Zahen

Put governed AI agents inside your product

Zahen is Toobler's governed agentic AI engine. It runs agents under rules you set — grounded in knowledge they are allowed to read, paused for a person's approval before anything consequential, and logged end to end. It ships with no front end of its own, because the first way we deploy it is behind software you already have.

The Zahen console's Knowledge screen: policy documents indexed for retrieval, each row carrying the department that owns it and the access level that governs it — employee, department or restricted — so what an agent can search is set by permission, not by prompt.

Adding an agent is easy. Shipping one safely is the year of work.

The model is the least of it. Before an agent can touch a customer record, move money or send something on your behalf, someone has to be able to answer three questions: what was it allowed to see, who approved the action, and can you still prove both a year from now.

That is what Zahen is — not a chatbot and not a model, but a runtime agents execute inside, where those answers are produced as a by-product of running rather than promised in a prompt.

The governance spine

What the runtime enforces, whatever the model does

  1. Grounded retrieval

    An agent only reads what the person it is acting for is allowed to read. Permissions are applied before the search runs, not filtered out of the answer afterwards.

  2. Human approval gates

    Anything consequential stops and waits. The proposed action goes to a person, and Zahen refuses to proceed without a recorded decision.

  3. Separation of duties

    Whoever started a run cannot approve it. Zahen checks that itself, so a self-approval fails even if the surrounding system would have allowed it.

  4. Scope that only narrows

    Each run is bound to a scope fixed at the start, which can shrink but never widen. An agent cannot talk itself into more access mid-task.

  5. No credentials held

    Zahen holds no keys to your systems. It asks your backend to act, and your backend re-checks the request against live permissions before it does.

  6. Append-only audit

    Every retrieval, proposal, decision and system call is written once and never edited. Exportable, and readable by someone who was not in the room.

Two ways to adopt it

Behind your product, or in front of your own team

  1. Embedded — inside software you already have

    Our primary route. Your backend calls Zahen; Zahen renders nothing. Your users get governed agents inside the product they already use, with no second login and no sign of us anywhere they can see. This is how our own products run.

  2. Standalone — a governed workspace

    The same engine with its own console, for teams that want governed agents without building a surface for them: a workspace to start runs, an approval queue for the people who sign off, and the audit trail behind both.

One run, end to end

What actually happens when an agent acts

  1. 01

    Your system starts the run

    Your backend asks for a run and signs who it is for, on whose behalf, and the scope of what this run may touch. Zahen will not start without that.

  2. 02

    The agent reads what it may

    Retrieval is filtered to the requester's own permissions before the search, so nothing the person could not open becomes a candidate answer.

  3. 03

    It proposes, rather than acts

    The model returns an intended action. Low-risk steps continue; anything with consequences outside the run is gated instead of executed.

  4. 04

    A person decides

    The run suspends and your own interface shows the exact draft that would execute. The decision comes back signed and bound to that run.

  5. 05

    Zahen acts, and records it

    Execution goes back through your systems, which re-authorize it. Every step lands in an audit trail you can export and hand to a reviewer.

Built for the work that has consequences

Zahen exists for the workflows where an agent being wrong is expensive — one that touches a customer record, moves money, commits the company, or goes out under your name. In those places the question was never whether the model could do the task. It is whether you can show what it was allowed to see, and who agreed to the action.

Go deeper: Embedded mode and the six integration seams · How the governance actually works · Agentic AI as a capability

Talk to the team that built it

Bring the workflow you would not let an unsupervised agent near. That is the one worth governing first.

Frequently asked

Is Zahen a model?
No. Zahen is the runtime agents execute inside. It selects and calls models under a policy you set, but the product is the governance around them — permissioned retrieval, approval gates, scope limits and the audit trail.
Do our users have to learn a new tool?
In embedded mode, no. Zahen has no interface of its own, so your product keeps the whole experience — including the screen where a person approves what an agent proposed.
Where does our data go?
Into your own isolated deployment. One tenant's data never enters another tenant's run, secrets are scoped per tenant, and customer data is not used to train or fine-tune models.
Can we start small?
That is the only way we start. One scoped workflow, with the approval gate and audit trail on from day one. Every Zahen integration is a co-build with our engineers rather than a self-serve signup.

Start with one measurable use case.

A Readiness Sprint is a fixed-scope engagement that maps your integration and AI readiness and produces a production-oriented plan — before anything is built.