and cumulative limits. Preauthorized actions proceed; consequential exceptions reach a person with connected evidence.

    Review the decisions that need attention.
The technical foundation

Policy above the task.
Enforcement at the effect.

A trusted control plane connects task context to controls at supported system and application boundaries. Inspection, identity, and storage tools contribute through shared interfaces.

TRUSTED CONTROL PLANE

Task identity · Authority · Policy

Who authorized the work, which resources it can use, what it may change, and when its permission ends. Policy and approval state stay outside agent-controlled workspaces.

01 / SYSTEM BOUNDARY

Protect execution.

Processes and descendants, files, credentials, executables, and network paths.

02 / ARTIFACT BOUNDARY

Inspect. Repair. Validate.

Generated code, dependencies, installation behavior, and the exact output approved for use.

03 / APPLICATION BOUNDARY

Govern the effect.

Supported records, recipients, operations, and cumulative action limits.

ENTERPRISE ADMINISTRATION

Enrollment · Roles · Central policies · Updates · Health & coverage · Audit exports

One evidence trail.Task lineage · Policy decisions · Observed effects · Containment · Supported recovery

A scan is evidence, not permission. A clean artifact still needs authority to change a business record or send a message.

A child task cannot grant itself more access. Delegation and retries share the original task’s limits.

Coverage is defined by the supported OS, runtime, harness, and application integration. Vendor-hosted execution needs an accessible enforcement point; local recovery cannot undo a sent message or disclosed information.

Before we get started

A little more clarity.

Answers for the people doing the work—and the people protecting it.

What is Gensee Agent Execution Security?

Gensee brings task authority, execution protection, artifact inspection and repair, application controls, and correlated evidence into one enterprise platform. It is designed to protect supported agent workflows from human mistakes, agent errors, and malicious inputs.

Who is it for?

Teams with agents that already read sensitive information, run code, or change business systems. Operations and support are a natural starting point, with analytics, finance, and engineering workflows also in scope. The operational owner, platform or IT team, and security team define the boundaries together.

Do we need to replace our existing agents?

The approach is to protect your existing agents and workflows. Coverage depends on the supported runtime, harness, OS, and application connectors. An inaccessible vendor-hosted agent needs a supported integration or a control point at the resource it uses.

Will normal work require constant approvals?

Preauthorized work should proceed under reusable policy. Routine screening and connected context are designed to reduce false alerts and unnecessary approvals. Human review focuses on consequential exceptions; model confidence alone does not authorize an action or discard high-risk evidence.

How do inspection and repair fit into execution security?

Inspection supplies evidence about code, packages, and tools. Gensee connects that evidence to task authority and execution policy. A safer version or repaired artifact must be independently validated, and approval must apply to the exact artifact used. A passing scan does not grant new permissions.

Can Gensee reverse every action?

No. Recovery applies to supported local state. It cannot unsend an email, reverse an arbitrary remote transaction, or recall disclosed data. Those effects need controls at the application or resource boundary before they occur.

Which capabilities can we evaluate today?

The architecture describes the unified platform direction. The console walkthrough and benchmarks show specific existing work; they do not establish coverage for every execution path. We scope the supported configuration and demonstrate the protections available for your workflow.

Let’s talk about your workflow.

Bring the task your team delegates.
We’ll help map the boundaries that matter.

Contact us
Gensee / Agent Execution Security

Let agents do the work.
Keep your business in control.

Start with the work you already delegate.
See what it takes to protect the path from request to result.