New One-call approvals are live in the console
For platform teams

Configure governance once. Not once per vendor.

You own the connectors, the identities and the blast radius. Govna gives you one connection address that every client — Claude, ChatGPT, Cursor, custom agents, CLI tools, desktop apps — reaches under the same approval screen.

01 Substance

The four things that actually decide this

Not features — the questions the decision turns on.

One integration surface

Apps, logins, permission sets and rules are set up once and apply to every client. No per-vendor integration to build or maintain.

Change is reviewable

An app update lands as something to review: new tools hidden, changed tools paused, removed tools stopped, until you approve.

Policy where you need it

Checks run before a call and after it. Deny, require approval, or trim the request — never expand it.

Rollout without exceptions

Permission sets let teams help themselves inside limits you set, instead of asking you for a permanent exception.

02 Chain of command

One call, end to end

The same seven stages apply no matter which client made the request.

Someone asks
Permission set
Login
Tool
Rules
Outcome
Receipt
01 Someone asksA person asks an agent to do something, starting from a permission set.
Next step

Where to go next

Two readers, two different next steps.

Build path

One connection address, one exact consent.

Everyone else

Start with the words: permission set, session, approved tool list, receipt.