Palma.ai raises $1.8M to govern AI agents across enterprise tools

Patrick Eden and Julian Kolbe are building a shared permissions and audit layer for agents using different AI assistants.

By · Published

Primary source: Tech.eu

Why it matters

Palma.ai is betting that enterprises will buy one control point for agent actions across multiple assistants. Its gateway covers connected tools, leaving deployment and unmanaged connections central to that bet.

Two professionals in a modern office stand near an abstract digital display showing interconnected systems.

Patrick Eden and Julian Kolbe have announced a $1.8 million pre-seed round for Palma.ai, their San Francisco-based software company that aims to control what AI agents can do inside an enterprise. Tech.eu reported the financing on September 23rd. D11Z led, with participation from Plug and Play Ventures, Deel, Scale Now Ventures and angels, including executives from Cisco and Deel. Cisco was not named as an investor.

Eden has built infrastructure software for large companies before. He co-founded Replex, a Kubernetes-monitoring business that Cisco acquired in November 2021. Palma.ai describes Kolbe, its CTO and co-founder, as a developer of secure systems for European fintech and automotive companies. Their wager is that connecting an agent to a business system is becoming easier than deciding which actions to let it take.

"Every company is about to give AI agents the keys to its systems," Eden told Tech.eu. Palma.ai is trying to put a checkpoint at the door: a common place to assign access, inspect requests, require approvals and record actions, even when employees use different assistants. That is a narrower and more testable proposition than promising to make agents safe in general.

A policy for the action, not just the user

The Model Context Protocol, or MCP, gives AI clients a standard way to connect to tools exposed by other software. A company might expose a CRM update or a financial-reporting function through an MCP server. Once several assistants and teams use those connections, administrators need to decide who can invoke a tool, with what arguments, and who must approve a consequential request. Palma.ai says its gateway sits between the clients and approved servers, applying those decisions at the time of a tool call.

The distinction matters in practice. An employee's access to a CRM does not necessarily mean an agent should be able to change every deal. Palma.ai says administrators can make a rule depend on the fields or amounts in a request, rather than only on the employee's identity. The gateway can allow the call, deny it or hold it for a named human approver. Palma.ai says it then attributes the action to the person, agent and client in a tamper-evident audit record. These are product claims, rather than independently demonstrated measures of how reliably the controls work in a customer deployment.

Palma.ai's approach is built around one governed connector for each person's approved tools and reusable "Skills," its term for playbooks that tell an agent how to carry out a workflow. Access follows groups in identity systems such as Entra and Okta, according to Palma.ai. Palma.ai says the same policies can follow a user across clients including Claude, ChatGPT, Copilot and Cursor; it also offers deployment in a customer's cloud environment, on premises or air-gapped. The business case is straightforward: IT can approve a workflow once rather than rebuild its controls for every assistant an employee tries.

There is a boundary to that design. Palma.ai says its gateway discovers tools on servers connected to it, but does not find unmanaged MCP servers on an employee's laptop. A central checkpoint can govern the traffic routed through it; finding connections that bypass it is a different job. That limit makes deployment across an organization as important as the rules configured inside the product.

The money and the proof Palma.ai needs

The financing announcement gives Palma.ai capital to expand its engineering and go-to-market teams, according to Tech.eu. An earlier Form D filed on June 5th provides a useful timestamp on its fundraising: Palma.ai reported $1,345,666 sold toward a $2 million equity offering, with the first sale dated April 29th. That filing is a snapshot from June, not a September closing statement. It does not establish how its offering total relates to the subsequently announced $1.8 million round.

D11Z appears on Palma.ai's website as both an investor and a customer. That gives the round a named example of an organization using the product, although an investor-customer testimonial cannot by itself establish performance across other enterprises. The financing report supplies no valuation or customer-scale figure; Palma.ai's website illustrates a dashboard with tool-call and token totals, but does not identify those figures as company-wide traction.

Other vendors are working on the same control point. Willow said in June that it raised $7 million to build an enterprise agent-access platform and claimed roughly 5,000 weekly active users at Wix. Noma Security describes agent and MCP-server discovery alongside access controls. Nightfall AI announced an early-access MCP gateway this month with inline enforcement and server visibility. Those offerings differ in scope, and their published descriptions do not establish a performance ranking. They do show that Palma.ai will have to win on how well its controls work across the assistants and systems a customer actually uses.

Eden's Replex experience helps explain the choice of market. Replex addressed the operational complexity that followed widespread Kubernetes adoption; Palma.ai is applying a similar infrastructure thesis to agents connected through an open protocol. Its immediate test is less abstract: persuade an enterprise to route meaningful agent actions through Palma.ai, then show that the approvals and audit records hold up when those agents do real work.

Reader comments

Conversation for this story loads after sign-in.