Skip to content

Product

Integrate, manage and secure your whole AI estate

Olivares AI brings every part of your enterprise AI under one roof — the models and agents, the MCP servers and identities behind them, the data they touch and the budgets they spend. See what each can reach, decide what it can do, and prove it — multi-provider by design, on your own infrastructure.

The access map · the differentiator

Permitted versus observed, on every resource

olivares · access map prod / search agents, resources… Preview
agents 214
live sessions 37
models 11
mcp servers 19
hosts · clouds 42 · 4
spend · 30d $8.4k
drift 3
compliance 98%
Access map ObservedPermitted writes only last 24h readwrite
claude-deploy-bot
claude-opus-4-8
support-rag-agent
gpt-5.5
billing-reconciler
claude-sonnet-4-6
infra-copilot
claude-opus-4-8
data-export-job
magistral-small
qa-runner
gpt-5.4-mini
prod-postgres
database
WRITE
s3://billing-exports
object store
stripe-api
external api
internal-wiki-mcp
mcp server
k8s-prod
cluster
vault-secrets
secrets
slack-mcp
mcp server
data-export-job → prod-postgres · WRITE · unreviewed
The Olivares AI access map: agents on the left, the resources they reach on the right, with read edges dashed and write edges solid. One agent holds an unreviewed write to a production database — least-privilege drift, caught by diffing permitted against observed.

Read vs read/write

Every edge carries an access mode taken from your infrastructure’s own records — whether an agent only reads a resource, or can also write to it. Write is where the risk is.

Permitted vs observed

Permitted is what policy allows; observed is what the collector actually saw. The gap between them is least-privilege drift — an observed write nobody allowed is the headline finding.

Attributed vs approximate

Confidence is shown, never faked. When activity can’t be tied to a specific agent, attribution collapses honestly to the credential and is marked approximate — we never invent an agent.

One self-hosted product

Everything you need to operate AI agents, in one place

Olivares AI is a single self-hosted product. The access map is the spine; around it sit the capabilities a platform, security or FinOps team needs to run an AI estate — the full scope the complete product targets, grouped here by what they help you do.

Visibility

See your whole AI estate.

I

Discovery & inventory

Automatically discover and catalog every agent, session, MCP server, skill and model running across your infrastructure — multi-host and multi-cloud, with no proxy to babysit.

II

Live operations & sessions

Inspect observed session actions, models, tokens, costs, and event history, with governed work items and handoffs. Goals depend on the reporting source; computed task progress and the complete operating workflow are not yet verified.

XXII

Health, SLA & uptime

Track the health, uptime and SLAs of your agents and MCP servers, with alerts on outages or degradation and a live dependency map.

Governance

Govern who — and what — is allowed to act.

VI

Identity, permissions & governance

Granular control over who and what can act — role- and attribute-based access, per-agent identity, human-in-the-loop approvals and a policy engine — with every action traceable to a person.

IV

Agent communication & orchestration

View observed agent relationships and use bounded workflows for work, runtime, messages, and handoffs. Coverage gaps remain explicit; the combined coordination and acknowledgment workflow is not yet verified end to end.

The work plane →
XIV

Internal catalog & marketplace

Curate and reuse approved agents, MCPs and skills as versioned company templates, with governed self-service.

Security

Secure and auditable by design.

IX

Security, guardrails & audit

Tamper-evident audit, secrets and egress controls, and guardrails against prompt injection, jailbreaks and data leaks — with reconstructable incident forensics.

XVIII

Red-teaming & adversarial testing

Probe your agents safely — adversarial prompt-injection, jailbreak and exfiltration tests, scored against the OWASP agentic-risk checklist.

XVII

Simulation sandbox

Run operator-authored mock scenarios and ordered replay when a history source is available. Operating-system isolation requires a configured isolation backend and separate attestation; mock execution does not provide it.

Models & Cost

Govern the whole stack, control the spend.

X

Models & providers

Resolve routing policies and ordered fallback candidates. The measured execution path requires a configured Claude Messages-compatible client; this does not verify every provider, local model, or console execution path.

XI

Cost & FinOps

Track AI spend by team, agent, model and project, set budgets and alerts, and forecast — with routing and caching policy to manage spend.

XII

Quality, evals & testing

Answer the question that matters — is my agent still doing the right thing? — with evals, regression testing, output-quality monitoring and drift detection.

Data

Govern what your agents know.

VIII

Data, knowledge & context

Govern what your agents know and retrieve — knowledge bases and RAG, governed retrieval, data lineage and residency, versioned prompts and persistent memory.

Compliance

Open the enterprise door.

XIII

Compliance & regulatory

Map your AI program to the frameworks enterprises ask about — the EU AI Act, NIST AI RMF, ISO 42001, SOC 2 / ISO 27001 and GDPR — with exportable audit evidence and agent risk classification. It helps you demonstrate controls; it does not grant a certification.

Platform & Operations

Operate the platform itself.

V

MCPs, skills & capabilities

Govern your agents’ tools — a catalog of MCP servers, skills and plugins, what is connected to whom, configuration, versioning and health.

VII

Deployment & integration

Govern the agent and MCP lifecycle — provision, update and retire — and wire them into your real network, servers and data stores, with versioning, rollback and GitOps. Direct actuation is governed and deny-closed: live for a subset today, provisioned on-demand for the rest.

XV

Outbound integrations & notifications

Olivares talks to the tools you already run — chat, on-call, your SIEM, ITSM systems, developer portals, webhooks and email.

XIX

API & manage-as-code

Manage Olivares itself as code — a full API, a Terraform provider, a declarative CLI and event webhooks.

XX

Multi-tenancy & organizations

Organization hierarchy and delegated administration for service providers and large enterprises, with real tenant isolation and per-org usage.

XXI

Executive dashboards & reporting

High-level views for leadership — KPIs across cost, usage, risk and compliance, with scheduled, exportable reports.

XVI

Voice & realtime agents

Manage conversational and realtime voice agents — sessions, state, transcription, latency and governance.

On the roadmap · post-v1

Your own models and fine-tuning

Managing an organization’s own trained or hosted models — a private model registry and fine-tuning workflows — is planned for after the first release. We are not presenting it as available today.

Editions

Run it free, or with a contract behind it

The open AGPL-3.0 build is the complete governance platform, free for unlimited users. Business and Enterprise add what an organization needs around it.

  • Community

    The complete product under AGPL-3.0, self-hosted, with unlimited users.

    View the repository
  • Business

    A commercial license, a signed release channel and four optional add-ons, priced per deployment.

    See pricing
  • Enterprise

    An annual order form with negotiated terms: several legal entities, LTS and OTA mirror, OEM and redistribution rights.

    Why Enterprise

See what your agents can reach

Deploy Olivares AI on your own infrastructure and get the access map your platform and security teams have been asking for.