Govern every team's agents
under one roof.
When agents move from one developer's laptop to the whole org, the keys, the budgets and the audit trail scatter. P1 Halo pulls them back together — a shared vault, role-based access, and one signed audit chain for the entire company.
Five Solos give you
five blind spots.
As you grow, the easy move is to let each team buy its own seat and govern itself. But governance doesn't add up that way — five separate accounts means five separate vaults, five sets of rules, and five audit trails that never reconcile. The platform team inherits the gap between them.
Five accounts, five blind spots
Independent seats can't see each other. When leadership asks “company-wide, what did our agents do this quarter and what did it cost?”, the answer is five exports in five formats that don't add up — and no single chain anyone can re-verify.
SCATTERED · NO ONE VIEWOne chain of custody instead
Consolidate onto one org with role-based access and a shared vault, and every team's runs flow into a single actor-stamped, Ed25519-signed chain. One vault to rotate, one set of rules, one budget hard-stop, one export the whole company stands behind.
CONSOLIDATED · ONE SIGNED CHAINOne place to hold the keys, budgets & proof.
Agent adoption spreads faster than governance. Without one place to hold keys, gate destructive actions and capture what happened, every team becomes its own unaudited island. Five controls pull it back under one roof.
Shared vault, not scattered secrets BYOK · LIBSODIUM-ENCRYPTED
One encrypted vault holds your model keys for the whole org. Keys are libsodium-encrypted at rest and injected by the sole-egress broker at call time — they never enter an agent container and never get pasted into five different repos.
Role-based access for the whole org OWNER · REVIEWER · VIEWER
Owner, reviewer and viewer roles are enforced server-side, below the agent. A read-only viewer can't touch shared keys or billing; a reviewer can approve work but not delete the vault. Everyone sees what they should — nothing more.
Separation of duties on destructive actions ROLE-GATED
The actions that can hurt you — wiping shared keys, changing billing, cancelling a run — are gated by role. No single seat can quietly do all of it, and removing a member can't lock out the last owner.
One org budget, one hard stop PER-RUN + ORG CAP
Set per-run and org-wide cost caps. Cross a cap and a host-authoritative watchdog SIGKILLs the run — an escaped agent can't outspend the thing that kills it. No surprise bill at the end of the month.
One signed audit chain for everyone Ed25519 · ACTOR-STAMPED
Every team's runs flow into a single Ed25519-signed, hash-chained log — actor-stamped, so you know who launched what. Export the whole org's history and re-verify every event offline. Tamper one byte and verification fails.
Sell governance, not seats. A solo plan protects a developer. Team protects the company — one vault, one set of rules, and one audit chain you can hand to whoever asks how your agents behave.
Consolidate the blind spots
into one chain.
Roll your teams onto one org with a shared vault, role-based access, an org budget hard-stop, and one signed audit chain you re-verify yourself. Team $544 for up to 5 seats · Business $1,779 for up to 20 — BYOK, so you only pay your provider for tokens. We're honest about the edges: SSO/SAML isn't here yet, and our SOC 2 attestation is targeted for Q3 2026 — what ships today is the governance and the proof.