SERAA Cortex - Multi-Cloud Agent Control Plane | Covasant
CAMS is now SERAA Cortex. The Covasant Agent Management Suite has joined the SERAA platform. Same product, same roadmap, one name, existing contracts, APIs and deployments are unaffected.
Every agent. Every cloud. One control plane.
An AI agent is a mission-critical digital asset. It demands lifecycle governance.
Cortex is the agent operating system for the enterprise agent lifecycle: build, orchestrate, register, and monitor. Vendor-neutral by design, it governs agents that you built here alongside agents built in Gemini, Azure, AWS or Databricks, without fragmentation and without lock-in.
SERAA Cortex, Control Tower, every agent, every cloud
CTO / AI Ops
CONTROL TOWER
Multi-cloud execution monitoring & policy enforcement.
Agent Execution Log• Live
All CloudsGKEAKSEKSAll ScopesSYSTEMORGAll StatusAllowRedact
| Agent | Runtime | Model | Status |
|---|---|---|---|
| kyc-doc-verifier | GKE · us-east | gemini-2.5-flash | Running |
| agentbricks:reg-monitor | AKS · eu-west | gpt-4o-mini | Running |
| dispute-resolver | EKS · us-west | claude-3.5-sonnet | Awaiting HITL |
| partner:nova-ontology | Vertex · global | gemini-2.5-pro | Running |
| portfolio-explainer | GKE · ap-south | gemini-2.5-flash | Running |
| gemini-ent:onboarding | GKE · us-east | gemini-2.5-pro | Running |
Control at a glance
42
Active Agents
3 Clouds
GKE · AKS · EKS
Connected
$1,420
Total Cost (24h)
99.8%
Policy Compliance
3 Tasks
Awaiting Human Review
Review Gate
Governed at every step · Full audit trail & kill switch active.
4 Lifecycle modules, plus Test Bench
GKE · AKS · EKS Multi-cloud runtimes
Dev → Prod Governed promotion with HITL gates
SBAC System, org and project scoping
The hard part was never building the first agent.
It is the fiftieth. Agents built in silos by different teams on different platforms, with no shared governance, no single catalogue, no lifecycle visibility and no audit trail. That is an operations problem.
PROBLEM 01
Nobody owns the estate
Agents appear in business units faster than any central team can inventory them. There is no single catalog and no way to answer what is running.
Uninventoried Agents
PROBLEM 02
Ungoverned paths to production
Without mandatory gates, an agent reaches real data because someone was in a hurry, not because it passed a review.
Bypassed Gates
PROBLEM 03
Cost with no attribution
LLM spend arrives as one invoice. Without per-agent, per-model attribution, nobody can tell which agent is expensive or why.
Unattributed LLM Spend
PROBLEM 04
Vendor fragmentation
Each hyperscaler wants to be the agent platform. Enterprises end up with several, and no layer that governs across them.
Hyperscaler Lock-in
Build, connect, register, monitor, and evaluate before production.
Four official lifecycle modules, each with its own primary persona, plus the Agent Test Bench tracked separately.
01
Agent Work Bench — build
AI Developer / Engineer
Build no-code or pro-code agents in one place, persona, base model, system prompt and knowledge base, tested in an integrated playground before anything moves on. Pro-code runs on LangGraph, so business teams ship without waiting for engineering and engineering keeps the escape hatch.
02
Multi-Agent Orchestration (MAO) — connect
Solutions Architect
Wire agents into multi-step workflows on a visual canvas, with dependency management and error recovery, the coordination layer that turns dozens of individual agents into a process.
03
Agent Registry — register & govern
Governance Lead / Platform Admin
The org-wide catalog. Every agent is versioned and governed through Dev → QA → Pre-Prod → Prod gates with mandatory approval, including agents built on Gemini, Azure or AWS.
04
Agent Control Tower — monitor
AI Operations Manager
Real-time oversight of cost, governance, observability, guardrails and performance. Track LLM spend by agent and model, cap budgets, and kill any misbehaving agent instantly.
05
Agent Test Bench (ATB) — evaluate
Beta
LLM-as-judge evaluation and digital-twin simulation before an agent touches production. In beta, tracked separately from the four shipped modules rather than folded into the count.
Five surfaces, what each one is for.
SERAA Cortex ships as five surfaces. Agent Work Bench, Agent Registry and Agent Control Tower are also available standalone, so an enterprise can adopt the part that matches its current maturity and expand later. The full feature-by-feature reference, every dashboard, panel and integration, lives in the docs; this is the shape of it.
01
Build Surface
Agent Work Bench
The primary development environment. Technical and business teams create, configure and manage individual agents in one interface, with no-code and pro-code paradigms side by side rather than in separate tools.
