Skip to main content

Organizations are deploying AI agents into governance-critical processes — procurement, risk decisions, compliance enforcement, architectural change. The gap between what these agents can do and what governance can verify is widening. That gap is where catastrophic failures live — not because the AI is wrong, but because governance can't tell whether it's right.

We built OntoRamp on a bet: governance is not a compliance problem — it is a physics problem. Organizational intent degrades through transformation the same way energy dissipates through friction. Policies exist but nothing connects them to the decisions they're supposed to govern. Accountability is declared but structurally unenforced. These aren't failures of discipline. They're structural gaps that only a graph can see.

The pages below are the published specification of a computable governance system — the theoretical framework, the measurement vocabulary, the domains we assess, the methodology we follow, and the API that makes it programmable. Written for governance architects, platform engineers, and executives who need precision, not persuasion.

Quickstart

Zero to your first governance tool call in about five minutes — get a free API key, connect your MCP client, and run your first free tool.

Framework

The theoretical foundation. Why governance is a physics problem — and why conservation, not optimization, is the correct frame for organizational transformation.

Vocabulary

The measurement scale. Five tiers on the Governance Ladder — defined precisely enough to compute, not just discuss.

Domains

The assessment surface. Seven domains that map the full governance structure of an organization.

Methodology

How it works. What an Enterprise Governance Assessment measures, how it computes scores, and what the outputs mean.

ArchiMate Export

The deliverable. How a governance maturity assessment exports a standards-compliant ArchiMate 3.2 model — four viewpoints, ready for your EA tool.

Glossary

Every term, defined. The complete vocabulary — precise enough to eliminate ambiguity between engineering and governance teams.

MCP API

The programmable interface. Eleven tools across three plugins — connect your agent runtime to governance intelligence.

Agent Authentication

How an AI agent authenticates to the governed MCP server — a Bearer API key and the WWW-Authenticate challenge an unauthenticated request receives.

Agent Discovery

How agents discover OntoRamp through machine-readable descriptors, call its tools, and transact — including a programmatic checkout link.

RFC 9728 Discovery

A worked RFC 9728 (OAuth 2.0 Protected Resource Metadata) discovery example — how an AI agent reads OntoRamp’s protected-resource metadata to learn the auth method: a Bearer API key, no OAuth authorization server.

Connect

Setup guides. Add OntoRamp to Perplexity, Le Chat, LangSmith, AWS AgentCore, Gemini CLI, Cursor, and VS Code.

SOC 2 Readiness Assessment

How to run a SOC 2 readiness assessment as a structural exercise — documentation coverage and control-to-evidence traceability before the audit.

ISO 27001 Gap Analysis

How to do an ISO 27001 gap analysis: Annex A control intent versus broken evidence chains across the governance domains.

AI Governance Readiness

How to assess AI governance readiness for autonomous agents — agent-deployment governance, model-risk controls, and a computable access boundary.

Governance Maturity Assessment

How to measure governance maturity across the enterprise — score the seven domains on a five-level maturity scale from your corpus.

Technology Due Diligence

How to do technology due diligence for an M&A deal — the governance and architecture posture a curated data room hides.

Board Governance Report

How to prepare a board-ready governance posture report — translate a structural assessment into executive risk visibility.