What QuilrAI actually governs.
QuilrAI puts itself in front of the calls an agent makes and decides there. That is a real runtime architecture, and it is closer to ours than most. The difference is in who the decision is about.
The three enforcement points
The product is a decision engine with three ways into the traffic, and each one is worth scoring on its own.
- LLM gatewayan OpenAI-compatible endpoint that an application reaches by changing one base URL. Requests pass through identity, rate limits, guardrails, custom detections, routing and token compression, and responses are scanned on the way back.
- MCP gatewayone URL that multiplexes hundreds of MCP servers. Policy runs at session, discovery, request and response, so a destructive tool can be hidden from the agent, refused if called anyway, or paused until a person approves it.
- Endpoint agent and browser extensiona daemon on macOS and Windows that hooks AI tool processes at the operating-system level, plus a browser extension that scans prompts and pastes. Together they reach coding agents and chat tools that never touch a gateway.
Above all three sits the Guardian: a per-agent policy written from a one-sentence purpose statement and a short round of clarifying questions, with a red-team agent testing it before and after it goes live.
Where QuilrAI is strongest
Three of the sixteen rows below go to QuilrAI and four are level. They follow from where it chose to sit: on the device and in the call path, with a partner channel built around both.
- Browser and device-level network enforcementa force-installed browser extension paired with a native browser agent, rolled out through Group Policy, Intune or Jamf, and TLS inspection on managed laptops. We govern the action rather than the traffic, and run alongside whatever already inspects that traffic.
- Speed to a first governed callone base URL change, no SDK, and first agents surfaced within minutes. Level with ours.
- Partner reacha cloud-marketplace listing, resellers, global systems integrators and managed security providers carry the product, which gives it a wider distribution footprint than ours today.
Inline is not the same as accountable
On runtime, the two architectures are close. A tool call through the MCP gateway is judged before it lands, one call can be refused without stopping the agent, and every call is logged. The table scores those rows level or one point apart, and that is the honest reading.
The gap opens on the question a verdict is supposed to answer: who is this agent, and who answers for it? In QuilrAI the agent is recognised by a keyword in its User-Agent header or by a token scoped to it. The person is whoever the calling application names in a header or a JWT, and that is optional until an administrator enforces it. A decision made about a header is only as good as the header.
Delegation is scoped, not owned
For multi-agent systems, QuilrAI checks each handoff so a child agent never receives more than its parent holds. That is a real control, and it scores a 3. It depends on the agent network being registered in advance, and it bounds what is passed down rather than carrying a named owner through the chain. When a scheduled agent acts at 3am, the useful question is not which permissions it inherited but which person is accountable for the action.
QuilrAI's gateways and sensors, read against the table's three axes
The table groups its rows by runtime, identity and coverage. QuilrAI's design, two gateways and two device sensors under one decision engine, gives a different answer to each.
- RuntimeQuilrAI decides before the call lands. The MCP gateway rules at session, discovery, request and response, and the LLM gateway scans prompts on the way in and completions on the way out. An action that crosses neither gateway nor a managed device has no QuilrAI decision point.
- Identitythe Guardian's verdict is only as specific as what reaches it: a User-Agent keyword or scoped token for the agent, and an email header or JWT for the person, supplied by the calling application. Neither field records who answers for the agent.
- CoverageQuilrAI's reach is the sum of its sensors: the endpoint daemon on macOS and Windows, the browser extension, SaaS connectors and the two gateways. An agent on an unmanaged server, or a customer-facing agent whose traffic is never pointed at a QuilrAI endpoint, sits outside all of them.
The bill follows the same lines. QuilrAI licenses its browser and endpoint sensors by count, from a 100-license floor, and meters LLM and MCP gateway calls per unit, so spend tracks devices and call volume. Agen is licensed per governed agent, so spend tracks the agents themselves.