Decision Execution Governance vs. adjacent controls
| Control | What it does well | What it does not stop in time | How dexgate fits |
|---|---|---|---|
| Permissions | Define what the user or service principal can reach. | An agent can still use those permissions for the wrong action at the wrong time. | On supported surfaces, dexgate evaluates covered proposed actions before execution. |
| Sandboxing | Limits process and environment reach. | It does not decide whether a sensitive allowed action should proceed. | dexgate returns allow, deny, or require-review inside the allowed boundary. |
| Agent settings / permission modes | Shape behavior and safer defaults; some hosts (e.g. Grok Build) can set ask/auto/always-approve fleet-wide via remote config. | They do not provide independent action approval, Passports, or shared governed evidence—always-approve can increase unreviewed tool use. | dexgate free hard-gates high-consequence tools; paid Dexgate policy runtime decides, issues Passports, and records even if the host would auto-approve. |
| Monitoring | Gives visibility and forensics after behavior happens. | It is often too late once the risky action has already run. | dexgate prevents or constrains the action first, then leaves a reviewable record. |
| Policy engines | Express and evaluate policy logic. | Still need agent-path integration, enforcement at the action boundary, and a surrounding evidence model. | On supported surfaces, dexgate integrates policy evaluation into the agent execution path with enforcement and reviewable evidence. |
Concrete example: a deployment promotion command may be technically allowed, sandbox-compatible, fully configured, and fully monitored. Decision Execution Governance still decides whether that exact promotion should run now. Agent Execution Governance applies that same model to AI-agent actions.
Trust note
Compatibility labels, evidence packs, and validation statements on this site describe first-party dexgate testing for the specific declared runtime rows and release scope shown. They are not third-party approvals and do not replace your own review, deployment controls, or legal guidance.