Company
Somebody has to govern the agents nobody owns.
Rotascale builds RotaGrant: a governance layer for autonomous agents that works across runtimes rather than inside one vendor's estate. Authority stated in advance, enforced before the action, and evidence that survives being checked by somebody who does not trust you.
Why this, and why now
Every serious enterprise is putting agents into production faster than it can answer a simple question about them: who said this one could move money. The tooling that grew up around models answers a different question — how a model scores, what it cost, what it said. None of it constrains what an agent may do at four in the afternoon with a payment API in reach, and none of it produces a record a supervisor can check afterwards.
The action is the governable unit
Not the model, not the prompt, not the token spend. An agent's consequential actions are where the money moves and where the obligation attaches, and they are the only thing a control can sit in front of.
observed →Nobody will build this across
Every platform vendor is building agent governance for their own estate, which is rational and is also the opening: governing a competitor's runtime well is a feature that helps a customer leave. An enterprise runs agents on several. Each new entrant makes a neutral layer worth more.
observed →Several jurisdictions, one workload
A Singapore bank with European customers is under PDPA and GDPR and the AI Act at once, possibly on a Canadian host. A product built for one country resolves one regime. This one resolves a profile per decision and seals it into the record.
observed →Where the product came from
Rotascale spent several years doing senior advisory work on AI in banking, insurance and government — the sectors where an autonomous system's mistakes have a regulator attached. That work is why RotaGrant looks the way it does, and it taught us three things we have built into the product rather than into a slide.
- Nobody is short of dashboards
- Every institution we worked with could tell you what its models did. None could tell you what a named person had authorised, or produce the refusal that should have happened and did not.
- The evidence question arrives late and hard
- It arrives as an incident, an audit, or a supervisor's letter — and by then the record either exists or it does not. Nothing you build afterwards can make last quarter checkable.
- A control that cannot refuse is not a control
- The most common finding in that work was a governance layer that observed everything and stopped nothing, presented internally as though it were enforcement.
How we work
The vocabulary is open, and unbranded
The entity model and authority grammar are published under Apache 2.0 with our name in them exactly once, as the reference implementation. A competitor's engine can claim conformance to it. That is the point.
observed →The demo is a running deployment
Not a video and not seeded rows. Agents run daily, ask for authority, get refused, and the evidence is sealed. When a grant runs down a named person renews it, and that is on the page too.
observed →We publish where our own controls fail
The adversarial grid against our own identifier detector is on the site, including the cells it fails and the two wrong gates we built before the right one.
observed →The company
RotaGrant is built by Rotascale. Rotascale is a product of Rota, Inc., San Francisco. We also build Rotavision, which does for India what Rotascale does globally.