Summary
- Palma.ai is building a central policy layer for agents operating across different AI platforms and enterprise tools.
- Controls can govern tool calls, require human approval, and retain an audit trail rather than relying only on application-level access.
- The company is entering an increasingly competitive market for agent governance as autonomy reaches production systems.
Enterprise AI governance startup Palma.ai has raised $1.8 million to develop a common control layer for AI agents, targeting organisations that do not want to manage permissions and audit rules separately inside every assistant or automation platform they deploy.
The company sits between AI agents and the tools those agents call, applying policies at the point an action is requested. Administrators can allow or reject specific tool calls, impose limits, require human approval, and retain records showing what the agent attempted to do.
The design addresses a problem likely to become more pronounced as organisations accumulate AI products. A company may use Microsoft Copilot for workplace tasks, specialist coding agents in engineering, ChatGPT or Claude in other teams, and internally developed agents around operational systems.
If each platform controls authority independently, security teams inherit several places to configure who can do what and several audit formats to reconcile after something goes wrong.
Governance follows the action
Palma is building around Model Context Protocol, or MCP, which gives AI systems a common method for connecting with tools and data. MCP can make integrations more portable, but it does not determine whether an individual agent should be permitted to invoke a particular function.
A financial agent, for example, might be allowed to retrieve records freely, execute a low-value transaction under defined conditions, and route a higher-value action to an employee for approval. A governance layer can apply that policy regardless of which compatible AI client initiated the request.
The company also integrates with identity infrastructure including Microsoft Entra and Okta, tying permissions to organisational identities rather than creating a completely separate access directory.
That approach reflects a wider change in AI governance. Early controls were often concerned with which models employees could access or whether sensitive information could be pasted into a public service. Autonomous agents require governance of actions as well as information.
Runtime control is becoming competitive
Palma is entering a market attracting security companies, identity vendors, cloud platforms, and data-governance providers. All have an incentive to become the place where organisations decide what agents can see, which tools they may invoke, and what evidence is retained.
A standalone layer can offer consistency across vendors, although large enterprise-software providers may attempt to keep the same controls inside products customers already use.
MCP gives independent governance vendors an opening because it standardises part of the connection between agent and tool. The difficult commercial question is whether enterprises will want a separate control plane or expect their existing identity and security platforms to absorb that function.
There is also an organisational issue behind the architecture. Agent permissions can involve security teams, application owners, compliance functions, business departments, and IT operations, making policy ownership less straightforward than granting access to a conventional employee account.
As autonomous software becomes more capable, however, organisations will need an answer to a broader set of questions: which agent acted, which employee or service authorised it, which tool it called, what arguments it supplied, whether a person approved the action, and what happened next.
Palma’s financing is early-stage, but the problem it targets is moving into the centre of enterprise AI deployment. Once agents are capable of modifying systems rather than merely discussing them, permission becomes a runtime concern rather than a box checked when the software is first connected.












