Product Roadmap — Enterprise Agent Governance, Security & Compliance

The Tier-1 wedge, turned into a build plan: the feature set, which features matter at what size of company, the sequence to ship them, and the regulatory clock and buyers that pull them into market. Hover any i…marker for detail, rationale, or source. for the reasoning.
Wedge: agent-native, vendor-neutral control plane Buyers: CISO · Head of AI Platform · GRC / Compliance Grounded: EU AI Act (post-omnibus), NIST AI RMF, ISO 42001; 2026 competitor scan
The wedge, sharpened

01Positioning — the neutral control plane for agents in production

The market has two camps that each own half the problem, and a gap between them that no incumbent is structurally suited to fill. That gap is the product.

Thesis: Enterprises deploying agents need one place to see every agent, control what it can do, prove it works, and demonstrate compliance — across every model and cloud. Governance/GRC incumbents (built for the model era) can't do runtime or agent-native depth; agent-security tools do runtime but are thin on compliance and often locked to one vendor's model, cloud, or security suite. A vendor-neutral, agent-native platform that unifies runtime security + reliability/eval + audit + compliance mapping is the defensible middle — and it's exactly what a model provider can't build without a conflict of interest.
Camp 1 — Governance / GRC iCredo AI, OneTrust, Holistic AI, ModelOp, FairNow. Strong on policy, model registry, framework mapping and reporting — but built for the model era. Weak on runtime enforcement, agent execution paths, tool-calls, and evaluation.2026 AI-governance buyer guides (TechTarget, Modulos, Kovrr).
Owns policy, registry, framework mapping, reporting. Misses runtime, agents, eval.
The gap — Nometria ✦
Agent-native + vendor-neutral, unifying runtime security, eval/reliability, audit & compliance in one control plane. The defensible middle.
Camp 2 — Agent security iArthur, Zenity, Lakera, Palo Alto (Prisma AIRS), Microsoft (Agent 365), Astrix. Strong on runtime guardrails, identity, discovery — but thin on compliance/eval depth, and several are locked to one model, cloud or security suite (Palo Alto, Microsoft).Arthur "Best AI Agent Security Platforms 2026"; TrueFoundry buyer's guide.
Owns runtime guardrails, identity, discovery. Misses compliance depth, eval, neutrality.
The product

02Six product pillars — the full feature taxonomy

Everything the platform does, organized as six pillars. Together they answer the four questions an enterprise asks about any agent: what is it, what can it do, does it work, and can we prove it. Build order comes in §04 — this is the complete surface.

1Discovery & Agent Registry

"What agents do we even have?" — visibility first
  • Agent & tool inventory — every agent, model, tool, MCP server in use
  • Shadow-agent detection — find ungoverned agents via telemetry/network iThe #1 enterprise anxiety: agents spun up outside IT's view. Detecting them via traffic/telemetry is the same "shadow AI discovery" Palo Alto, Arthur and Zenity lead with.
  • Lineage & dependency map — which agent calls which tool/data/model
  • Ownership & metadata — owner, business purpose, risk tier

2Identity, Access & Authorization

"What is this agent allowed to touch?" — least privilege
  • Non-human identity (NHI) — every agent gets a governed identity iAgents are non-human identities that act with real credentials. Managing them (Astrix's core, Microsoft Entra Agent ID) is becoming a distinct control category — secret rotation, revocation, posture.
  • Tool-scoped permissions — per-agent least-privilege on each tool/action
  • Human-in-the-loop approvals — step-up gates for risky actions
  • SSO / SCIM / RBAC — enterprise auth & role model

3Runtime Guardrails & Security

"Stop the bad thing before it happens" — inline defense
  • Prompt-injection & jailbreak defense — inline detection/blocking
  • PII / DLP & output filtering — data-leak prevention both directions
  • Tool-call containment — intent-based policy on the full execution path iZenity's "intent-based detection examines the full execution path including tool calls." Blocking a malicious action, not just a bad string, is the agent-native differentiator over model-era filters.
  • Low-latency enforcement — inline, sub-100ms (Lakera targets <50ms)
  • Data residency / VPC / self-host — keep data in the customer boundary

4Evaluation & Reliability Assurance

"Does it actually work?" — the eval-gap wedge
  • Offline eval + regression gating — block bad releases in CI
  • Online / production eval + drift — catch degradation live
  • Silent-failure detection — the ~78% of failures no one sees iTies the governance product back to the #1 pain (reliability) and the widest gap in the stack. This pillar is what separates Nometria from pure-security vendors — you govern correctness, not just safety.
  • Automated red-teaming — continuous adversarial testing

