SERAA Cortex - Multi-Cloud Agent Control Plane | Covasant

CAMS is now SERAA Cortex. The Covasant Agent Management Suite has joined the SERAA platform. Same product, same roadmap, one name, existing contracts, APIs and deployments are unaffected.

Every agent. Every cloud. One control plane.

An AI agent is a mission-critical digital asset. It demands lifecycle governance.

Cortex is the agent operating system for the enterprise agent lifecycle: build, orchestrate, register, and monitor. Vendor-neutral by design, it governs agents that you built here alongside agents built in Gemini, Azure, AWS or Databricks, without fragmentation and without lock-in.

Book a demo Platform overview

SERAA Cortex, Control Tower, every agent, every cloud

CTO / AI Ops

CONTROL TOWER

Multi-cloud execution monitoring & policy enforcement.

Agent Execution Log• Live

All CloudsGKEAKSEKSAll ScopesSYSTEMORGAll StatusAllowRedact

Agent Runtime Model Status
kyc-doc-verifier GKE · us-east gemini-2.5-flash Running
agentbricks:reg-monitor AKS · eu-west gpt-4o-mini Running
dispute-resolver EKS · us-west claude-3.5-sonnet Awaiting HITL
partner:nova-ontology Vertex · global gemini-2.5-pro Running
portfolio-explainer GKE · ap-south gemini-2.5-flash Running
gemini-ent:onboarding GKE · us-east gemini-2.5-pro Running

Control at a glance

42

Active Agents

3 Clouds

GKE · AKS · EKS

Connected

$1,420

Total Cost (24h)

99.8%

Policy Compliance

3 Tasks

Awaiting Human Review

Review Gate

Governed at every step · Full audit trail & kill switch active.

4 Lifecycle modules, plus Test Bench

GKE · AKS · EKS Multi-cloud runtimes

Dev → Prod Governed promotion with HITL gates

SBAC System, org and project scoping

The hard part was never building the first agent.

It is the fiftieth. Agents built in silos by different teams on different platforms, with no shared governance, no single catalogue, no lifecycle visibility and no audit trail. That is an operations problem.

PROBLEM 01

Nobody owns the estate

Agents appear in business units faster than any central team can inventory them. There is no single catalog and no way to answer what is running.

Uninventoried Agents

PROBLEM 02

Ungoverned paths to production

Without mandatory gates, an agent reaches real data because someone was in a hurry, not because it passed a review.

Bypassed Gates

PROBLEM 03

Cost with no attribution

LLM spend arrives as one invoice. Without per-agent, per-model attribution, nobody can tell which agent is expensive or why.

Unattributed LLM Spend

PROBLEM 04

Vendor fragmentation

Each hyperscaler wants to be the agent platform. Enterprises end up with several, and no layer that governs across them.

Hyperscaler Lock-in

Build, connect, register, monitor, and evaluate before production.

Four official lifecycle modules, each with its own primary persona, plus the Agent Test Bench tracked separately.

01

Agent Work Bench — build

AI Developer / Engineer

Build no-code or pro-code agents in one place, persona, base model, system prompt and knowledge base, tested in an integrated playground before anything moves on. Pro-code runs on LangGraph, so business teams ship without waiting for engineering and engineering keeps the escape hatch.

02

Multi-Agent Orchestration (MAO) — connect

Solutions Architect

Wire agents into multi-step workflows on a visual canvas, with dependency management and error recovery, the coordination layer that turns dozens of individual agents into a process.

03

Agent Registry — register & govern

Governance Lead / Platform Admin

The org-wide catalog. Every agent is versioned and governed through Dev → QA → Pre-Prod → Prod gates with mandatory approval, including agents built on Gemini, Azure or AWS.

04

Agent Control Tower — monitor

AI Operations Manager

Real-time oversight of cost, governance, observability, guardrails and performance. Track LLM spend by agent and model, cap budgets, and kill any misbehaving agent instantly.

05

Agent Test Bench (ATB) — evaluate

Beta

LLM-as-judge evaluation and digital-twin simulation before an agent touches production. In beta, tracked separately from the four shipped modules rather than folded into the count.

Five surfaces, what each one is for.

SERAA Cortex ships as five surfaces. Agent Work Bench, Agent Registry and Agent Control Tower are also available standalone, so an enterprise can adopt the part that matches its current maturity and expand later. The full feature-by-feature reference, every dashboard, panel and integration, lives in the docs; this is the shape of it.

01

Build Surface

Agent Work Bench

The primary development environment. Technical and business teams create, configure and manage individual agents in one interface, with no-code and pro-code paradigms side by side rather than in separate tools.

