AgentHub Connect · Governance Console

Governance and monitoring of AI agents

AgentHub Connect is the console that manages Wiven agents on your infrastructure. You see what each agent does, you decide what it is allowed to write to your software, and you set its cost.

In short

An AI agent doesn't stop at simply providing a response: it reads documents, calls tools, and suggests entries in your business applications. AgentHub Connect routes each of these entries through a human decision or a pre-defined rule. It logs each execution without retaining the processed content and pauses an agent as soon as it exceeds its budget. The console runs on your system, and every output is logged.

// Why a frame

An agent acts. Therefore, it is necessary to know who authorized him, what he did, and what it cost.

A chatbot produces text that someone then proofreads. An agent, on the other hand, handles the process automatically: it retrieves an invoice, locates the supplier in the ERP system, and then generates the accounting entry. The time savings are significant, but it raises three questions that a manager, financial officer, or auditor will eventually ask.

Who decided?

An entry in the accounting system or a closed ticket in the system must be able to be linked to a specific person or rule, along with its reason.

What happened?

What documents, what tools, what data, and above all where to: a template on your machines, a business software, or an external service.

How much does it cost?

A looping agent or a misconfigured external model can consume a month's budget overnight. We need a cap that takes action, not just a report that observes.

What does the law say?

The new Data Protection Act (nLPD) requires that the data subject be informed of an automated individual decision that has legal effects concerning him or her or significantly affects him or her, and that he or she be given the right to request a review by a natural person (Art. 21). It also provides for a record of processing activities (Art. 12).

// The journey of a writing

The agent makes the proposal. The gateway writes it down only after a decision.

In AgentHub Connect, an agent never has direct access to your software. They go through a gateway that only exposes the granted tools, keeps access secrets to the vault, and only writes once a decision has been made.

  1. The agent readsA supplier invoice arrives. The agent analyzes it using a template running on your infrastructure.
  2. He consultsIt queries the ERP through the gateway, tool by tool, for example to find the supplier.
  3. He proposesHe submits the accounting entry. It waits in the validation queue.
  4. You decideA person validates, corrects, or rejects the request, or a self-validation rule applies. Only then does the gateway write.
Each step is recorded in the journal: who, what, where to, how many.
// Part 1 · Governance

Governance: who decides, and on what basis

AI agent governance is the set of rules that define what an agent is allowed to do, who authorizes it, and how it is verified. In AgentHub Connect, these rules are not a separate document: the console applies them itself.

No writing without a decision

Any entry that an agent wants to make in a business software program goes into the queue of validations. For each, three choices: validate and execute ; refuse, with a logged pattern that the agent also sees; or edit and then confirm. In the latter case, the corrected version is executed, and the fingerprint of the original proposal remains in the log. A request without a decision times out instead of executing by default.

Self-validation rules, if you wish.

For repetitive and low-risk transactions, an administrator can create a rule: one agent, one tool, a maximum amount per transaction, and a maximum number and total per day. Within these limits, the transaction is executed immediately and logged like any other. Without a rule, everything goes through a single person.

A processing register per agent

Each agent carries their own record, completed according to the guidelines: purpose, legal basis, data subjects, and retention period. An agent without a record cannot be activated. These sections include some of those from the register of processing activities required by the nLPD (New Federal Act on Data Protection).

Pause, emergency stop, general stop

Pausing an agent prevents new runs and tool calls, with a logged reason. An emergency shutdown also interrupts its current calls and freezes its pending entries; only the owner can undo it. A full shutdown shuts down all agents at once.

Roles and an identity

We connect via WivenLLM, which identifies the person. Rights follow distinct roles, for example owner or auditor, so that the person who controls is not the one who operates.

A history that cannot be erased

Every change to an agent is dated and attributed: a pause decided by a person, an automatic pause because the limit is reached, an automatic resumption when the budget allows again. In the event of an audit, you show the chronology instead of reconstructing it.

// Part 2 · Monitoring

Monitoring: what your agents are doing, live

Monitoring AI agents answers a simple question: is each agent doing its job right now, and at what cost? An agent failure is rarely obvious. More often than not, it continues running while producing errors, or it stops communicating without anyone noticing. We have described this risk here.

An overview that fits on one screen

Active, paused, or error-prone agents; recent failed or unresponsive runs; broken connectors; pending validations; open alerts. Recent runs scroll live. Each alert represents a problem, regardless of the number of repetitions: you won't be overwhelmed with fifty notifications for the same issue.