5Audit, Observability & Traceability

"Show me exactly what happened" — the evidence layer
  • Full execution-path trace — every prompt, tool call, decision
  • Immutable / tamper-evident audit log — the compliance backbone
  • Auditor-ready evidence export — one-click evidence packages
  • SIEM / OpenTelemetry integration — flows into existing SOC

6Policy & Compliance Management

"Prove we meet the rules" — the CISO/GRC pillar
  • Policy-as-code engine — write once, enforce at runtime + audit
  • Framework mapping — EU AI Act, NIST AI RMF, ISO 42001, SOC 2 iControls map to the frameworks driving 2026-27 demand. ISO/IEC 42001 (certifiable AI management system), NIST AI RMF (+ GenAI profile), EU AI Act (legally binding, phased). Mapping once and satisfying many is the GRC value prop.
  • Model/agent risk register & assessments — per-agent risk tiering
  • Continuous compliance monitoring & reporting — always audit-ready
  • Board / exec risk dashboards — the CISO's up-and-out view
What matters, and to whom

03Feature × company-tier matrix

The core of your question — which features are needed at what level of company. The same product means different things at different scale: a 900-person scale-up buys safety + speed; a Fortune-500 bank buys audit, residency and compliance. Need-level per tier below (hover the feature name for the "why").

◆ Tier A — Mid-market / AI-native
~500–2,000 employees · scale-ups
Pain: ship fast and pass their own customers' security review. Buys SOC 2 + safety + eval. Budget-light, self-serve, bottoms-up. Economic buyer = Head of Eng / Platform.
◆ Tier B — Enterprise
~2,000–10,000 employees
Pain: security & reliability at scale; first real GRC involvement. Buys the platform — registry, runtime, audit, policy. Buyer = CISO + Head of AI Platform.
◆ Tier C — Large / regulated
10,000+ · finance · health · gov · F500
Pain: board-level risk, legal compliance, residency, air-gap. Buys everything, high ACV, slow. Buyer = CISO + Chief Compliance / GRC + DPO + procurement.
Feature◆ A · Mid-market◆ B · Enterprise◆ C · Large / regulated
1 · Discovery & Registry
Agent & tool inventoryNiceCoreCritical
Shadow-agent detectionfind ungoverned agents—CoreCritical
Lineage & dependency map—NiceCore
2 · Identity, Access & Authorization
Tool-scoped least-privilegeCoreCriticalCritical
Non-human identity (NHI)—CoreCritical
Human-in-the-loop approvalsNiceCoreCritical
SSO / SCIM / RBACCoreCriticalCritical
3 · Runtime Guardrails & Security
Prompt-injection / jailbreak defenseCoreCriticalCritical
PII / DLP & output filteringCoreCriticalCritical
Tool-call containment (intent-based)NiceCoreCritical
Low-latency inline enforcement<100msNiceCoreCritical
Data residency / VPC / self-host—NiceCritical
4 · Evaluation & Reliability
Offline eval + regression gatingCoreCoreCore
Online / production eval + driftNiceCoreCritical
Silent-failure detectionNiceCoreCore
Automated red-teaming—NiceCritical
5 · Audit, Observability & Traceability
Full execution-path traceCoreCoreCritical
Immutable / tamper-evident audit logNiceCoreCritical
Auditor-ready evidence export—NiceCritical
SIEM / OpenTelemetry integrationNiceCoreCritical
6 · Policy & Compliance
Policy-as-code engineNiceCoreCritical
Framework mappingSOC 2 → EU AI Act / NIST / ISO 42001Nice(SOC 2)CoreCritical
Model/agent risk register—CoreCritical
Continuous compliance monitoring—NiceCritical
Board / exec risk dashboards—NiceCore
Critical deal-maker; they won't buy without it Core expected in the platform Nice valued, not decisive — not needed at this tier
How to read it: the "Critical" column shifts rightward and downward — safety/eval features are critical early (Tier A/B); compliance, residency, evidence and risk-register features only become critical at Tier C. That shift is your expansion path: land Tier A/B on security + reliability, expand into Tier C as you add the compliance pillar. Don't build Tier-C compliance features before you have Tier-B design partners using the runtime + audit core.
The build sequence

04Roadmap — four phases, wedge to platform

Build in the order that lets you sell now and expand later: start at the acute, demonstrable pain (a blocked prompt-injection + an audit trail a security team can see), then widen to the control plane, then unlock the high-ACV compliance buyer. Each phase's target tier is tagged.

