The Standard
What is AGAP?
The Agent Governance and Action Protocol (AGAP) is an open standard that defines the runtime governance requirements for AI agent systems. It specifies how agents must authenticate, how their actions must be authorised, how sensitive data must be protected, and how every decision must be recorded.
AGAP was created by MTE Software Ltd and published under CC BY 4.0. The full specification, including requirement definitions and conformance criteria, is available at agap-protocol.org.
Conformance is structured in three tiers (Core, Extended, and Full), allowing organisations to adopt governance incrementally and verify each level independently.
Conformance
1000+ tests. Published results.
Every Vortalis release is verified against the AGAP Conformance Test Suite. Here is where we stand.
AGAP Core
Complete17/17 requirements satisfied
Foundational governance controls: policy enforcement, credential isolation, audit logging, kill switches, and role-based access.
AGAP Extended
Complete11/11 requirements satisfied
Advanced capabilities: anomaly detection, human-in-the-loop approval, inter-agent governance, runtime sandboxing, and workflow enforcement.
AGAP Full
In progress5/7 requirements satisfied
Ecosystem features: governance spine with principal chain tracking, federated governance, cross-tenant policy negotiation, and regulatory export automation.
Why it matters
Standards-backed governance
Open Standard, Not Vendor Lock-In
AGAP is published under CC BY 4.0. Any organisation can build a conformant implementation, evaluate existing tooling, or contribute to the specification. Choosing Vortalis means choosing an open ecosystem.
Regulatory Compliance by Architecture
AGAP conformance maps directly to EU AI Act Articles 12–27, DORA, and NIST AI RMF. Your compliance evidence is generated automatically, not assembled manually.
Conformance Tested
Every Vortalis release is verified against the AGAP Conformance Test Suite. 1000+ tests. Published results. No self-certification.
Governance you can verify
Vortalis is built on an open standard with published conformance results. No black boxes. No trust-us claims.