News · September 9, 2026

Introducing Orcher: The Control Plane for Enterprise Superintelligence

Seven components, two layers, one verified execution cycle — built so autonomy can run at machine speed without the enterprise losing the ability to prove, on demand, what happened and under whose authority.

By Odero OtienoFounder, CEO & CTO, Dipp AI Technologies, Inc.

Orcher is the agentic control plane Dipp AI Technologies built to make Enterprise Superintelligence governable by construction: provider-neutral, role-bound, and evidence-producing by design. It is available today to eligible enterprise customers.

Today we are introducing Orcher, the agentic control plane Dipp AI Technologies built to make Enterprise Superintelligence governable by construction. Orcher is the infrastructure that lets enterprises deploy AI they can actually trust with real work: verifiable, cost-disciplined, and in control of their own data. It is provider-neutral, role-bound, and evidence-producing by design — it sits between a professional's actual authority and whichever models execute on it, so autonomy can run at machine speed without the enterprise losing the ability to prove, on demand, what happened and under whose authority.

Enterprises can trust what a model says, but very few can prove what an agent actually did once it has already happened. Reviewing an agent's output after the fact, the industry's current default, fails even when a human is demonstrably present and demonstrably watching. Orcher is our answer to both findings, and it is available today to eligible enterprise customers.

What we built

Orcher is seven components operating as one system across two layers. Layer 1 is accountability: sequential gates that decide whether a proposed action may commit at all, and halt by default if any one of them fails. Layer 2 is control: continuous mechanisms that govern data, cost, and visibility for the entire life of a directive, without blocking execution. Nothing about this architecture requires replacing the agents, models, or orchestration frameworks an enterprise already runs. Orcher sits in front of them and decides, per directive, whether the work may proceed — then writes down exactly what it decided.

Select a component to reveal its Vol. I excerpt.

Layer 1 — sequential gatesLayer 2 — continuous controls01Directive InterfaceIntent captured02Role Identity FabricAuthority bound03Logic ScrubberAction verified04Immutable Audit LedgerEvidence hashed05Data Control GatewayData boundary + no-training06Cost GovernanceCeilings on autonomy07ObservabilityCross-provider traceOrcher™ · Dipp AI Technologies

Fig. CP-01 · The seven-component control plane

Fig. 1 — Two layers, seven jobs. Layer 1 gates whether an action may commit at all, sequentially, halting by default. Layer 2 runs continuously alongside execution, governing data, cost, and visibility for as long as the directive is live. Select a component to read its Vol. I excerpt.

The one architectural choice that makes this work

Every gate in Layer 1 defaults to halt, not proceed. If the Directive Interface, Role Identity Fabric, Logic Scrubber, or Immutable Audit Ledger cannot complete its check, nothing partial gets written and the action does not go through. The intuitive alternative — letting an action proceed and flagging it for review afterward — is the architecture the rest of the industry still defaults to, and the one our own research shows fails predictably under real volume and real time pressure. A system that defaults to proceeding is asking a person to catch what it missed. A system that defaults to halting never has to ask.

Why we built it now

FIG. A01-01

Adoption has outrun accountability

Select a measure

78%

Run AI agents in production

Agents are acting on live systems of record, not sandboxes. Adoption is effectively universal across the enterprise estate.

Fig. 2 — The conditions that made this the moment to build: adoption climbing, incidents climbing with it, named ownership and traceability flat.

The rest of the industry has spent 2026 independently arriving at the same diagnosis Orcher was already built to solve. On 26 August 2026, Okta made Agent SSO generally available, and its own announcement conceded the exact boundary Orcher exists to close: "Identity provides a control point, but it cannot determine whether every action an authorized agent attempts is safe or appropriate." Enterprises, the announcement continues, still need separate controls for data classification, prompt injection, model behavior, tool permissions, and human approval of sensitive actions — the six other jobs Orcher's seven components already perform as one system.

Okta is not alone. Six major identity vendors — Okta, Microsoft Entra, Ping Identity, SailPoint, BeyondTrust, and Snowflake — launched AI agent identity products within roughly two quarters of each other in 2026. An independent analysis of the wave found every one addresses the same layer, authentication and authorization, and none address what governed data context an authenticated agent actually receives once it starts acting. Only 18% of security professionals report being highly confident their current identity tooling can handle agents at all.

When teams try to stretch identity governance into a runtime control product, they usually end up with delayed governance wrapped around already-executed actions.

Independent review of agentic identity platforms, 2026

Independent architecture research is validating the shape of the answer, not just the shape of the problem. Futurum's Agent Control Plane Framework defines a principle nearly identical to Orcher's two-layer split, arrived at separately: agents decide, control planes govern, execution environments enforce, and systems generate evidence. Verizon's attempt to build a unified agent platform for 23,000 engineers ran into exactly the problem Orcher prevents: context does not transfer across runtimes. Orcher does not have that problem, because directives, roles, policy, and evidence live in Orcher itself, not inside any one runtime.

84%

cannot pass a compliance audit focused on agent behavior or access controls

43%

of breached organizations traced the incident to shadow AI

up from 20% a year earlier

$492M

projected 2026 enterprise spending on AI governance

Gartner

18%

are highly confident existing identity tooling can handle agents

How a directive moves through Orcher

FIG. A03-01

The Verified Execution Cycle

Tap a stage

1234567VECone billable unit

Directive

A named professional states intent. Nothing runs anonymously.

