About
The authority governance layer for AI agents
Enterprises are deploying AI agents that approve invoices, route escalations, recommend clinical actions, and execute procurement, at machine speed. No platform in the enterprise stack defines what those agents are organizationally authorized to decide. BotAris does.
Why we built BotAris
AI agents are no longer just answering questions. They approve transactions, update records, call other systems, and hand work to other agents. Every one of those actions is a decision, and most organizations have no way to state which decisions an agent is allowed to make.
The tools we have were not built for this. Identity and access management answers three questions: who is this, does it have valid credentials, and does it have the right permissions? Those answers still matter. But an agent with valid credentials and the right permissions can still make a decision nobody authorized. Access tells you an agent can reach the payments system. It does not tell you whether that agent should approve a payment of that size, on its own, right now.
The common response is to find every agent first and then govern each one individually. We do not think that model holds up. Agents can create other agents, and some may exist for only seconds. If governance depends on discovering every agent, registering it, and assigning the right permissions, then any agent you have not discovered sits outside the governance model. And even the agents you do know about are governed only at the level of access. Permissions, including deny rules, say which systems an agent can or cannot reach. They do not say which decisions the business never intended it to make.
So, we started from a different place. BotAris governs the action at the moment of decision, not the agent's registration. Known or unknown, every agent's actions face the same test: is this within the authority that was granted, and who granted it?
We call this authority governance. BotAris is the authority control plane for agentic AI. It lets organizations define what their agents are authorized to decide, enforce that authority at runtime, and keep an accountable record of every decision. Each action resolves to one of four outcomes: allow, constrain, escalate to a human, or deny.
Our mission
To let businesses innovate with AI agents by making every decision those agents make governed and accountable.
We give AI agents a mandate, not just a credential, and check every decision they make against it at runtime.
Our founder

Jonathan Edwards
Founder & CEO
Jonathan has spent nearly two decades in identity and access management, working across directory services, federation, privileged access management, identity governance, and non-human identity. His leadership roles have included CEO of the Americas for iC Consult and Managing Director at KeyData Cyber.
In 2018, Jonathan argued that customer identity should be viewed not only as a security control, but as a driver of revenue through customer acquisition, experience, and retention. That business-enablement mindset has since become a common part of how the industry approaches CIAM. Today, he is challenging another long-held assumption in identity: that controlling access is enough to govern autonomous systems. As AI agents become capable of making decisions and taking action on behalf of organizations, Jonathan believes the industry must evolve from governing who or what has access to governing the authority behind the decisions being made.
As AI agents moved from assistants to actors, Jonathan saw a gap in the identity model he had worked within for most of his career. Identity could tell an organization who an agent was and what it could access. It could not tell the organization what that agent was authorized to decide. In 2026, he stepped away from traditional IAM practice to found BotAris, built on the belief that identity remains essential but is no longer sufficient for governing autonomous AI.
