Employees can activate an agent and delegate their identity. Agents working autonomously can also use their own identity without a human delegating permissions.
Introducing Rippling AI Governance: Get your AI house in order

In this article
Today, we're introducing Rippling AI Governance, a suite of products that helps companies scale AI usage without losing track of spend, access, or accountability. It connects AI activity to the workforce context already in Rippling, so companies can move from reacting to AI sprawl after it happens to governing AI at the moment it's used.
Built on Rippling's employee graph, AI Governance gives IT leaders one place to understand AI usage and spend, control access to models and tools, and manage agents throughout their lifecycle, with policies that map to each employee's team and role.
AI adoption has outrun AI governance
Companies are under pressure to scale AI, but the systems to govern it haven't kept up. Leaders face three problems:
They can't see or control AI usage and spend. Data is scattered across vendor consoles, invoices, API logs, spreadsheets, and unmanaged accounts. Finance sees the spend after the fact, while IT has to explain what changed without a reliable view of the people, teams, models, and workflows driving it.
They can't reliably secure what employees and agents can access or do. Model access, tool permissions, and data security policies live across separate systems. Controls are often manual, vendor-specific, or applied only after access has spread.
They can't reliably identify and manage agents. Agents often run through shared keys, generic service accounts, or repurposed employee credentials. That makes it difficult to determine who is responsible, what an agent can access, what it has done, and what should happen when its owner changes roles or leaves.
That leaves companies with two bad options: move quickly and accept rising costs and security risks, or lock AI down and miss out on productivity gains.
Govern AI usage, spend, access, and agents from one platform
For leaders tasked with efficiently scaling AI across their organization, Rippling AI Governance is a set of software tools that allows companies to measure and control AI usage. This is a suite of products that, taken together, give admins a comprehensive set of controls for managing the use of AI within their organization. Rippling routes employees' LLM traffic, governs tool access, surfaces unsanctioned AI usage, and manages agent identity, all through the organizational context that makes policies enforceable. Our promise is to help companies scale AI adoption without losing control of spend, access, or auditability.

What we're launching
MCP Gateway
AI agents become useful when they can act on information, not simply answer questions. An AI agent decides how to complete a task. Model Context Protocol, or MCP, connects it to the tools, data, and systems it needs to do so. An MCP Gateway controls which of those connections and actions are allowed.
As employees connect AI tools to more business systems, every unmanaged connection creates another path to sensitive data that IT can't reliably see, control, or audit. IT may not know what is connected, who is using it, or what actions they can take once connected.
Rippling MCP Gateway gives IT a controlled entry point for supported MCP connections. The model is familiar: IAM governs which SaaS apps employees can access. MCP Gateway governs which company systems employees and agents can reach through AI, and what they can do once connected. Before a tool call runs, Rippling checks who is making the request and whether the relevant policy allows it. The call is then recorded for review.
That control goes deeper than deciding whether a connection can exist. An engineer may have broad access to GitHub, but an AI agent working on their behalf shouldn't automatically receive the same permissions. The agent might be allowed to read approved repositories and open pull requests, while being blocked from deleting branches, changing repository settings, modifying secrets, force-pushing code, or accessing security-sensitive repositories outside the engineer's team. MCP Gateway governs what an agent can do through a connection, not simply whether it can connect.
Because Rippling already knows each employee's role, team, and employment status, access updates automatically when employees join, change roles or teams, or leave the company. A standalone gateway has to import and maintain that context from external identity systems. Rippling starts with it.
With Rippling MCP Gateway, companies can connect AI to more of the business without losing control of who can access each system or what they can do within it.

Rippling MCP Gateway applies the same identity based access controls companies already use for SaaS apps to MCP connections. Permissions update automatically when employees join, change roles, or leave.
AI Gateway*
AI spend is becoming one of the hardest software costs for companies to manage. Employees and agents can call OpenAI, Anthropic, Google, and other providers directly, often across multiple tools and subscriptions. Finance sees the bill after the fact. IT sees only part of the access picture. And leaders struggle to answer the basic questions: who is using which models, which teams are driving spend, and where should usage be limited or optimized?
Rippling AI Gateway gives companies one governed path for LLM traffic. It sits between employees, apps, agents, and model providers, so admins can control access to models, set budgets, enforce spend limits, and log usage with the employee and organization context already in Rippling.
That matters because AI governance is not just about saying yes or no to AI. It is making sure the right people have the right level of access, at the right cost. A security engineering team may need frontier models for complex work, while other teams can be steered toward faster, lower-cost models for everyday tasks. With AI Gateway, companies can route the right traffic to lower-cost models, set hard budget caps, and block usage when limits are reached.
The result is governance and spend management in the same system. Companies get visibility into model usage and cost by user, team, department, provider, and model, auditability for every request, and controls that apply at the moment AI is used, not weeks later when the invoice arrives.