02

Orchestration

Multi-Agent Orchestration

A drag-and-drop canvas for wiring individual agents into coordinated multi-step pipelines, so a solutions architect designs and deploys a multi-agent workflow without custom engineering.

03

Discovery & Record

Agent Registry

The authoritative record of what agents exist, where they are deployed and how they are managed across environments and tenants, including agents nobody on your platform team built.

04

Production Ops

Agent Control Tower

The production operations centre for every live agent, activity, cost, performance, guardrail enforcement, LLM call logs and policy compliance in one place, regardless of where the agent was built.

05

Platform Admin

System Config

The platform-administration surface behind the four lifecycle modules: who exists, what they can reach, which models and runtimes are available, and where the whole thing runs.

One set of protocols, everywhere agents run.

01

Model Context Protocol (MCP)

Every external tool integration is a standardised MCP server, which is what makes agent-to-service communication secure, auditable and extensible rather than bespoke per tool.

02

Agent-to-Agent (A2A)

Agents invoke and coordinate with other agents as sub-agents inside a workflow, including agents hosted on third-party platforms.

03

RAG knowledge bases

Agents are equipped with domain-specific retrieval-augmented generation stores so answers are grounded in your content rather than in model memory.

Runtimes

KubernetesGKE · AKS · EKS

ManagedGCP Agent Engine

Platform hosting

GCP · AWS · Azure

Discovery & Orchestration

Gemini EnterpriseDiscover · orchestrate

Azure AI FoundryDiscover · orchestrate

AWS BedrockDiscover · orchestrate

Databricks AgentBricksDiscover · orchestrate

Knowledge Base Stores

GoogleVertex AI Search

MicrosoftAzure AI Search

AmazonKendra · OpenSearch · S3 Vector

DatabricksMosaic AI Vector Search

Open sourceFAISS

Sources

GCS · S3 · BigQuery · SharePoint

From first prompt to live kill switch.

Authenticate

Entra ID or GCP SSO

Build & test

Work Bench playground

Register

Deployment plan, any environment

Promote

Governance gates, HITL approval

Monitor

Cost, logs, kill switch on standby

Authenticate once

Cortex runs in any modern browser. Sign in with your organisation's Entra ID or GCP credentials and move across every module without re-authenticating.

Build and test

Configure persona, model and system prompt, optionally attach a knowledge base, and exercise it in the integrated playground before it sees real data.

Register and plan deployment

Create a deployment plan, choose the target environment (Dev, QA or Production) and deploy the instance. Or register an externally-built agent so it falls under the same governance.

Promote through gates

The Registry's promotion workflow runs next, in order, before the agent advances.

Monitor and intervene

Review dashboard metrics, watch live sessions, investigate LLM logs, set budget caps, tune guardrails. Full cost attribution and compliance reporting out of the box, with a kill switch on standby.

The hyperscaler multiverse is the reality, not the exception.

Most enterprises will run agents on more than one cloud, and most will inherit agents built in tools they did not choose. A governance layer that only governs its own agents governs nothing.

Models

Model-agnostic

Orchestrate across OpenAI, Anthropic, Google, Azure and on-premise models simultaneously. No single point of failure.

Clouds

Cloud-agnostic

Deploy on GKE, AKS or EKS, Cloud Run, Azure Functions, Foundry Agent Service or Gemini Agent Engine.

Runtimes

Plugin runtime

A Plugin SDK extends Cortex to proprietary runtimes, including on-prem and VPC edge.

Governance

Governance as foundation

Role-based access, tenant isolation and an immutable activity audit log, built in from day one rather than retrofitted after the first incident.

Responsible AI

Responsible AI enforcement

Guardrail policies enforce content safety, PII detection and redaction, and GDPR and HIPAA compliance across every deployed agent by default.

A category qualifier, not a moat

We are direct about this internally and will be with you. Vendor neutrality for agent governance has become a baseline expectation, competitors have shipped comparable governance platforms. The durable differentiation sits one layer down, in Axon's data mastering and Synapse's shared memory. Cortex's job is to be the control plane you can actually defend in an audit, not to be the only one that exists.

Cortex is one of four. Here is where it sits.

STRAIGHT ANSWERS ON GOVERNING, PROMOTING, COSTING AND STOPPING AI AGENTS.

What is SERAA Cortex?

SERAA Cortex is the operating system for the enterprise agent lifecycle and the Act layer of the SERAA platform. It covers build, orchestration, registration, monitoring & Test Agent from one control plane, across GKE, AKS, EKS, and GCP Agent Engine. It is vendor-neutral by design, so it governs agents built inside it alongside agents built on other platforms.

What are the modules of SERAA Cortex, and can we adopt just one?

