Cartha logoCartha
Sign in
Runtime control plane · SDK 0.5.3

ControleveryAIagentbeforeittakesaction.

Runtime governance for autonomous agents — observability, policy enforcement, and a decision trace you can hand to risk. Two lines to instrument. Stops a tool call before it lands.

AGENTMODELCARTHAPOLICYTOOLAPIDATABASE

requested —

RUNTIME IDLE
cartha.in / control
Live preview

Active agents

12

Policy violations

03

Blocked actions

07

Spend (UTC)

$42.81

AgentHealthRiskTool callsCost
claims.intake
healthy
12184$4.12
underwriting.risk
watch
4196$11.40
support.triage
healthy
818$2.08
kyc.verify
blocked
7814$0.61

Execution timeline

  1. 14:02:11model.invoke · 1.2s
  2. 14:02:12web.search · allowed
  3. 14:02:12memory.read · scope=team
  4. 14:02:13customer_data.export · blocked

Action blocked

customer_data.export never executed. Waiting on human approval.

Illustrative control-plane UI — not live tenant data.

Runtime story

An agent wakes up

It has a goal, a model, and tools. Nothing watches the side effects yet.

0% of the path

AGENTCARTHAPOLICYACTION

packet: idle · tool.call

The production reality

AI in production is a black box. When things break, you're left guessing.

Which agent made this decision?

Why did this workflow fail?

What memory influenced this response?

Why did API costs suddenly spike?

Which policy blocked this execution?

How do we audit this decision later?

Cartha sits in between.

Between your agents and production — so they're governable, predictable, and auditable.

How it works

Connect. Observe. Govern. Audit.

  1. 01

    Connect

    Init and instrument. Two lines against the stack you already run — LangGraph, CrewAI, OpenAI Agents, and the rest.

  2. 02

    Observe

    Every LLM call, tool, and memory access lands in one event graph. Cost, latency, and agent health without extra wrappers.

  3. 03

    Govern

    Policies, allow-lists, budgets, and human gates evaluate before the side effect. Deny is a first-class outcome.

  4. 04

    Audit

    Replay the run. Export the evidence. Show risk what the agent knew, what it attempted, and what Cartha stopped.

Control plane

Six controls. One runtime.

Observability without governance is a dashboard. Governance without a trace is a black box. Cartha is both, in the path of the call.

01 · Observability

Agent execution timeline

Every LLM call, tool, and memory read in one event graph — same schema, any framework.

  1. 09:42:11Agent initialized · support.triage
  2. 09:42:12Tool call · web.search
  3. 09:42:13Retrieved external data · 4 sources
  4. 09:42:14Policy evaluation · PII_EXPORT_RESTRICTED
  5. 09:42:14Risk detected · action blocked

02 · Governance

Policy engine

Evaluated before the side effect.

Agentsupport.triage
Requestedcustomer.email.export
PolicyPII_EXPORT_RESTRICTED
Decision
✕ BLOCKED

03 · Memory

Quad-scoped isolation

User
Team
Agent
Org

TTLs per scope. No context bleed.

04 · Cost

Attribution + breakers

Agentresearch.runner
Tokens42.8K
Tool calls18
Run cost$0.82

Hard ceiling at 90% of envelope

05 · Decision tracing

What happened. Why. What stopped.

What the agent knew, which tools it called, which policy fired, and how it arrived at the action.

  1. What did it do?tool.transfer_funds requested
  2. Why?Prior step returned a payout instruction
  3. What stopped it?tool.allowlist + HITL gate

06 · Execution replay

Rewind the run

Agent state, tools, memory, and policy decisions — debug from the past, deterministically.

t=0 statetoolmemorypolicyaction

Accountability

When AI makes a decision, you should be able to prove what happened.

Cartha turns activity into an auditable record — what an agent did, what it accessed, which policies applied, and where a human stepped in.

EU AI Act — Article 12
Immutable audit trails and automatic event capture
EU AI Act — Article 14
Human approval gates and pause-for-signoff
SOC 2 — CC7
Real-time monitoring, policy enforcement and alerts
NIST AI RMF
Policy controls, governed memory and budget breakers
Internal AI policies
Natural-language rules scoped by organization, team or agent

Bring your AI policy or audit checklist.

We'll show where Cartha closes the gap — no jargon, a few minutes.

