Palma.ai has raised a $1.8 million pre-seed round to build a permissions and audit gateway that controls what AI agents do across enterprise tools. The bet: companies will pay for one central checkpoint that governs agent actions, regardless of which AI assistant an employee uses. The round was reported by Tech.eu on September 23rd. D11Z led the investment, with participation from Plug and Play Ventures, Deel, Scale Now Ventures and individual angels, including executives from Cisco and Deel.
Co-founders Patrick Eden and Julian Kolbe are addressing a problem that emerges when companies connect AI agents to business systems. Eden previously co-founded Replex, a Kubernetes-monitoring company that Cisco acquired in 2021. Kolbe, the CTO, built secure systems for European fintech and automotive firms. Their thesis: connecting an agent to a system is now easier than deciding which actions to let it take.
"Every company is about to give AI agents the keys to its systems," Eden told Tech.eu. Palma.ai positions its gateway as the door checkpoint - a place to assign access, inspect requests, require approvals and record actions across different assistants.
A policy for the action, not just the user
The Model Context Protocol, or MCP, gives AI clients a standard way to connect to tools exposed by other software. A company might expose a CRM update or a financial-reporting function through an MCP server. Once multiple assistants and teams use those connections, administrators need to decide who can invoke a tool, with what arguments, and who must approve a consequential request. Palma.ai says its gateway sits between the clients and approved servers, applying those decisions at the time of a tool call.
An employee's access to a CRM does not necessarily mean an agent should change every deal. Palma.ai says administrators can make a rule depend on the fields or amounts in a request, rather than only on the employee's identity. The gateway can allow the call, deny it or hold it for a named human approver. The company says it then attributes the action to the person, agent and client in a tamper-evident audit record. These are product claims, not independently demonstrated measures of how reliably the controls work in a customer deployment.
One governed connector, across multiple assistants
Palma.ai's approach centers on one governed connector for each person's approved tools and reusable "Skills," its term for playbooks that tell an agent how to carry out a workflow. Access follows groups in identity systems such as Entra and Okta. The same policies can follow a user across clients including Claude, ChatGPT, Copilot and Cursor. IT can approve a workflow once rather than rebuild its controls for every assistant an employee tries.
There is a boundary to that design. Palma.ai says its gateway discovers tools on servers connected to it, but does not find unmanaged MCP servers on an employee's laptop. A central checkpoint can govern the traffic routed through it. Finding connections that bypass it is a different job. That limit makes deployment across an organization as important as the rules configured inside the product.
Funding and competitive pressure
The financing gives Palma.ai capital to expand its engineering and go-to-market teams. An earlier Form D filed on June 5th provides a timestamp: Palma.ai reported $1,345,666 sold toward a $2 million equity offering, with the first sale dated April 29th. That filing is a snapshot from June, not a September closing statement. D11Z appears on Palma.ai's website as both an investor and a customer - a named example of an organization using the product, though an investor-customer testimonial cannot by itself establish performance across other enterprises.
Other vendors are working on the same control point. Willow said in June that it raised $7 million to build an enterprise agent-access platform and claimed roughly 5,000 weekly active users at Wix. Noma Security describes agent and MCP-server discovery alongside access controls. Nightfall AI announced an early-access MCP gateway this month with inline enforcement and server visibility. Those offerings differ in scope, and their published descriptions do not establish a performance ranking. They do show that Palma.ai will have to win on how well its controls work across the assistants and systems a customer actually uses.
Eden's Replex experience helps explain the choice of market. Replex addressed the operational complexity that followed widespread Kubernetes adoption. Palma.ai applies a similar infrastructure thesis to agents connected through an open protocol. Its immediate test: persuade an enterprise to route meaningful agent actions through Palma.ai, then show that the approvals and audit records hold up when those agents do real work.
Why this matters for IT, legal and operations teams
For IT leaders mapping out AI agent governance, Palma.ai represents a specific architectural choice: a gateway that enforces policy at the point of a tool call, with attribute-level rules and approval workflows that span multiple assistants. The product's limit - it does not discover unmanaged MCP servers - means deployment coverage directly determines control coverage. Legal and compliance teams should watch whether the tamper-evident audit trail holds up under discovery or regulatory review, not just in a dashboard screenshot. Operations teams evaluating the product will need to test whether the approval routing adds latency that breaks real-time workflows. The $1.8 million round is seed-stage money. The proof points that matter - paying customers at scale, independent security assessments, uptime under production load - are still ahead.
Your membership also unlocks: