Selfic AI
PlatformAI control plane
AI control planeSelfic platform

Decide what every AI agent can see, do and spend

The Selfic control plane sits between AI and your enterprise. Before any agent touches data or takes an action, it checks who is asking, what they are allowed to do, which rules apply, whether it fits the token budget and whether a person must approve. Then it records everything.

For CIO, CISO, security, AI governance and platform teams

Capabilities

Nine controls, one place to manage them

Select a capability to see what it does, or let the tour play.

Select any capability
Selfic control plane1 of 9

Know every agent that touches your enterprise

Agents are registered with an owner, a purpose and a risk tier. Anything unregistered is blocked at the door.

AgentOwnerRisk tierStatus
ChatGPT EnterpriseITMediumActive
ClaudeRisk teamMediumActive
Claims triage agentOperationsHighActive
Vendor support botServiceHighIn review
Unknown agentNoneUnknownBlocked

Verify the person behind every request

Users sign in through your identity provider with MFA. Selfic issues a short-lived token scoped to exactly what they may do.

Userfinance.analystSign inSSO and MFA verifiedIssuedScoped token, 60 minutes
erp:invoices.readdocs:policies.readcrm:accounts.read
Least privilege by default. The agent can only do what this user is allowed to do.

Access that follows role, department and group

Define access once for each role. It applies in every agent your people use.

RoleFinance dataCustomersHR recordsRisk register
Finance manager✓M–✓
Risk analyst✓M–A
HR partner––✓–
Contractor––––

✓ allowed   M masked   A approval to change   – no access

Rules applied on every request

Policies are written in plain language and evaluated in real time, before data leaves a system.

External agent reads personal dataMask fields
Any agent exports more than 1,000 recordsDeny
Payment above $25,000Require approval
Department reaches 100% of token budgetPause and notify
Matched: Claude asked for customer records. Personal fields were masked before the data left Salesforce.

Govern which tools agents can use

Every MCP server and tool is approved before agents can see it. Risky tools are off or need approval.

ToolSettingEnabled
sap.get_invoiceRead
sap.post_paymentApproval required
crm.read_accountRead, masked
crm.export_allNot approved
hr.read_salaryNot approved

Agents never hold your keys

System credentials live in the Selfic vault. Agents receive a capability, never a password, so there is nothing to leak.

CredentialStoredVisible to agents
SAP service account••••••••••Never
Salesforce OAuth••••••••••Never
Claims database••••••••••Never
Revoke in one place. Remove an agent's access without rotating a single system password.

People decide where it matters

High-impact actions pause and wait for the right owner, with the full context in front of them.

Awaiting approval

Release payment run of $184,200 to 12 suppliers

Requested by AP agent for finance.analyst. All 12 invoices matched to purchase orders.

ApproveReject
Approved by the finance controller. The action continues and the approval is recorded.

Central control of all AI spending

Set token budgets for every department, group and user on every agent. Consumption is tracked on each request, and limits are enforced before the spend happens.

BudgetAgentUsed this monthStatus
FinanceChatGPT4.1M of 5M82%
OperationsChatGPT6M of 6MPaused
RiskClaude2.2M of 4M55%
claims.handlerChatGPT230K of 250K daily92%
Limit reached. Operations paused on ChatGPT. New requests need approval or move to a lower-cost model.

A complete record of every decision

Every request, decision, approval and outcome is logged. Export it to your security tools or hand it to auditors.

09:14:02ChatGPT read 42 invoices for finance.analystAllowed
09:14:09Claude read account data for sales.leadMasked
09:15:31Vendor bot tried a bulk exportDenied
09:16:48Payment run approved by controllerApproved
Allowed78%
Masked14%
Approval5%
Denied3%
Token monitoring and governance

One place to control every AI token your enterprise spends

Decide how many tokens each user, department and group can spend on each agent. Watch consumption as it happens, and restrict spending automatically, before it becomes a surprise invoice.

  • Budgets at every level

    Set limits for the organization, each department, group and individual user.

  • Limits for each agent

    Give Finance 5M tokens a month on ChatGPT and 3M on Claude, and set something different for every team.

  • Automatic restrictions

    Warn owners at 80%. At 100%, pause, require approval, or route to a lower-cost model.

  • Real-time monitoring and chargeback

    See who spends what, on which agent, and allocate AI cost back to each department.

Policy in plain language

Rules your security team can read, and your auditors can check

Examples of policies you can set in the control plane.

When an external agent reads personal data

Then mask national ID, bank and contact fields

When any agent tries to change a payment

Then require approval from the finance owner

When a contractor uses any agent

Then allow published policies and documents only

When a department reaches 80% of its token budget

Then notify the owner and route to lower-cost models

Illustrative policies. Rules are configured to your organization.

The difference

From scattered controls to one control plane

Without a control planeWith the Selfic control plane
Agent inventoryUnknown, spread across teams and vendorsOne registry with owners and risk tiers
CredentialsShared accounts and personal tokens inside agentsHeld in the vault, never exposed to agents
AccessConfigured separately in every toolDefined once by role, department and group
Sensitive dataDepends on each vendor's settingsMasked by your policy before it leaves the system
High-impact actionsNo consistent approval stepApproval gates with recorded decisions
AI spendSpread across vendor invoices, with no limits per teamBudgets by user, department, group and agent, enforced in real time
EvidenceVendor logs, app logs and chat historiesOne audit trail across every agent
Two planes, one platform

The control plane decides. The execution plane delivers.

Every request passes through both. Governance without execution stops at "no". Execution without governance never reaches production. Selfic gives you both in one platform.

Asks

Any AI

Claude, ChatGPT, Copilot, your own agents, vendor agents and workflows.

Decides

AI control plane

Who may act, on what data, with which tools, and when a person must approve.

Delivers

AI execution plane

Connectors, context, tools, agents and workflows that complete the work.

Explore the execution plane

Result: real business work completed in your systems, with every decision recorded.

Enterprise ready

Built for the way regulated enterprises operate

Deploy your waySaaS, private cloud, on-premises or hybrid
Secure by designSSO, MFA, RBAC, tenant isolation, encryption and a credential vault
Human controlApproval gates, action limits, exception handling and escalations
Complete visibilityAudit logs, execution history, monitoring and evidence
Model agnosticUse the AI models and agents that fit your enterprise

Put every AI agent behind one control plane

See how Selfic governs identity, access, policy, approvals and audit for every agent in your enterprise.