What Lema actually governs.
Lema starts from the vendor. It asks what a third party can reach, what AI it has quietly added, and whether its paperwork matches its behaviour. That is a real question, and a different one from what an agent is allowed to do right now.
The four modules
The platform is presented as four modules over one vendor inventory, and the AI governance work extends the third-party risk workflows the rest of the product already runs.
- Forensic AI Assessmenta vendor assessed in under five minutes from the artifacts it submits and its public footprint, with contradictions across that evidence surfaced and cited. Custom controls are written in natural language.
- Blast Radius Monitoringcontinuous tracking of what each vendor can reach, read from the identity provider, cloud posture, CASB and EDR data, alongside procurement and contract systems. Scope drift and shadow applications raise a violation.
- Agentic Risk Engineeringexposure paths chained from isolated signals, with every finding carrying a prescriptive fix: a configuration change, a contract amendment, a permission rollback.
- Third-Party AI Governancemodel providers, AI-native applications and embedded AI identified across the vendor estate — including tools employees adopt through SaaS sign-ups, browser extensions or OAuth grants without review — with agentic behaviour, code execution, MCP and web access flagged as capabilities that change a vendor's risk profile.
Where Lema is strongest
Three of the fourteen rows below go to Lema. Each follows from where the product starts: the vendor, not the agent.
- Vendor risk assessmenta forensic read of a vendor's own evidence, fast enough to run on every new supplier. We govern agents once they act, which is what lets one policy reach agents built anywhere.
- Watching vendors for new AIan alert when a supplier adds agentic features or a new model provider, or changes how it uses your data. We see new agents as they appear in your own environment rather than inside a vendor's roadmap.
- Procurement and GRC reachintegrations into procurement, contract and GRC systems that sit outside the security stack entirely. We integrate where agents act rather than where suppliers are bought, which keeps every agent under one policy plane.
A vendor is not an action
Third-party risk asks whether a supplier should be trusted, and with how much. The answer is a decision about the relationship — a permission scope, a contract clause, a setting turned off — and it holds until the next assessment or the next drift alert.
An agent acting on your systems asks a narrower question many times a minute: may this action, by this agent, on behalf of this person, happen now? A trusted vendor's agent can still take an action you would not allow, and an agent your own team built has no vendor relationship to assess at all. That is where the architecture draws its line, and why the verdict row scores a 1.
Who signed in is not who answers for it
Lema reads the identity provider to see who signs in to which application and what permissions were granted. For vendor oversight that is the right level: it tells you which teams opened which doors.
It does not resolve an individual agent action to the human accountable for it. When an agent writes a record or moves money, the question is not which app was connected, but who owns this agent and whether this action was within what they allowed.
Three questions a vendor lens leaves open
Lema's four modules settle whether a supplier deserves trust. Governing an agent raises three further questions, and the first three groups of the table are built around them.
- Be at runtimeLema answers a violation with a resolution plan — a setting, a permission rollback, a contract amendment — that a team carries out. The test is whether a decision lands at the moment one agent acts.
- Know the identityLema's identity data shows who signed in to which vendor app and what was granted. The test is whether a single agent action resolves to the named human who answers for it.
- Cover everythingLema's inventory is the vendor estate, including AI that employees adopt without review. The test is whether the agents your own teams build are in scope as well.
Then there is cost. Lema's commercial entry is a demo request with no pricing unit on its site, so what it costs to add agent governance to a vendor programme cannot be read from outside. Agen is priced per governed agent.