Skip to main content
    Reign OpsAI substrate

    Operate the infrastructure your AI agents depend on.

    Reign Ops operates agent runtimes, model access, tool connections and the supporting control plane as a dedicated environment. Customer policies define who and what may use them; the operating record shows what happened.

    Delivered as a single-tenant dedicated instance, in infrastructure iTmethods operates or in your own cloud account on AWS or Azure. Both are available today. Air-gapped and sovereign deployment are supported.

    The substrate four parts
    Four layers; scope agreed per engagement run Agent runtimes reach Governed model access bind MCP and tool operations underneath The control plane identity · network · secrets · logs Gateway models Each layer carries the one above it A record at every layer, in a form a reviewer can follow
    Four parts, one envelope. The agent is the part everyone looks at; the four beneath it are what Reign Ops operates as one scope.
    What Reign Ops operates

    One operating scope from agent runtime to control plane.

    Reign Ops puts the runtime, model access, tool layer and control plane into one agreed operating scope. The engagement defines which layers Reign Ops operates, how access and changes are handled, and where the operating record goes.

    Underneath all three rest on it
    What everybody demos Agent runtimes Model access MCP and tools All three rest on this The control plane Identity Network boundary Secret store Scheduler Retrieval layer Log pipeline Operated by iTmethods, on infrastructure you own Hardest of the four to add afterwards
    Nobody demos the control plane. It is the first thing a reviewer asks about, and the last thing you can retrofit.
    01The layers stack, and each one carries the one above
    Agent runtimes ride on governed model access. Model access rides on the MCP and tool layer. All three ride on the control plane.

    Which means a gap in the control plane is not a control-plane problem. It is a gap in everything standing on it.

    02We do not build the agents
    iTmethods does not host or serve foundation models at scale, and does not sell you an agent.

    What we operate is the envelope they run inside: the runtime, the routing, the tool boundary and the substrate beneath. That distinction is worth being exact about, because most of this market is selling the other thing.

    03The control plane is where reviews are decided
    Identity, network boundary, secret store, scheduler, the retrieval layer, the log pipeline.

    None of it is what anyone demos. All of it is what a reviewer asks about, and it is the layer that is hardest to add afterwards.

    04Twenty-one years of the same problem
    Operating foundational infrastructure inside somebody else's boundary, under their controls, is not a new discipline here.

    The workload is new. The operating model is the one iTmethods has run since before any of this was called AI.

    The substrate

    The layers in scope, operated together.

    Each layer can stand alone. The engagement defines which layers Reign Ops operates and how they work together around your agents.

    Reach

    Governed model access

    The gateway, policy and record layer between your agent runtime and the model providers. Version pinning, routing policy and credential rotation run as managed infrastructure. Planned capability: Reign Gateway will support policy-controlled failover across customer-approved models. The customer will define the permitted alternatives, order and constraints; Gateway will record the routing decision and outcome.

    What you get. Teams manage permitted model access in one place instead of inside each agent. Calls sent through Gateway leave an operating record for review.
    Available today How the boundary works →
    Bind

    MCP and tool operations

    The tool layer run as a governed supply chain: managed MCP servers, tool registries, third-party integrations and in-house tool servers, sandboxed at the tool-call boundary with provenance on every tool definition.

    What you get. Teams can add MCP tools without making them available to every agent. Each identity sees only the tools it has been granted.
    Available today MCP and tool operations →
    Underneath

    The control plane

    The substrate beneath the substrate: identity, network boundary, secret store, compute scheduler, the retrieval layer and the log pipeline, operated on infrastructure the customer owns.

    What you get. Operations and review teams know where agent identities, secrets, runtime health and logs are managed for the agreed environment.
    Available today Scope the control plane →

    The same architecture in every deployment shape. What changes is where it sits, and only the single-tenant dedicated instance is available today. Deployment options →

    Service scope

    The same posture at every layer.

    The point of one substrate is that these hold across all four parts rather than being negotiated at each.

    A supported place to run.

    Agent runtimes, dependencies and releases are operated through an agreed change and incident process.

    One governed route to models and tools.

    Where Reign Gateway is included, model and tool interactions routed through it carry identity, policy decisions and an operating record.

    Credentials and access with owners.

    Your identity provider is enforced at every edge. Identity, secrets, service accounts and revocation behavior are documented for the environment instead of remaining inside individual prototypes.

    A record for operations and review.

    The agreed telemetry shows runtime health and governed interactions, with destinations and retention stated for the deployment.

    Where Reign fits

    Reign Ops runs the substrate. Reign Gateway applies policy and records the model and tool interactions sent through it.

    Model and tool interactions produce separate records. Reign Gateway sits on the model path and the tool path, applying one policy to what passes through those two points.

    For each model call sent through Gateway:
    The identity that made it, the policy that applied, the decision taken, the model that answered and the time it happened.
    For each tool binding made through Gateway:
    What the agent asked to bind, what was allowed and what it did once bound.
    For the control plane:
    Identity events, key rotations, retrievals and scheduling decisions. The record is written in line rather than assembled in batch.
    The part worth being precise about. This is a record of what happened, prepared so that a reviewer can follow it. It is not a verdict, it is not an audit opinion, and it is not independent assurance of anyone's controls. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →

    Which agents and which tools are sanctioned, what each agent is allowed to reach and on whose authority, and what a policy exception means and who may grant one, are customer decisions. Your models, your prompts, your data.

    FAQ

    Do you build the agents?
    No, and we do not host or serve foundation models at scale either. What Reign Ops operates is the envelope the agents run inside: the runtime, the routing to the model providers, the tool boundary and the control plane underneath. You choose the agents.
    Can we adopt one part without the others?
    Yes, and most estates do. The layers stack, so adopting a lower one makes the ones above it easier, but each is scoped and operated on its own terms. The first conversation is usually about which layer is causing the most trouble right now.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in infrastructure iTmethods operates or in your own cloud account on AWS or Azure. Both are available today and both are single-tenant. Google Cloud is planned for 2027. Air-gapped and sovereign deployment are supported. There is no multi-tenant or shared option at any tier. Deployment options states which is which without softening any of them.
    What does it cost?
    Scoped per engagement. This site publishes no price list and no tiers, because what we would operate for you is the thing being priced and it is different every time. The scoping call is where that gets answered, and it commits you to nothing.
    FINOS Linux Foundation, Silver member Agentic AI Foundation, Silver member
    Member and contributor in the open standards behind governed AI. The Linux Foundation, FINOS, and the Agentic AI Foundation.
    Next step

    Tell us what your agents run on today.

    Which runtimes, which models, and what they are allowed to reach. We will come back with what we would operate, what stays with your team, and which layer we would start with.