Skip to content

Compare

Why Olivares AI, said plainly

Keep the gateway, the tracer and the identity provider. Olivares AI is the self-hosted kernel that sees the agent those tools do not: identity over time, what it reached, who approved it, and whether any of it can be proven.

This page is not a checklist contest. The long form, with vendor quotes and their sources, is on the sibling pages. This is the shape.

What it is

A self-hosted kernel (one artifact) that:

  1. Discovers agents and builds a read/write access map from native audit and the telemetry you configure, out of band. Coverage is tiered — clean, lossy or opaque — and attribution is firm, approximate or unknown. Nothing is guessed.
  2. Holds policy and optional deny-closed enforcement points you wire. In current development those points are the Claude Code hook, an opt-in inline /v1/messages proxy that stays unmounted until you provision it, an MCP tools/call gate and an A2A delegation gate.
  3. Writes an append-only, hash-chained audit ledger with Ed25519-signed checkpoints, exportable for offline re-verification, and pushes it to a SIEM sink when you configure one. That is tamper-evident evidence, not an immutable WORM store unless you configure WORM archival.
  4. Can bind an agent to an existing non-human identity, or mint a dedicated one. A dedicated NHI is what lets the access map attribute access firmly; a shared account stays approximate; an unresolved identity is never silently treated as a real NHI. Roster connectors read your IdP’s and the hyperscalers’ agent registries as read-only snapshots — Olivares does not become your IdP.

What it sits beside (not instead of)

LayerTypical toolsWhat Olivares does not do
Model-call pathLiteLLM, Cloudflare AI Gateway, Portkey, Bedrock GuardrailsRoute, cache, load-balance, or filter content
Host / runtimeeBPF, existing APMReplace the tracer or store full OTel spans
Control towersMicrosoft Agent 365, ServiceNowReplace the tower; federation is read-only snapshot ingestion, not live-verified trust
IdentityEntra, AWS, Google, SPIFFEBe an IdP

Sourced comparisons: vs AI gateways, vs LLM observability, vs control towers, vs Bedrock AgentCore, vs Microsoft AGT, vs WitnessAI.

Honest limits (repeated on purpose)

  • Pre-1.0 preview. Not certified.
  • Air-gap is the kernel and its data, not Claude inference.
  • The stop is a deny gate the wired surfaces consult, not a process killer, and only as wide as the gates you wired.
  • Fidelity is tiered; nothing is guessed.
  • Community is the long-term default; commercial add-ons are additive packs, not a wall in front of the AGPL core.

How the pieces fit: how it works. Who it is for: solutions.

Ask Claude

Questions

What does Olivares AI refuse to be?

An AI gateway, a tracing backend, an identity provider, a content-safety filter, a hosted SaaS for your agent traffic, or a certified compliance programme. Those refusals are the product.

Where is this sourced?

From the public comparison pages on this site (AI gateways, LLM observability, control towers, Bedrock AgentCore, Microsoft Agent Governance Toolkit, WitnessAI) and from the honesty & limits document. This page adds no vendor quotes of its own.