HookBus Enterprise

Part of HookBus Enterprise

AgentProtect CRE

When there is no human in the loop, CRE is the Agent in the Loop.

The policy enforcement component inside HookBus Enterprise. Every consequential tool call passes through AgentProtect CRE before execution. The AI cannot bypass, disable, or argue with it.

Book a demo Full CRE detail →

Three outcomes

Deny. Allow. Ask.

Every tool call is evaluated before execution. Three possible outcomes, one mechanical gate.

DENY

Hard block

The agent cannot execute this action. Full audit record created. Deterministic rules fire in under 10ms.

ALLOW

Permitted

Tool call passes through. Agent continues. L1 and L2 evaluation both passed.

ASK

Human required

Approval is needed. Approver receives a notification link. Approve or deny from any device. Full audit trail.

Two layers

Deterministic speed.
Probabilistic depth.

L1

Deterministic patterns

Under 10ms

Explicit action, resource, scope, risk, and organisation-policy patterns evaluated before consequential actions execute.

L2

Probabilistic patterns

Customer-approved model path

Evaluates ambiguous intent, alignment, and policy context. Catches substitutions, shortcuts, and creative reinterpretations that deterministic rules alone miss.

Features

What CRE does that system prompts cannot.

Mechanical enforcement — operates outside the AI's context window. The AI cannot skip, modify, or argue with it.
Intent alignment — L2 evaluates whether the tool call matches the user's instruction and policy context.
Anti-evasion — detects encoded commands, lateral movement, and scripts designed to bypass enforcement.
Audit-ready — full audit trail, every decision logged. SOC2-ready, ISO 27001-ready, ISO 42001-ready.