Pentra Omni | AI gateway

AI gets access.
Not the keys.

Omni is the gateway between your analysts and AI agents and the security tools and models they use. Each person and each agent reaches only what they are allowed, vendor and model credentials stay inside Omni, and every call is recorded.

What Omni governs

Two ways out. One policy.

AI clients and agents reach your security tools and your models through the same gateway, under the same identities, roles and audit trail.

Tool access

  • One endpointAI clients and agents connect to one authenticated endpoint that fronts your security vendors' tool servers.
  • Per-tool rightsEach person sees only the tools they are allowed. Anything else is left out of their tool list and refused if called.
  • Kill switchDisabling a vendor connection stops its tool calls at once, with no restart.

Model access

  • Model catalogCallers choose from named models in Omni's catalog. They never pick a destination or see a provider key.
  • No retentionA model can be called only after an administrator approves it as meeting your no-retention terms.
  • BudgetsToken and cost allowances are reserved before each call, so parallel requests cannot overspend them.

Investigation sessions

Access for one investigation. Not forever.

An agent working a case gets a short-lived session grant instead of a standing key: the exact tools it may call, for one investigation, for a limited time.

01 | Scope

Exact tools, one case

A grant names the investigation, the exact tools, an expiry and an optional call budget. Asking for one tool beyond the requester's own rights refuses the whole grant.

02 | Approve

A second person by default

A grant waits for an independent person's approval unless an administrator has marked every one of its tools for automatic approval. Whoever asked for it cannot approve it.

03 | Contain

Containment is never automatic

Containment actions, such as isolating an endpoint, cannot be marked for automatic approval. They always wait for that second person.

04 | Revoke

Narrower, never wider

An agent can pass part of its grant to another agent, but only a smaller set that ends no later. Revoking a grant ends every grant made from it.

Controls and evidence

Built for the people who answer for it.

Security and compliance teams decide who holds which rights, and can show afterwards exactly what happened.

Audit trail

Append-only, and the call waits for it

Every tool and model call is recorded with the person or agent, the grant, the investigation and the decision. The database refuses edits and deletes, and if a record cannot be written, the call does not go ahead.

What is recorded

Metadata by default

In hosted Omni, each model call is recorded by its tokens and cost, without the prompt or the reply. If you self-host, you can also keep the full messages for audit in your own environment. Either way, credentials are redacted and every permission change is recorded.

Roles and review

Least privilege you can check

Roles and groups grant console rights and tool access, and a deny always wins. No one can grant a right they do not hold, and an access view shows what each person can do and where it came from.

Sign-in

Your single sign-on

People sign in through single sign-on. With Google Workspace, a Workspace group decides a person's role in Omni, so access follows the groups you already manage.

Monitoring

Rules that watch usage

Rate rules block a caller who goes over a limit, and alert rules flag unusual activity, with email notifications to the people who need to know.

Release integrity

Signed, scanned images

Omni ships as signed container images, each with a software bill of materials. Nothing is published unless every image passes its vulnerability scan.

Works with

The clients, models and tools you already use.

  • AI clientsClaude Code, Claude Desktop and Codex, configured by Omni's setup tool, plus your own agents on the same endpoint.
  • ModelsOpenAI-compatible endpoints, Anthropic, Amazon Bedrock and Gemini on Google Vertex AI. Bedrock and Vertex AI are reached with your cloud identity, so no long-lived key is stored in Omni.
  • Security toolsRapid7, and SentinelOne for endpoint isolation. Any vendor tool server you add sits behind the same controls.
  • DeploymentSingle-tenant: each customer gets its own Omni, with its own database, encryption key and tool connections. Enterprise deployments are designed to run in your own cloud account.
  • Pentra GraphPentra Graph gathers evidence from your tools through your Omni, so the investigation engine never holds a vendor key.

Talk to us

Put your AI behind one gateway.

Tell us which AI clients, agents and models your team uses, and which security tools they need to reach. We will walk through how Omni would govern them.

Go to contact form