Phase 0 · Beachhead
0–6 months

The wedge that demos itself

  • Inline prompt-injection + PII/DLP guardrails (SDK/proxy)
  • Full execution-path trace → searchable log
  • Offline eval + CI regression gating
  • Tool-scoped permissions (basic)
Goal: 3–5 design partners; block a real incident on day one. Land via the security/platform team.iPick features that produce an undeniable "it just caught something" moment. A blocked injection + a trace a CISO can read beats any deck. Ship as a lightweight SDK/gateway that drops in without re-architecting the agent.
Target: Tier A/B
Phase 1 · Land
6–12 months

Point tool → control plane

  • Agent registry + shadow-agent discovery
  • Online eval + drift + silent-failure detection
  • Immutable audit log + SIEM/OTel export
  • Human-in-the-loop approvals; SSO/RBAC
Goal: become the single pane for "all our agents." Convert design partners to paid; first Tier-B logos.
Target: Tier B
Phase 2 · Expand
12–24 months

Unlock the compliance buyer

  • Policy-as-code engine (runtime + audit)
  • Framework mapping: EU AI Act, NIST, ISO 42001
  • Risk register + auditor-ready evidence export
  • NHI management; residency / self-host / VPC
Goal: high-ACV Tier-C deals; CISO + GRC co-sign. Ride the EU AI Act clock (§05).
Target: Tier C / regulated
Phase 3 · Category
24 months +

The neutral standard

  • Cross-model / cross-cloud control plane
  • Automated red-teaming at scale
  • Board dashboards; cross-org benchmarking
  • Partner/marketplace ecosystem
Goal: own "agent governance" as a category; neutrality as the moat vs Microsoft/Palo Alto bundles.
Target: Tier B + C
Sequencing logic: revenue-bearing security value first (Phase 0–1) funds the slow, expensive compliance build (Phase 2) — and by the time high-risk EU AI Act obligations bite (Dec 2027), your compliance pillar is mature. Building compliance first would mean 18 months of GRC engineering before a single "it works" demo — the wrong order for a startup.
Demand timing

05The regulatory clock — what pulls features into market

Compliance features don't sell on merit; they sell on deadlines. The EU AI Act's phased schedule (recently relaxed by the "omnibus" delay) is the demand pump. Align Phase-2 delivery to land ~12 months ahead of each obligation. iDates reflect the 2026 post-omnibus timeline. Note the high-risk delay to Dec 2027 / Aug 2028 — it buys you time to build the compliance pillar, but the transparency (Aug 2026) and GPAI (Dec 2026) obligations are near-term demand triggers now.

Feb 2025
Prohibited practices already enforceable — plus AI-literacy duties for all providers/deployers
LIVE
2 Aug 2026
Transparency obligations enforceable — disclose AI interactions, mark AI-generated content; market-surveillance authorities stand up
NEAR-TERM PULL
2 Dec 2026
GPAI grace period ends — general-purpose model obligations bite for Code-of-Practice signatories
NEAR-TERM PULL
2 Dec 2027
High-risk systems (Annex III) — standalone high-risk AI obligations apply (delayed from 2026)
PHASE-2 TARGET
2 Aug 2028
High-risk embedded in products (Annex I) — full obligations apply
PHASE-3 HORIZON
Beyond the EU: NIST AI RMF (+ its Generative AI profile) is the US voluntary baseline buyers ask you to map to, and ISO/IEC 42001 is the certifiable AI-management-system standard enterprises increasingly require of vendors — support all three in the framework-mapping feature so one control set satisfies many regimes. Sources listed at the foot.
Who buys, and how you sell

06Buyer map & GTM motion by tier

The buyer changes as you move up-tier — and so must the motion. The trap is selling a CISO/GRC compliance story to a 900-person scale-up (too heavy) or a self-serve dev tool to a bank (won't clear procurement). Match motion to tier.