The Runs Journal

Each agent execution is logged with its time, trace, status (in progress, successful, failed, canceled, no updates), duration, number of documents and tokens, data categories affected, and cost. Filters allow you to find all runs that accessed HR or health data in the past month.

A run in detail, step by step

Model calls, tool calls, anomalies: each step displays its duration, the data category involved, and its destination (no output, model on your infrastructure, business application). You see where the information went, without having to guess.

A journal that is not a copy of your data

The processed content (texts, documents, model responses) is not recorded in the log. Only its type, size, and a fingerprint are. The log proves what happened, by whom, and to where, without itself becoming a repository of sensitive data requiring protection.

The health of each agent

Failure rates over 24 hours and 7 days, including runs with no response. Activity over the last seven days, median duration, and 95th percentile of runs. Connectors used, along with their calls and failures over 30 days. A drift is visible before it becomes an incident.

// Budgetary safeguards

A ceiling that acts, not a report that observes

Each agent has a monthly spending limit, a spending limit per run, and an alert threshold, all in francs. These safeguards are as much a part of governance as they are of monitoring: they act without waiting for anyone's input, but according to a rule you have established.

  • Reservation before execution. Each run reserves its limit before starting. If there is no more space in the monthly budget, the run is refused, the agent is paused and an alert is opened.
  • Immediate pause in case of overrun. A run that is more expensive than expected or costs received late may cause the cap to be slightly exceeded: the agent is then put on pause without waiting.
  • Nothing is counted as zero by mistake. The prices of external models are entered in francs per million tokens, along with their country. An external model not listed in this table is never considered free: the agent is paused. A call counts as zero only if its host is included in the list of models installed on your infrastructure, such as WivenLLM.
  • A transparent consumption pattern. Cost observed since the 1st of the month (Zurich time), portion reserved for ongoing runs, and end-of-month projection, presented for what it is: a trend, not a guarantee.

This is the technical translation of our pricing : external resources are billed back at cost, up to a limit that you set.

// Connectors

Your software, behind a gateway

Agents access your business applications only through the gateway: tool by tool, with access secrets securely stored, and every call logged. The health of each connector is monitored every minute. A degraded connector is disabled for agents until it is restored, rather than allowing an agent to write to an unstable system.

console catalog

Available in the current version:

GLPI · Teclib'’MS.ERP · Mediasoft

Planned:

AbacusSAP Business OneProConceptImmomigMicrosoft 365 / SharePoint

For a complete list of the software our agents connect to, see the page Integrations.

// For whom

One console, four readings

Direction

Knowing what is automated, at what cost, and being able to stop everything with a single gesture.

Finance

Validate the proposed entries, set the ceilings, monitor consumption to the nearest franc.

Computer science

See failed runs, broken connectors, and the health of each agent, without digging through technical logs.

Data protection and auditing

Having access to the register by agent, the categories of data affected and a dated and attributed history, in read-only mode.

To learn more: The five safeguards to demand before letting an AI agent write to your ERP.

Frequently Asked Questions

What we are being asked about the governance of agents

What is AI agent governance?

This is the set of rules that define what an agent is allowed to do, who authorizes it, and how it is proven: validation of entries, self-validation rules, processing log per agent, roles, pause and stop, change history. In AgentHub Connect, the console applies these rules itself.

What is the difference between governance and monitoring?

Governance decides in advance what is permitted. Monitoring shows what is actually happening: runs, failures, connectors, costs, alerts. Budgetary safeguards link the two: a pre-established rule that is applied in real time.

Can an agent write anything in our ERP system on their own?

No, unless an administrator has created an auto-validation rule for that agent and tool, with a maximum amount per transaction and daily limits. Outside of these limits, each transaction requires human approval. It's always the gateway that makes the entry, never the agent.

Does the newspaper contain our documents?

No. The processed content itself is not recorded in the log: only its type, size, and a fingerprint are, along with the destination of each step. The log proves what happened without becoming a copy of your data.

What happens when an agent reaches their ceiling?

Each run reserves its budget before starting. If there is no more space, the run is rejected, the agent is paused, and an alert is opened. It resumes when the budget allows again, and each pause and resumption is logged.

Where does AgentHub Connect run?

On your infrastructure, alongside WivenLLM, which is also used to identify users, calls to external models are only possible if they have been declared with their price and country.

// Sources
// Demonstration

See the console on your own cases

In twenty minutes, we show you AgentHub Connect with an agent close to your needs: validations, log, limits and stop.

Request a demonstrationBack to AgentHubDiscover WivenLLM