02
Orchestration
Multi-Agent Orchestration
A drag-and-drop canvas for wiring individual agents into coordinated multi-step pipelines, so a solutions architect designs and deploys a multi-agent workflow without custom engineering.
03
Discovery & Record
Agent Registry
The authoritative record of what agents exist, where they are deployed and how they are managed across environments and tenants, including agents nobody on your platform team built.
04
Production Ops
Agent Control Tower
The production operations centre for every live agent, activity, cost, performance, guardrail enforcement, LLM call logs and policy compliance in one place, regardless of where the agent was built.
05
Platform Admin
System Config
The platform-administration surface behind the four lifecycle modules: who exists, what they can reach, which models and runtimes are available, and where the whole thing runs.
One set of protocols, everywhere agents run.
01
Model Context Protocol (MCP)
Every external tool integration is a standardised MCP server, which is what makes agent-to-service communication secure, auditable and extensible rather than bespoke per tool.
02
Agent-to-Agent (A2A)
Agents invoke and coordinate with other agents as sub-agents inside a workflow, including agents hosted on third-party platforms.
03
RAG knowledge bases
Agents are equipped with domain-specific retrieval-augmented generation stores so answers are grounded in your content rather than in model memory.
Runtimes
KubernetesGKE · AKS · EKS
ManagedGCP Agent Engine
Platform hosting
GCP · AWS · Azure
Discovery & Orchestration
Gemini EnterpriseDiscover · orchestrate
Azure AI FoundryDiscover · orchestrate
AWS BedrockDiscover · orchestrate
Databricks AgentBricksDiscover · orchestrate
Knowledge Base Stores
GoogleVertex AI Search
MicrosoftAzure AI Search
AmazonKendra · OpenSearch · S3 Vector
DatabricksMosaic AI Vector Search
Open sourceFAISS
Sources
GCS · S3 · BigQuery · SharePoint
From first prompt to live kill switch.
Authenticate
Entra ID or GCP SSO
Build & test
Work Bench playground
Register
Deployment plan, any environment
Promote
Governance gates, HITL approval
Monitor
Cost, logs, kill switch on standby
Authenticate once
Cortex runs in any modern browser. Sign in with your organisation's Entra ID or GCP credentials and move across every module without re-authenticating.
Build and test
Configure persona, model and system prompt, optionally attach a knowledge base, and exercise it in the integrated playground before it sees real data.
Register and plan deployment
Create a deployment plan, choose the target environment (Dev, QA or Production) and deploy the instance. Or register an externally-built agent so it falls under the same governance.
Promote through gates
The Registry's promotion workflow runs next, in order, before the agent advances.
Monitor and intervene
Review dashboard metrics, watch live sessions, investigate LLM logs, set budget caps, tune guardrails. Full cost attribution and compliance reporting out of the box, with a kill switch on standby.
The hyperscaler multiverse is the reality, not the exception.
Most enterprises will run agents on more than one cloud, and most will inherit agents built in tools they did not choose. A governance layer that only governs its own agents governs nothing.
Models
Model-agnostic
Orchestrate across OpenAI, Anthropic, Google, Azure and on-premise models simultaneously. No single point of failure.
Clouds
Cloud-agnostic
Deploy on GKE, AKS or EKS, Cloud Run, Azure Functions, Foundry Agent Service or Gemini Agent Engine.
Runtimes
Plugin runtime
A Plugin SDK extends Cortex to proprietary runtimes, including on-prem and VPC edge.
Governance
Governance as foundation
Role-based access, tenant isolation and an immutable activity audit log, built in from day one rather than retrofitted after the first incident.
Responsible AI
Responsible AI enforcement
Guardrail policies enforce content safety, PII detection and redaction, and GDPR and HIPAA compliance across every deployed agent by default.
A category qualifier, not a moat
We are direct about this internally and will be with you. Vendor neutrality for agent governance has become a baseline expectation, competitors have shipped comparable governance platforms. The durable differentiation sits one layer down, in Axon's data mastering and Synapse's shared memory. Cortex's job is to be the control plane you can actually defend in an audit, not to be the only one that exists.
Cortex is one of four. Here is where it sits.
STRAIGHT ANSWERS ON GOVERNING, PROMOTING, COSTING AND STOPPING AI AGENTS.
What is SERAA Cortex?
SERAA Cortex is the operating system for the enterprise agent lifecycle and the Act layer of the SERAA platform. It covers build, orchestration, registration, monitoring & Test Agent from one control plane, across GKE, AKS, EKS, and GCP Agent Engine. It is vendor-neutral by design, so it governs agents built inside it alongside agents built on other platforms.
What are the modules of SERAA Cortex, and can we adopt just one?