Fig. 3 — The Verified Execution Cycle: one directive, one bound role, gates in sequence, one committed action, and a permanent record the enterprise keeps. Tap a stage to read what it enforces.
  1. Directive received — plain-language intent arrives with the issuer's identity attached. Anonymous directives are refused at the door.
  2. Role resolved and bound — the Role Identity Fabric resolves current entitlements and binds them cryptographically to this cycle. Anything outside the role halts here, before a token is spent.
  3. Proposed action verified — the Logic Scrubber checks the plan against systems of record: eligibility, policy, licensure, limits, before anything is written.
  4. Data boundary applied — the Data Control Gateway redacts, routes, and enforces the enterprise data boundary for every payload leaving the estate.
  5. Execution and metering — Cost Governance selects a model tier within the ceiling in force for that role; Observability streams the run across whichever providers are involved.
  6. Commit and hash — the result and the full decision trace are written to the Immutable Audit Ledger and retained as Dipp Intelligence.

Why Cost Governance halts, rather than reports

Cost Governance

Routing by stakes, enforced — not recommended

Pick a stakes class

Small / open class

1× relative cost · permitted

Classification, extraction, summarisation, routine drafting.

Mid class

halted by ceiling

Multi-step reasoning where an error is recoverable and reviewable.

Frontier class

halted by ceiling

Irreversible, high-stakes, or externally binding work only.

A directive with no external effect and a recoverable error path is capped at the small class. The frontier is not an option the router can pick.

Fig. 4 — The spread the ceiling governs. Pick a stakes class to see which tiers a directive is permitted to reach and which are halted outright.

The clearest illustration of what happens without a halt-by-default cost control is Uber's 2026 rollout. After giving roughly 5,000 engineers access to an AI coding agent in December 2025, usage nearly doubled by February 2026, and by March 84% of developers were classified as agentic coding users. By April — four months in — the company had burned through its entire 2026 AI budget. A separate enterprise reportedly spent $500 million in a single month after deploying AI access with no usage caps at all. Neither failure required a security breach.

A July 2026 survey of 107 enterprise respondents found 21% track agent spend only through post-hoc logs, with no real-time mechanism to halt a runaway execution loop, and another 30% depend entirely on whatever spending cap their model provider happens to ship. A single runaway agent can consume $50 to $500 in API costs before anyone notices, and that figure multiplies with every concurrent user hitting the same failure pattern.

Cost Governance is built around the same halt-by-default principle as Layer 1, applied continuously. It classifies a directive by its actual stakes before routing it, selects the cheapest model class those stakes permit, and halts a loop mid-execution the moment its behavior stops converging — rather than waiting for a monthly invoice to surface the damage.

The category is forming around the same conclusion

In August 2026, Nuggets launched what it calls an Authority Control Plane, built on the position that agents need verifiable, cryptographically bound authority rather than borrowed human credentials — the same conclusion that produced Orcher's Role Identity Fabric. A 2026 survey of 1,900 IT leaders found the market moving the same direction organizationally: enterprises are consolidating agentic AI strategy under a single centralized governance owner rather than letting each business unit run its own stack, precisely because per-unit governance cannot produce one defensible answer when a regulator asks who authorized an action.

We take the convergence as confirmation rather than competition. What distinguishes Orcher is not that it governs agents; increasingly, everything will. It is that all seven jobs — directive, role, verification, evidence, data boundary, cost, and visibility — run as one system with a shared halt semantic, so there is no seam between them where an action can commit while one check is still pending.

Provider-neutral, not provider-agnostic in name only

Data Control Gateway

The boundary is a decision the system makes on every call

Select a stage

The payload is classified before anything leaves the tenant. Regulated fields, identifiers, and privileged material are tagged at the field level, not at the document level.

Fig. 5 — Provider neutrality is enforced at the boundary: classification, redaction before egress, region pinning, training exclusion verified per call, refuse-by-default routing.

We decoupled orchestration from any single model provider deliberately. Directives, roles, policy, and evidence live in Orcher; models are interchangeable execution capacity beneath it. That is what makes routing by stakes possible, what makes the Data Control Gateway able to refuse a route that cannot satisfy an enterprise's boundary and select the next sufficient class automatically, and what keeps a single cross-provider trace intact in Observability when a directive touches three vendors in one cycle.

Everything Orcher records compounds. Each verified cycle adds to Dipp Intelligence, the permanently owned asset an enterprise is left holding — the record of what its own professionals authorized, on what basis, at what cost, and to what effect.

Sources

Sources for every figure in this article.

Where a number comes from Dipp AI's own analysis or an observed deployment, it is labelled as such and is not presented as an independently audited third-party finding.

  1. Okta, Agent SSO general availability announcement, August 26, 2026.
  2. Independent 2026 analysis of agentic identity launches across Okta, Microsoft Entra, Ping Identity, SailPoint, BeyondTrust, and Snowflake.
  3. Futurum Group, Agent Control Plane Framework, 2026.
  4. Verizon unified agent platform case reporting, 2026.
  5. Gartner, projected 2026 enterprise AI governance spending.
  6. IBM Cost of a Data Breach 2026 reporting on shadow AI.
  7. Uber AI coding agent rollout and 2026 AI budget reporting.
  8. July 2026 enterprise survey of 107 respondents on agent spend controls.
  9. Nuggets Authority Control Plane launch, August 2026.
  10. 2026 survey of 1,900 IT leaders on agentic AI strategy and governance centralization.
  11. The Enterprise Superintelligence Report, Vol. I, Dipp AI Technologies, August 2026.

Case studies

Organisations that ran this argument in production.

Modelled reference scenarios with the measurement window, the components enforced and the numbers attached. Each one downloads as a PDF.

Written by Odero Otieno.

Writes the Dipp AI record on enforced governance for agentic systems — authority, enterprise data boundary, cost and compute. Every figure in this piece carries a source, and corrections are published on the record rather than made quietly.