Checking Control live demo · Runtime authorization for AI context

AI context should not gain authority just because an agent can access it.

Johka Control enforces runtime authorization for AI context flows, correlation and derived context—before protected context reaches the AI provider. It is a complete, independently deployable product.

  • Customer-hosted
  • Independent product
  • Fail-closed
  • Auditable
  • Provider-independent core
LIVE ENFORCEMENT PATH POLICY ACTIVE
01
REQUEST ORIGINApplication / Agent
CONTEXT ATTACHED
Context envelope
ENFORCEMENT POINTJOHKA CONTROL
VERIFYING
IdentityPurposeGrantLineage
ALLOWREDACTBLOCKREQUIRE_APPROVAL
AUTHORIZED PAYLOAD
03
UPSTREAMAI Provider
MINIMIZED
UNAUTHORIZEDNO PROVIDER CALL

AI systems can reach more context than they should be allowed to use.

Retrieval controls what data can be found. Johka controls whether context may flow, correlate, be derived or be reused at runtime.

01

Access is not correlation authority

An agent may technically reach two contexts without being authorized to combine them. Johka makes that boundary explicit and enforceable.

REACHABLE ≠ AUTHORIZED
02

Derived context keeps its authority

Summaries and inferred facts do not become unrestricted because they are new. Johka carries origin, lineage and policy forward.

DERIVATION ≠ RESET
03

Unauthorized means no provider call

When Johka refuses a flow, protected context stays at the enforcement point. The upstream AI provider receives nothing.

BLOCK = ZERO EGRESS

Your agent can access both. That does not mean it may combine both.

Johka is for teams whose AI agents work across conversations, CRM records, orders, cases, documents and connected systems. Traditional access control can prove reach. Johka decides whether those contexts may be combined for this task.

Customer-support AIMulti-tenant B2B SaaSEnterprise copilotsAI agent platformsFintech & insuranceHealthcare · HR · legal
PRIMARY USE CASESUPPORT + CRM + ORDER
SOURCE 01Support conversationQuestion · email · internal note
SOURCE 02CRM & order dataAccount · status · payment · contract
THE REAL AUTHORIZATION QUESTION

Which customer fields may be combined for this purpose, sent to this destination and reused later?

QUALIFICATIONJOHKA BECOMES RELEVANT WHEN…
  1. 01

    The AI can reach at least two separate data sources.

  2. 02

    Those sources contain customer, tenant or otherwise bounded context.

  3. 03

    Not every accessible field may be combined for every AI task.

  4. 04

    The AI can send context to a provider or execute actions.

  5. 05

    You must prove why a combination was allowed.

  6. 06

    Authority can expire, be revoked or depend on purpose and destination.

Four or more apply? Your architecture is a strong fit for a Johka evaluation.

JOHKA CONTROL

Decides what AI is allowed to do.

JOHKA LINK

Connects the context Control has approved.

THE RULE

Connectivity is not authorization.

Not every AI system needs Johka.

PROBABLY NOT NECESSARY

One unrestricted source. No meaningful boundary crossing.

If an AI workflow reads one public or unrestricted source and does not cross customer, purpose or provider boundaries, Johka may be unnecessary.

JOHKA BECOMES RELEVANT

Multiple bounded contexts. Access to both must not mean permission to combine both.

That is where purpose, field scope, destination, reuse and technical evidence need an enforceable runtime decision.

Watch authority change—not just the prompt.

One request evolves across context boundaries, explicit grants, minimization, derivation and revocation. Johka evaluates every transition.

STEP 01 / 06ALLOW

Bind authority to origin

A payroll context enters with tenant, principal and purpose already attached. Johka evaluates the flow before payload inspection begins.

REQUESTpayroll/employee-104 → benefits-agent
DECISION EVIDENCEruntime
  • tenant: acme-eu
  • principal: hr-ops
  • purpose: benefits-review
PROVIDER CALLPermitted

Built as enforcement infrastructure, not another AI data layer.

Johka sits in the execution path and returns an enforceable decision before an AI request can leave the controlled environment.

CUSTOMER ENVIRONMENT
CALLERSApps · Agents · RAGContext identity attached
→
PRIVATE CONTAINERJohka ControlPolicy · grants · lineage
→
GATEWAYProvider AdapterOpenAI proven today
AUDIT RAIL

Decision metadata · finding types · grant state · no raw protected context

Customer-hosted inside your controlled environment
Private, versioned container deployed inside your controlled environment
Scoped grants by purpose, principal, agent and context
Revocation and expiry evaluated at runtime
Context lineage retained across derived information
Privacy-preserving audit without raw protected content
CONTEXT MANAGEMENT

Organizes what AI can find.

≠
JOHKA CONTROL

Determines what AI context may do.

Prove one protected AI workflow in your own environment.

A fixed-scope Johka Control pilot for the first five design partners. Control remains independently deployable. Johka Link and work beyond this pilot are separately scoped.

Open Control live demo
FOUNDING DESIGN PARTNER · 5 PLACES ONLYJohka Control
FIXED-SCOPE PILOT€3,500FIXED SCOPE · EXCL. VAT

Founding Design Partner · 5 places only.

Founding partner pricing reflects the limited pilot scope and early product feedback.

  • 1 protected AI workflow
  • 1 customer-hosted deployment
  • 1 provider path
  • Context-flow and boundary mapping
  • Policy, grant and audit configuration
  • Technical evidence and pilot readout

Timing: 5–10 working days of implementation, typically completed within 2–4 calendar weeks.

You leave with: a working protected workflow, deployed enforcement and technical evidence of what was allowed, restricted and blocked.

No long-term commitment required for the pilot.

Anything outside the agreed scope: Separately scoped.

Pilot pricing covers a fixed-scope validation engagement. Production licensing, additional workflows, deployments and ongoing support are agreed separately after the pilot.

Discuss your pilot

Prove the boundary first. Expand only when it works.

  1. 01Fixed-scope pilot

    Protect and prove one real AI workflow in your environment.

  2. 02Production deployment

    Agree the production scope, licensing, implementation and support.

  3. 03More protected workflows

    Expand deliberately across additional flows, sources or deployments.

Production licensing and ongoing support are agreed after a successful pilot.

OOK VAN JOHKA

Een professionele website, volledig geregeld.

Johka ontwerpt, bouwt, host en onderhoudt websites voor zelfstandigen en kleine ondernemingen. Eén aanspreekpunt van eerste idee tot dagelijks beheer.

Ontdek Johka Websites