Book a review

Zero-code setup

Two lines. Then your existing agent code.

Initialize, instrument, run. No decorators, wrappers, or manual tracing required.

  • cartha.instrument() across installed frameworks
  • Automatic agent, tool, and environment discovery
  • Same event schema no matter the stack
app.py
import cartha
import langgraph

cartha.init(api_key="…")
cartha.instrument()

# your agent, unchanged
graph = langgraph.graph.StateGraph(…)
graph.invoke(…)

The platform

Six controls. Live walkthroughs.

Runtime, audit, memory, policy, budgets, and failover — each beside a product recording.

01

Universal Runtime Model

Framework-agnostic governance. Zero-code setup for instant visibility across any agent framework with a unified event schema.

cartha.in · Universal Runtime Model

02

Governance & Auditing

Prove compliance with immutable audit logs. Track every LLM decision, tool execution, and data access retroactively.

cartha.in · Governance & Auditing

03

Quad-Scoped Memory

Prevent context bleed. Segment agent memory across User, Team, Agent, and Org boundaries with strict TTLs.

cartha.in · Quad-Scoped Memory

04

Policy Guardrails

Define natural language rules. Enforce them in microseconds to block PII leaks or halt risky tool executions instantly.

cartha.in · Policy Guardrails

05

Budget Breakers

Establish hard financial ceilings per execution. Automatically terminate runaway agent loops before budgets are exhausted.

cartha.in · Budget Breakers

06

Runtime Resilience

Configure automatic agent failover and trace replays to ensure high availability and deterministic debugging.

cartha.in · Runtime Resilience

Architecture

How Cartha sits in your stack

USERAI AGENTCARTHA RUNTIMEPOLICY ENGINETOOLS / APIs
permitted evaluating blocked
Cartha Infrastructure Diagram

Where it applies

Runtime control for agents that take action

If a system can call a tool, read memory, or spend tokens, it belongs on a governed path. These are the shapes of work Cartha is built for — not a customer list.

Tool-calling agents

Search, write, transfer, ticket — allow-lists and HITL before the side effect.

RAG that acts

Retrieve, then do. Trace which context influenced the next tool call.

Internal automation

Budget breakers and policy on workflows that run without a human in the loop.

Support agents

PII and export policies on customer data, with a replayable decision trail.

Research / analysis

Cost attribution per run when models and tools stack up across a long session.

Regulated workflows

Evidence for what happened — mapped to controls you already have to answer for.

Built-in, not bolted on.

Memory isolation, approvals, budgets, and replay — without assembling a custom ops stack.

Quad-scoped memory

Isolate agent contexts natively.

Human approvals

Pause execution for manual sign-off.

Budget breakers

Hard-stop agents when spend trips the cap.

Policy guardrails

Enforce rules before the tool runs.

Immutable audit trails

Every state and decision, retained.

Execution replay

Debug from the past, deterministically.

Tool allowlists

Restrict dangerous executions.

Agent failover

Reroute when an agent hits its ceiling.

Time-travel memory

Query what an agent knew at that instant.

Supported frameworks

Keep the stack you already use. We handle governance.

LangGraph logo
LangGraph
OpenAI logo
OpenAI
Anthropic logo
Anthropic
Gemini logo
Gemini
LiteLLM logo
LiteLLM
CrewAI logo
CrewAI
OpenAI Agents SDK logo
OpenAI Agents SDK
Google ADK logo
Google ADK
AutoGen logo
AutoGen
PydanticAI logo
PydanticAI

With and without

Without
With Cartha
Manual instrumentation
Zero-code instrumentation
Unknown execution flow
Automatic execution graph
Manual governance
Policy engine
Budget surprises
Hard budget breakers
Memory guesswork
Quad-scoped memory
Ad-hoc setup
CLI: doctor, instrument

Security

Controls mapped. Honest about certification.

Tenant isolation, encryption, and audit logging are in the product. SOC 2 Type II and ISO 27001 are aligned — not claimed as completed audits.

SOC 2 Type II — mapping

Access control, immutable-style audit logging, and monitoring designed against CC-series controls.

ISO 27001 — aligned

Quad-scoped isolation and encryption in transit and at rest. Certificate when the audit is done — not before.

Your agents are becoming autonomous.
Your controls should too.

Instrument the runtime. Govern the action.