TierEconomic buyerChampion / userLead withMotionACV
A · Mid-marketHead of Eng / PlatformSenior engineersSafety + eval + SOC 2 to sell upmarketPLG / self-serve, bottoms-up$ low
B · EnterpriseCISO + Head of AI PlatformPlatform & security engControl plane: see + control + audit all agentsSales-assisted, design partners, security review$$ mid
C · Large / regulatedCISO + Chief Compliance / GRCGRC, DPO, risk, auditProvable compliance, residency, board riskEnterprise sales, POC, procurement, MSA$$$ high

The land-and-expand path

Enter bottoms-up through the platform/security engineer who feels the runtime pain (Phase 0). Prove value on real incidents, expand to the CISO as the control plane (Phase 1), then to GRC/compliance as the audit & framework story matures (Phase 2). Each buyer unlocks the next tier's budget — you don't need the CISO on day one, you earn them.

Vertical beachhead option

If Nometria has a domain edge, start in one regulated vertical (fintech, health, insurance) where the compliance pain is acute and the reference sells the next ten logos. A narrow, deep "agent governance for [vertical]" beats broad-and-shallow — and the compliance mappings you build there generalize outward.iThis is the biggest open decision. A vertical beachhead accelerates Tier-C credibility and gives you proprietary compliance depth, at the cost of TAM per logo. Horizontal is bigger but faces the incumbents head-on sooner. Depends on Nometria's existing domain relationships.

The competitive field

07Where you sit — and how you defend it

Two axes decide the field: agent-native depth (does it understand runtime execution paths & eval, up) vs compliance depth (policy, frameworks, audit, right). The incumbents cluster in two corners; the top-right — deep on both, and neutral — is open.

The table below carries the competitive read — the 2-D map needs a wider screen.
▲ agent-native & runtime depth
shallow / model-era ▼
◀ light on compliance
deep compliance ▶
Lakera
Zenity · Arthur
Palo Alto · Microsoft
Credo AI · OneTrust
Holistic · ModelOp · FairNow
Nometria ✦
Defensibility recap: neutrality is a structural moat Microsoft & Palo Alto can't copy (they sell the lock-in); agent-native runtime + eval depth is what the GRC incumbents can't retrofit; and unifying all six pillars in one control plane is what the point-security tools (Lakera, Zenity) don't attempt. Your risk is a well-funded agent-security player (Arthur, Zenity) adding compliance faster than you add runtime — so keep the runtime + eval lead while racing them to the compliance pillar.
Make it concrete

08MVP definition & the metrics that matter

MVP (Phase 0) — the smallest thing worth paying for

A drop-in SDK / gateway that sits inline on an agent and, on day one: (1) blocks prompt-injection & PII leakage, (2) records a full, searchable execution-path trace, and (3) runs eval gates in CI so a bad agent can't ship. One dashboard. No re-architecture required.

Why this: it's demonstrable in a 20-minute call, it's owned by a buyer who can say yes without procurement (platform/security lead), and it plants the trace/audit spine that every later pillar hangs off.

Metrics — prove the wedge, then the expansion

Phase 0–1design partners; incidents blocked; % agents traced; eval coverage %
Phase 1–2paid conversion; agents under management; time-to-audit-evidence; net revenue retention
Phase 2–3Tier-C logos; ACV expansion B→C; frameworks supported; % ARR from compliance
Assumptions to confirm with you: this roadmap assumes a horizontal, vendor-neutral entry with an optional regulated-vertical beachhead, and a bottoms-up security/platform wedge before the CISO/GRC motion. If Nometria already has (a) a specific vertical, (b) enterprise/CISO relationships to sell top-down, or (c) existing eval vs security IP to build from, the sequencing shifts — tell me which and I'll re-cut Phases 0–2 and the beachhead accordingly.
Sources — EU AI Act post-omnibus timeline: Data Protection Report (Norton Rose Fulbright), Jul 2026 · SIG EU AI Act summary (Aug 2026) · EU AI Act Service Desk (ec.europa.eu). Frameworks: NIST AI RMF + GenAI profile; ISO/IEC 42001. Competitor / feature landscape: Arthur "Best AI Agent Security Platforms 2026," TrueFoundry buyer's guide, TechTarget / Modulos / Kovrr AI-governance platform guides 2026 (Credo AI, OneTrust, Holistic AI, ModelOp, FairNow; Palo Alto Prisma AIRS, Microsoft Agent 365, Zenity, Lakera, Astrix). Market context carried from the prior verified briefing (Menlo, Bessemer, LangChain, OpenAI, Cleanlab).

Caveats: vendor capability claims come from 2026 buyer-guide / vendor sources and shift quickly; validate specific competitor features before positioning against them. Regulatory dates reflect the 2026 post-omnibus schedule and remain subject to further EU adjustment — re-check before committing compliance-feature delivery dates. Company-tier need-levels are informed judgments for planning, not survey data.