VirtualHatch, Inc. today announces the availability of OmniHatch, an AI Agent Execution & Control Infrastructure that governs the path an AI agent takes when it uses tools, runs code and acts on business systems and external services.
It is offered for production use inside companies and organisations, and for OEM and embedded use by AI model developers and AI platform providers, for systems integration by SIers, and for technical integration with existing agent platforms.
Generative AI has moved quickly from systems that produce text to agents that choose tools, run code, manipulate data and carry work across several systems at once.
The more genuinely an AI acts, the less it is enough to know what the model decided. What has to be governed, independently, is who may do what — with which authority, against which system — on the basis of that decision.
Rather than relying on the model to observe the rules, OmniHatch provides a structure in which only permitted actions reach external systems, and only along a controlled path.
Governing the action that executes, not the AI's judgement
AI governance has so far tended to manage what sits around the model: filtering inputs and outputs, keeping audit logs, publishing usage guidelines.
But when an agent acts directly on APIs, databases, SaaS, MCP, code sandboxes and internal systems, getting a correct answer from the model and being able to authorise that action as an organisation are two different things.
OmniHatch places an independent control boundary on the path an agent takes to act on the outside world.
Before anything runs, it decides — permit, deny, or request approval — on the basis of who is acting, which tool or system is being targeted, what the operation is, what authority is available and which policies apply.
Operations that need human approval stop before execution. Operations without authority never reach the outside world.
Safety therefore does not rest on the choice or capability of the model alone: the actions an AI actually takes are governed by the system.
Separating arbitrary code execution from outward effects
Increasingly, the code and skills a model generates act on networks, data, credentials and business systems.
Rather than granting an AI or its sandbox broad external authority, OmniHatch separates the environment in which arbitrary code runs from the external systems themselves, and funnels every outward effect through a controlled path.
Code runs in an isolated environment, and reaches networks, persistent data, credentials and external tools only by way of explicitly permitted routes.
Where the conditions required for control cannot be confirmed — the isolation boundary, or the verification of authority — the design stops the execution or the outward effect rather than falling back to direct access.
Risks such as escaping the sandbox, or generated code reaching somewhere it was never meant to, are therefore contained by several control boundaries rather than by a single judgement from a model.
Being able to run code and being able to change an external system are held apart. An AI's compute and the authority it may exercise over its environment are managed separately. That is the basic design of OmniHatch.
The aim is not to hold AI back, but to make the authority a highly capable AI can actually exercise something explicit and controllable.
Tracing not just the result, but how the action came about
Running AI in production means being able to explain more than what finally executed: which inputs, decisions, delegations, tool calls and approvals led to it.
OmniHatch records model calls, delegation between agents, tool execution, approvals and outward effects together with what preceded and followed each one, making the sequence of execution traceable.
That gives the evidence needed for incident investigation, internal audit, explaining an event to a customer, and reviewing how AI is being used.
The point is not that logs exist, but that the path by which an AI arrived at an action can be reconstructed.
Change management, for an era when the AI itself keeps changing
An agent system is not static: agents, skills, the models in use, tools and policies all keep changing.
So OmniHatch governs more than the AI's actions. Changes to the running configuration are governed too.
A proposed change is kept distinct from what is running, and only what has been through evaluation, approval and deployment becomes the next live configuration. An AI generating an improvement and an AI freely rewriting production are thereby separated.
Agents can become more autonomous while change management and lines of responsibility hold.
An action control layer that does not depend on any one model
OmniHatch is not a guardrail closed around a particular LLM or a single agent.
Where several models, agents, tools, code sandboxes and external systems coexist, the actions that arise between them are treated as one common object of control.
It is designed to be vendor-neutral: the layer of execution, authority, approval and audit is maintained independently, even as the models and agents in use change.
It is intended not only for organisations that use AI, but for those that provide it — model developers, agent vendors and AI platforms embedding execution control into their own products.
For VirtualHatch, OmniHatch is not an AI audit dashboard. It is the execution and control layer for the moment an AI acts on real work and on the outside world.
Built for production
VirtualHatch has been developing OmniHatch as a system that treats autonomous execution and governance as one thing.
In its current form, that idea is implemented as an AI Agent Execution & Control Infrastructure covering execution control, authority management, approval, control of outward effects, audit and change management.
It is now available for production use in companies and organisations, for OEM and embedded use by AI model developers and platform providers, for systems integration by SIers, and for technical integration with agent platforms.
It does not assume that existing models or agents will be replaced. What it offers is an independent control layer on the path those systems take when they move to real action.
As AI shifts from answering to executing, this gives organisations a way to govern — in the system itself — the authority and the actions an increasingly capable AI can exercise.
Who it is for
OmniHatch is aimed at organisations taking agents beyond a PoC and connecting them to real work and external systems, and at companies developing and providing AI models and platforms.
In finance and insurance: controlling where confidential data may go and which models may be used, keeping evidence of AI-driven operations, and investigating incidents.
In manufacturing: managing the authority of agents that handle design data and source code, and controlling what may be sent outside.
In public services and critical infrastructure: accountability for AI-driven actions, change management, approval, and continuous audit.
In healthcare, pharmaceuticals and other fields handling sensitive information: clear lines of responsibility, and records, for data use and AI execution.
For AI model developers and platform providers: embedding execution control, per-customer authority management, approval, control of outward effects and audit as a shared control layer — both while developing their own models and agents, and when delivering them into customer environments.
In short, environments where what has to be managed is not only how capable the AI is, but what it may do, with what authority, and how far.
Deployment, OEM and technical partnerships
We welcome enquiries about deploying OmniHatch, about deployment and systems integration by SIers, about OEM and embedded use by AI model developers and platform providers, and about technical integration with agent platforms.
The approach is not to replace an existing AI environment wholesale, but to place an execution and control layer between the models, agents and tools in use and the business systems they act on.
For deployment, OEM and embedding, joint development or technical partnership, please get in touch below.
OmniHatch https://vhatch.co.jp/en/services/omnihatch/
Contact https://vhatch.co.jp/en/contact/
About OmniHatch
OmniHatch is an AI Agent Execution & Control Infrastructure that governs what an AI agent does — execution, authority, approval, outward effects, audit and change management.
Rather than granting an AI broad authority directly, it passes only permitted actions along a controlled execution path, separating the AI's intelligence from its authority over systems.
It also separates arbitrary code execution from effects on external systems, so that even where several agents, tools, sandboxes and external systems are involved, the actions actually exercised are governed independently.
It is available for production use by companies and organisations, and for OEM and embedded use by AI model developers and AI platform providers.