SERAA Cortex has four lifecycle modules, and three of the four are adoptable on their own without the rest. Agent Work Bench builds no-code and pro-code agents in one interface, Multi-Agent Orchestration wires them into multi-step workflows on a visual canvas, Agent Registry catalogs and governs them, and Agent Control Tower monitors them in production. Agent Work Bench, Agent Registry, and Agent Control Tower each ship as independent offerings, so you can build without taking the whole suite, govern agents built elsewhere without moving them, or monitor production agents whatever their origin. Covasant reports 70 percent faster time to market for new agents.
Which clouds and runtimes can agents deploy to?
Agents deploy from one workflow to GKE, AKS, EKS, or GCP Agent Engine, which is what makes multi-cloud agent orchestration possible without a separate control plane for every cloud. Platform hosting runs on Google Cloud, AWS, or Azure. Single sign-on works with Microsoft Entra ID, GCP IAM, AWS Cognito, SAML, and one account can hold different roles at different scopes.
Can we use our own tools and third-party agents with SERAA Cortex?
Yes. Every external tool integration in SERAA Cortex is a standardized Model Context Protocol server, registered centrally in an MCP Hub with its metadata, scope, category, execution logic, inputs, and outputs, then published into the agent canvas for any agent to call. A2A protocol support means agents invoke and coordinate with other agents as sub-agents inside a workflow, including agents hosted on third-party platforms. That is what keeps tool and agent integration auditable and extensible rather than bespoke for every connection.
Which large language models can agents use?
The Model Hub in SERAA Cortex carries more than 100 large language models across Google, Anthropic, OpenAI, Azure, AWS, and Databricks etc and this keeps getting added as and when new model is available. Multi-Agent Orchestration supports node-wise model selection, so a different model can run at each stage of a workflow rather than one model across the whole pipeline.Covasant reports 40 to 60 percent lower model spend through governed routing.
How do you track and cap what an AI agent costs?
SERAA Cortex attributes cost by agent, model, user, provider, and tenant, with configurable budget caps on each of them. Every large language model call is written to a searchable log carrying timestamp, status, session ID, agent, model, tokens, and per-call cost, so who ran what and what it cost is one query rather than an investigation across three vendors' invoices. Budget caps sit in the same control plane, so a run that breaches its ceiling can be stopped rather than found later in a monthly bill.
How does an agent get promoted to production?
An agent is promoted through Agent Registry's governed promotion workflow, where each environment transition, Dev to QA to Staging to Production, runs through a checklist-driven approval gate that cannot be skipped. When a team requests a promotion, the agent is scored against the applicable promotion policy and must clear a configurable readiness threshold before the promotion can even be submitted. Every requested promotion surfaces in a promotion approvals workspace as one view showing the promotion path, a live readiness percentage, current status, and approver feedback. Checklist items accept mixed evidence: approver sign-offs, file attachments such as security scans, free-text entries such as data classification, and confirmations such as guardrails enabled. The gates are defined centrally as reusable promotion policies, scoped to an organization or project, so the same governance applies to every agent. Agents carry strict semantic versioning of major, minor, and patch, and any version can be diffed against the one before it and reviewed before publishing. An externally built agent registered into the catalog passes the same gates as anything built in SERAA Cortex.
Can we test an agent before it reaches production?
Agent Test Bench within SERAA Cortex simulates Agent conversational interactions against a workflow built from your own historical logs, and execution validation. It profiles your knowledge bases and historical ground truth, clusters semantic intents without manual test-case authoring, synthesizes scenarios across expert, novice, and adversarial personas, and returns a scored baseline on faithfulness, context precision, and task success rate etc.
How is access controlled across teams and tenants?
Access in SERAA Cortex runs on Scope-Based Access Control, using three nested scopes: System for enterprise-wide standards and approved models, Organization for a business unit shaping its own environment, and Project for the specific use case. Assets flow upward, so an agent, knowledge base, or tool stays anchored to the scope that created it and is visible to every scope above. Infrastructure flows downward, so a project can never reach for capability its parent has not granted. SERAA Cortex manages distinct prompts, keys, knowledge bases, and rules per tenant from one control plane.
Are there other vendor-neutral AI agent governance platforms?
Yes. Vendor neutrality has become a category qualifier rather than a differentiator, and several platforms now claim it. What varies between them is how much survives a cloud boundary. Every hyperscaler governs well inside its own perimeter, and no cloud provider can sell cross-vendor governance without arguing against its own consolidation case, which is a position rather than a gap in execution. What SERAA Cortex adds is one catalog, one policy engine, and one cost view that hold across four vendor platforms, which is what an audit actually tests.
Bring one agent estate nobody can currently see.
We will show you what governing it actually looks like, catalogue, gates, cost attribution and kill switch, on your own cloud.