Organizations are deploying AI agents into governance-critical processes — procurement, risk decisions, compliance enforcement, architectural change. The gap between what these agents can do and what governance can verify is widening. That gap is where catastrophic failures live — not because the AI is wrong, but because governance can't tell whether it's right.
We built OntoRamp on a bet: governance is not a compliance problem — it is a physics problem. Organizational intent degrades through transformation the same way energy dissipates through friction. Policies exist but nothing connects them to the decisions they're supposed to govern. Accountability is declared but structurally unenforced. These aren't failures of discipline. They're structural gaps that only a graph can see.
The pages below are the published specification of a computable governance system — the theoretical framework, the measurement vocabulary, the domains we assess, the methodology we follow, and the API that makes it programmable. Written for governance architects, platform engineers, and executives who need precision, not persuasion.
Quickstart
Zero to your first governance tool call in about five minutes — get a free API key, connect your MCP client, and run your first free tool.
Framework
The theoretical foundation. Why governance is a physics problem — and why conservation, not optimization, is the correct frame for organizational transformation.
Vocabulary
The measurement scale. Five tiers on the Governance Ladder — defined precisely enough to compute, not just discuss.
Domains
The assessment surface. Seven domains that map the full governance structure of an organization.
Methodology
How it works. What an Enterprise Governance Assessment measures, how it computes scores, and what the outputs mean.
ArchiMate Export
The deliverable. How a governance maturity assessment exports a standards-compliant ArchiMate 3.2 model — four viewpoints, ready for your EA tool.
Glossary
Every term, defined. The complete vocabulary — precise enough to eliminate ambiguity between engineering and governance teams.
MCP API
The programmable interface. Eleven tools across three plugins — connect your agent runtime to governance intelligence.
Agent Authentication
How an AI agent authenticates to the governed MCP server — a Bearer API key and the WWW-Authenticate challenge an unauthenticated request receives.
Agent Discovery
How agents discover OntoRamp through machine-readable descriptors, call its tools, and transact — including a programmatic checkout link.
RFC 9728 Discovery
A worked RFC 9728 (OAuth 2.0 Protected Resource Metadata) discovery example — how an AI agent reads OntoRamp’s protected-resource metadata to learn the auth method: a Bearer API key, no OAuth authorization server.
Connect
Setup guides. Add OntoRamp to Perplexity, Le Chat, LangSmith, AWS AgentCore, Gemini CLI, Cursor, and VS Code.
SOC 2 Readiness Assessment
How to run a SOC 2 readiness assessment as a structural exercise — documentation coverage and control-to-evidence traceability before the audit.
ISO 27001 Gap Analysis
How to do an ISO 27001 gap analysis: Annex A control intent versus broken evidence chains across the governance domains.
AI Governance Readiness
How to assess AI governance readiness for autonomous agents — agent-deployment governance, model-risk controls, and a computable access boundary.
Governance Maturity Assessment
How to measure governance maturity across the enterprise — score the seven domains on a five-level maturity scale from your corpus.
Technology Due Diligence
How to do technology due diligence for an M&A deal — the governance and architecture posture a curated data room hides.
Board Governance Report
How to prepare a board-ready governance posture report — translate a structural assessment into executive risk visibility.