SERAA Cortex has four lifecycle modules, and three of the four are adoptable on their own without the rest. Agent Work Bench builds no-code and pro-code agents in one interface, Multi-Agent Orchestration wires them into multi-step workflows on a visual canvas, Agent Registry catalogs and governs them, and Agent Control Tower monitors them in production. Agent Work Bench, Agent Registry, and Agent Control Tower each ship as independent offerings, so you can build without taking the whole suite, govern agents built elsewhere without moving them, or monitor production agents whatever their origin. Covasant reports 70 percent faster time to market for new agents.

Which clouds and runtimes can agents deploy to?

Agents deploy from one workflow to GKE, AKS, EKS, or GCP Agent Engine, which is what makes multi-cloud agent orchestration possible without a separate control plane for every cloud. Platform hosting runs on Google Cloud, AWS, or Azure. Single sign-on works with Microsoft Entra ID, GCP IAM, AWS Cognito, SAML, and one account can hold different roles at different scopes.

Can we use our own tools and third-party agents with SERAA Cortex?

Yes. Every external tool integration in SERAA Cortex is a standardized Model Context Protocol server, registered centrally in an MCP Hub with its metadata, scope, category, execution logic, inputs, and outputs, then published into the agent canvas for any agent to call. A2A protocol support means agents invoke and coordinate with other agents as sub-agents inside a workflow, including agents hosted on third-party platforms. That is what keeps tool and agent integration auditable and extensible rather than bespoke for every connection.

Which large language models can agents use?

The Model Hub in SERAA Cortex carries more than 100 large language models across Google, Anthropic, OpenAI, Azure, AWS, and Databricks etc and this keeps getting added as and when new model is available. Multi-Agent Orchestration supports node-wise model selection, so a different model can run at each stage of a workflow rather than one model across the whole pipeline.Covasant reports 40 to 60 percent lower model spend through governed routing.

How do you track and cap what an AI agent costs?

SERAA Cortex attributes cost by agent, model, user, provider, and tenant, with configurable budget caps on each of them. Every large language model call is written to a searchable log carrying timestamp, status, session ID, agent, model, tokens, and per-call cost, so who ran what and what it cost is one query rather than an investigation across three vendors' invoices. Budget caps sit in the same control plane, so a run that breaches its ceiling can be stopped rather than found later in a monthly bill.

How does an agent get promoted to production?

An agent is promoted through Agent Registry's governed promotion workflow, where each environment transition, Dev to QA to Staging to Production, runs through a checklist-driven approval gate that cannot be skipped. When a team requests a promotion, the agent is scored against the applicable promotion policy and must clear a configurable readiness threshold before the promotion can even be submitted. Every requested promotion surfaces in a promotion approvals workspace as one view showing the promotion path, a live readiness percentage, current status, and approver feedback. Checklist items accept mixed evidence: approver sign-offs, file attachments such as security scans, free-text entries such as data classification, and confirmations such as guardrails enabled. The gates are defined centrally as reusable promotion policies, scoped to an organization or project, so the same governance applies to every agent. Agents carry strict semantic versioning of major, minor, and patch, and any version can be diffed against the one before it and reviewed before publishing. An externally built agent registered into the catalog passes the same gates as anything built in SERAA Cortex.

Can we test an agent before it reaches production?

Agent Test Bench within SERAA Cortex simulates Agent conversational interactions against a workflow built from your own historical logs, and execution validation. It profiles your knowledge bases and historical ground truth, clusters semantic intents without manual test-case authoring, synthesizes scenarios across expert, novice, and adversarial personas, and returns a scored baseline on faithfulness, context precision, and task success rate etc.

How is access controlled across teams and tenants?

Access in SERAA Cortex runs on Scope-Based Access Control, using three nested scopes: System for enterprise-wide standards and approved models, Organization for a business unit shaping its own environment, and Project for the specific use case. Assets flow upward, so an agent, knowledge base, or tool stays anchored to the scope that created it and is visible to every scope above. Infrastructure flows downward, so a project can never reach for capability its parent has not granted. SERAA Cortex manages distinct prompts, keys, knowledge bases, and rules per tenant from one control plane.

Are there other vendor-neutral AI agent governance platforms?

Yes. Vendor neutrality has become a category qualifier rather than a differentiator, and several platforms now claim it. What varies between them is how much survives a cloud boundary. Every hyperscaler governs well inside its own perimeter, and no cloud provider can sell cross-vendor governance without arguing against its own consolidation case, which is a position rather than a gap in execution. What SERAA Cortex adds is one catalog, one policy engine, and one cost view that hold across four vendor platforms, which is what an audit actually tests.

Bring one agent estate nobody can currently see.

We will show you what governing it actually looks like, catalogue, gates, cost attribution and kill switch, on your own cloud.