Centralized Registry & Governance
Register externally built agents and map each one to a human Entra identity. Provision the fleet with SCIM.
Secure Enterprise Agent Control Plane
Register every agent, verify identity at the gateway, sever access with one switch — and keep the audit trail that survives the incident.
Scroll anytime to keep reading. The tour plays end to end once you start it.
Space pauses. M mutes. Esc exits.
control plane
Register externally built agents and map each one to a human Entra identity. Provision the fleet with SCIM.
Tool-level authorization at the gateway. Flip one switch and Kimss severs the agent’s access for routed traffic.
Append-only telemetry and audit records for governed requests. Optional APIM GatewayLogs into Log Analytics when the compliance gateway path is enabled.
architecture
Stateless LLM providers stay yours. Memory, tools, and security run through Kimss — identity, guardrails, and audit in the gap.
Your keys. Your tenancy.
Execution you can govern.
security
Kimss is a control plane, not a second model vendor. Provider credentials stay yours. The proxy meters the hop without archiving proprietary text.
compliance
When APIM gateway mode is enabled, diagnostics feed Log Analytics for gateway-level records alongside app-side telemetry.
Inference stays on the vaulted endpoints you registered (OpenAI-compatible or native Anthropic). First use: vault a model, create an agent, then POST /v1/agents/run with an API key. Kimss does not host or relocate your models.
Human access via Entra ID. Agents map to people. The kill switch severs gateway access.
pricing
Meter what the control plane governs — register, report, and routed calls. Inference on your vaulted endpoints remains your provider bill.
Free tier includes 25,000 governed requests/month. No credit card required.