# Kihan

Canonical HTML: https://kihan.ai/
Last updated: 2026-09-25

> Decide what your AI agents are allowed to do, before they do it.

Kihan develops Inktomi, infrastructure for governing AI-agent actions before those actions cause effects in enterprise systems.

Kihan is the company. Inktomi is the product. Constitutional computing is the underlying architecture.

## The problem

AI agents can now do more than generate text. They can call tools, invoke services, change records, initiate transactions, modify systems, and create other external effects.

Identity and access credentials can establish who or what is calling. They do not by themselves establish that a particular proposed action is authorized under the policy, evidence, and approvals that apply to that action.

Inktomi adds an action-level governance decision before effect.

## How Inktomi works

1. An agent proposes a specific action.
2. Inktomi checks the proposal against configured customer policy and required evidence.
3. Routine actions can be permitted automatically.
4. When policy requires a person, the action waits for a human approver authenticated through the customer's identity provider using OIDC.
5. If the applicable conditions are satisfied, Inktomi issues a signed, single-use permit bound to the exact action and its details.
6. The protected customer system verifies the permit before acting.
7. A missing or invalid permit is refused through the governed interface.
8. The decision and evidence are recorded for replay and audit.

Agent proposes -> policy decides -> human intervenes when required -> destination verifies a signed permit -> action occurs -> evidence remains.

## One action, once

An approval does not create general permission for an agent to continue acting. A permit applies to one exact action, once.

Changing material details of the action requires the modified action to be adjudicated under the applicable policy rather than inheriting authority from a different action.

## Evidence after the decision

Every decision is written to a tamper-evident record. Replay re-derives each decision. Reconciliation can compare vendor audit logs with issued permits and identify activity for which no permit accounts.

Decision events can be exported to the customer's SIEM in OCSF.

## Coverage

Kihan distinguishes paths that can be stopped before execution from paths currently detected or reconciled after the fact.

Pre-execution governed paths include direct agent tools, tools called through MCP, and network calls mediated at the customer's network edge.

Files changed by any means and actions taken under the agent's own vendor accounts are currently represented as after-the-fact detection/reconciliation paths.

A deployment coverage report states which paths are governed.

## Deployment

The represented deployment model uses one node on each agent host, the customer's identity provider for approvers, and the customer's SIEM for export. Components run on the customer's hosts or at the customer's network edge.

The public architecture does not depend on a Kihan-hosted runtime component.

## Constitutional computing

Constitutional computing separates probabilistic model reasoning from the authority that determines whether a proposed action receives permission to cause an effect.

The model remains probabilistic. The governance decision is deterministic given the governed inputs, configured policy, and applicable evidence.

Read: https://kihan.ai/constitutional-computing.md

## Current public evidence status

Kihan's current public claim set does not assert customer deployments, independent testing, patent protection, or completed SOC 2, ISO/IEC 27001, FedRAMP, or other certification.

Kihan states that it is working toward ISO/IEC 27001 and SOC 2. It makes no blanket regulatory-compliance guarantee.

A founder-authored two-part feature, "Checking LLM Outputs Before They Become State," has been accepted by IEEE Computer and is forthcoming for December 2026 and January 2027.

## Evaluate

Evaluation path: https://kihan.ai/evaluate/

Complete machine-readable corpus: https://kihan.ai/llms-full.txt
