Operate Enterprise AI Agents Through One Governed Control Plane.

Know What Exists

Keep agents, owners, providers, data context, access, lifecycle, risk, and evidence in one accountable inventory.

Give Teams a Safe Workspace

Let people use approved agents in chat and projects while identity, DLP, connector, memory, and file policies remain attached.

Operate with Evidence

Review health, security events, usage, cost allocation, access decisions, audit history, and platform state from the same system.

Deployment

Choose the Operating Boundary Deliberately

Customer-Managed Infrastructure

Deploy Docker-based services inside the cloud, datacenter, region, network, and storage boundary selected by the customer.

Managed Options by Design

Scope managed hosting, isolation, availability, backup, support, and offline requirements during solution design instead of assuming one topology.

Validate the Environment

Use platform health and deployment validation to inspect schemas, migrations, extensions, indexes, and other required runtime state.

Docker-Based Packaging

Build from containerized services and apply the customer's own TLS, networking, storage, monitoring, backup, and recovery controls around them.

Configuration Portability

Export and restore supported platform configuration, providers, knowledge, policy, and operational settings with validation and clear dependency handling.

Deployment Responsibilities

Pristan supplies application and deployment building blocks. Final high-availability, edge protection, data residency, and offline behavior depend on the agreed environment and connected providers.

Make the Boundary Testable

Map where catalog records, conversations, files, secrets, telemetry, backups, and provider calls live. Then validate those controls against the selected deployment rather than relying on generic infrastructure claims.

Administration

Administration Across the Agent Lifecycle

Bring ownership, provider setup, access, capabilities, safety, health, cost, review, and retirement decisions into one repeatable administrative flow.

Agent Configuration

Create and review agent identity, provider operations, access mode, knowledge, artifacts, skills, memory, DLP, health, and cost metadata.

Provider Connections

Bind agents to typed provider connection operations and validated invocation templates instead of hiding runtime behavior in unstructured endpoints.

Backup and Restore

Back up and restore supported configuration and platform data with encryption options, validation, and explicit handling for secrets and dependencies.

Permission-Aware Admin AI

When Platform AI is configured, query catalog and operational metadata or run typed administrative actions without bypassing caller permissions or audit policy.

Variables and Managed Secrets

Centralize reusable configuration and secret references, then bind them into provider and integration settings without revealing values in normal administrative views.

Audit and Event History

Review administrative changes, access events, security signals, connector activity, and operational events with searchable and exportable context where exposed.

User Management

Identity and Access Around Each Agent

Connect identity providers, directories, groups, roles, feature policy, per-agent access, temporary elevation, and periodic review without flattening everything into one administrator role.

Groups and Role Definitions

Organize users into groups, define granular permission roles, and keep administrative domains such as agents, identity, security, integrations, and observability explicit.

Authentication Providers

Configure password, OAuth/OIDC, SAML, MFA, SSO-only, session, and conditional-access behavior according to the providers and policies enabled for the deployment.

Per-Agent Access

Grant access through users and groups, keep public/restricted/private modes explicit, and route requests or just-in-time access through review workflows.

Feature and Mobile Policy

Control access to My Files, Projects, memory, search, mobile clients, and related features for targeted users or groups.

Directories, SCIM and Import

Connect configured directories, issue SCIM provisioning tokens, and use bulk import jobs for controlled user and group lifecycle operations.

Access Reviews and Recertification

Review requests, active grants, exceptions, and recertification campaigns with accountable reviewers and recorded decisions.

Everyday Work

Useful Agent Work with Governance Attached

Give teams productive chat, files, projects, knowledge, connectors, skills, artifacts, and memory without detaching those experiences from policy and evidence.

Governed Agent Chat

Stream responses, attach allowed files, inspect citations, rate answers, and manage conversation history while DLP, usage, audit, and optional memory run through configured policy.

Collaborative Projects

Create project descriptions, shared files, project conversations, and collaborator permissions. Copy eligible personal chats into projects without carrying private resources across the boundary.

Files and Knowledge

Manage personal files, project files, knowledge bases, embeddings, vector storage, and retrieval context with processing state, access, and citations where configured.

Connectors and Sources

Install reviewed connector versions, assign approved operations to agents, expose effective sources in chat, and support encrypted per-user credentials where a connector declares them.

Skills, Artifacts and Dictation

Assign validated portable skills, create Markdown artifacts, and enable managed audio dictation only for the agents, users, and providers approved for those capabilities.

User Memory Controls

When memory is enabled, let users review, edit, import, export, resolve, or forget global and agent-specific memories within administrator-defined retention and management policy.

Extensibility

Connect and Automate Without Bypassing Policy

Extend Pristan through supported channel integrations, webhooks, API keys, invocation contracts, and MCP connections while keeping scopes, approvals, and audit history explicit.

Slack and Microsoft Teams

Configure workspace or tenant credentials, default agents, channel or user mappings, and access rules for supported collaboration-channel workflows.

Webhooks and ITSM

Send selected platform events to signed webhook destinations or map events into configured ticketing connections with tests, delivery history, retries, and explicit activation.

APIs and MCP

Use scoped API keys, documented REST contracts, typed invocation templates, and approval-aware MCP service tokens for external clients and automation.

Administrator Installation Is Not User Authentication

Pristan keeps connector installation governance separate from the account a person uses at runtime. Shared service credentials are an explicit choice; user-owned credentials remain scoped to that user when the connector supports them.

Observability

See Health, Usage, Security and Cost in Context

Use platform dashboards and exports to connect operational signals to agents, providers, users, groups, and projects. Exact coverage depends on the configured provider and telemetry paths.

Main and Custom Dashboards

Review platform metrics and usage trends, then create or import custom dashboards with supported widgets, data sources, and saved layouts.

Cost Tracking

Track provider usage and estimated cost by agent, user, group, and time range. Use cost-allocation views, budgets where configured, and exports for chargeback or showback work.

Agent and Platform Health

Review agent, provider, vector, schema, migration, extension, index, and enum health through dedicated operational surfaces.

Alerting Rules

Configure supported alert conditions, severity, cooldown, destination, and digest behavior for health, usage, cost, DLP, risk, and other monitored events.

Telemetry Stack

Use OpenTelemetry, Prometheus, client telemetry, logs, traces, SLOs, incidents, synthetics, RUM, and release-correlation paths where they are configured for the deployment.

Security and Event History

Review DLP and prompt-injection trends, alert activity, connector events, and the platform-wide event log with time and entity filters.

Evaluate the Workflow, Not a Feature Checklist

Start with Real Agents

Register a representative set of agents, owners, provider connections, users, groups, and access decisions.

Run Real Work

Test chat, projects, files, knowledge, connectors, DLP, and identity controls that match the capabilities you plan to enable.

Review the Evidence

Inspect health, security events, audit history, usage, cost allocation, and the operational gaps that still need design.

Plan an Evaluation