Rippling AI Gateway enforces model access and budgets as requests happen, while recording usage and spend for auditability.
Agent Identity Management
Agents are becoming a new class of worker. They can hold credentials, access apps, call tools, and take action across the business. But without a clear identity and owner, an agent can quickly become a security and audit risk: no one knows exactly what it can access, what it has done, or how to revoke it.
With Rippling Agent Identity Management, companies can create and manage agent records alongside employees and service accounts. Admins can assign owners, set permissions, and provision agents into third-party apps using the same access controls they already use in Rippling.
That means every agent can be known, owned, permissioned, auditable, and revocable from one system. Agent Identity Management gives companies the foundation to put agents to work safely, without letting them become invisible, shared, or unmanaged accounts.

An agent can act through permissions delegated by an employee or through its own managed identity. In either case, admins can see who owns it, what it can access, how much it spends, and what it does.
Shadow AI Detection*
Shadow IT has always been a problem for IT teams. Employees find a tool that helps them move faster, start using it before it has been reviewed, and suddenly the company has software with no clear owner, policy, or audit trail. Shadow AI raises the stakes. An unapproved AI tool may not just store data; it may read files, connect to apps, process sensitive information, call tools, or keep running as an agent.
Rippling Shadow AI Detection helps companies find AI usage they did not provision. It gives admins visibility into unapproved AI apps, third-party OAuth connections, browser extensions, coding assistants, local agents, and MCP servers, then connects that activity back to the employee, device, app, and organization context in Rippling.
From there, admins can decide what should happen next. They can approve a tool, restrict it, notify employees to move to an approved alternative, revoke risky access, or bring usage into a managed path through Rippling AI Gateway or MCP Gateway. The goal is not to slow AI adoption down. It is to make the approved path easier, safer, and more visible than the unmanaged one.
This completes the AI governance story. MCP Gateway governs how AI connects to business tools. AI Gateway governs model usage and spend. Agent Identity Management makes non-human actors known and accountable. Shadow AI Detection finds the activity happening outside those approved paths, so companies can scale AI without losing sight of what is actually being used.

Each ingestion flow lands in raw records before normalisation and review.
Get started today
AI adoption isn't slowing down. The companies that scale it well won't be the ones that move fastest or impose blanket restrictions. They'll be the ones that build governance into the same infrastructure that already runs their business. That's what Rippling AI Governance is: visibility and control over AI, built on the employee graph that already powers everything else.
MCP Gateway and Agent Identity Management are live today. See them in action.
*Join the waitlist for AI Gateway and Shadow AI Detection.
Disclaimer
Rippling and its affiliates do not provide tax, accounting, or legal advice. This material has been prepared for informational purposes only, and is not intended to provide or be relied on for tax, accounting, or legal advice. You should consult your own tax, accounting, and legal advisors before engaging in any related activities or transactions.
Author
Niki Sri-Kumar
VP Product, IT
Explore more

From unchecked AI spend to complete control: How Rippling built AI Spend Console
AI Spend Console gives CFOs and CTOs a clear view of AI spend, connects it to business outcomes, and governs the use of approved LLMs.

Introducing Rippling Procurement: Buy what your team needs 5x faster without overpaying
Rippling Procurement helps businesses buy what they need up to 5x faster while maximizing savings and minimizing risk on every purchase.

Agentic AI security: Complete guide to threats, risks & best practices 2025
Comprehensive guide to agentic AI security threats, risks, and best practices. Learn how to secure autonomous AI agents and implement robust governance frameworks.

Inside the Making of Rippling AI
As AI adoption accelerates across HR, organisations face growing pressure to balance efficiency with privacy, compliance and accountability. This behind-the-scenes look at Rippling AI explores how it was built to operate within strict governance frameworks, leverage real-time workforce data and deliver trusted insights for HR, payroll and compliance teams—without compromising security or human oversight.

AI for IT Operations: Why Most Tools Fall Short (And What Changes When They Don't)
Most AI for IT operations tools fail because they're built on fragmented environments. Learn what changes when AI has full context across identity, devices, access, and employee data.
Introducing Rippling Bill Pay
Discover how Rippling Bill Pay lets you consolidate, automate, and control your business spend from one platform. Simplify your bill payment process today.

How Rippling learned to work differently
Discover how Rippling’s Head of AI created a “treat it as your intern” policy that increased adoption for organization-level wins.

SaaD is stopping companies in their tracks. We’re putting an end to it.
Rippling unifies HR, IT, Spend, and more on one platform with a shared source of truth: your employee data. Change something once — a new hire, a promotion, a termination — and it updates everywhere.
See Rippling in action
Increase savings, automate busy work, and make better decisions by managing HR, IT, and Finance in one place.