Funding
Palma Raises $1.8M to Build the Governance Layer for Enterprise AI Agents

Palma.ai has raised $1.8 million in pre-seed funding to tackle a problem that is becoming more consequential as enterprises move from AI assistants that generate content to agents capable of taking actions inside corporate systems.
The round was led by D11Z, with participation from Plug and Play Ventures, Deel, Scale Now Ventures and angel investors that include executives from Cisco and Deel. The funding will be used to expand Palma.ai’s engineering and go-to-market teams as the company targets larger organizations deploying AI agents across multiple platforms.
There is also an unusual overlap between investor and customer in the round. D11Z and Plug and Play are already deploying Palma.ai internally, using its governance infrastructure to give employees AI agents that can access enterprise tools without independently configuring permissions and integrations for every AI application.
The Governance Problem Emerging Behind AI Agents
The rapid adoption of agentic AI creates a different security problem than the one enterprises encountered with the first generation of generative AI.
Giving employees access to a chatbot primarily raised questions around data exposure, model usage and what information workers were uploading. AI agents can potentially go much further. Connected to enterprise systems, an agent might update a customer record, query a database, trigger an internal workflow, modify code or initiate another action on behalf of an employee.
That capability is increasingly being enabled through the Model Context Protocol (MCP), an open protocol for connecting AI applications with tools and data. MCP has grown into a broader industry standard and is now governed through the Linux Foundation’s Agentic AI Foundation, alongside other technologies supporting interoperable agent infrastructure.
MCP solves an important interoperability problem, but it does not by itself provide every organization-level control needed to determine what a particular employee or agent should be permitted to do.
That gap is where Palma.ai is positioning itself.
A Control Layer Between Agents and Enterprise Systems
Rather than building another AI assistant, Palma.ai is developing an intermediary governance layer through which agent-to-tool requests can be routed.
The company’s platform assigns users and agents a governed connector containing the tools and organizational “Skills” they are authorized to use. Policies are then evaluated when an agent actually attempts an action, rather than simply granting broad access to an application.
For example, an employee might be permitted to use a financial system while an agent acting for that employee is allowed to perform transactions only below a specified threshold. Another action could automatically pause until a designated human approves it.
Palma’s policy system can evaluate the arguments contained within individual requests, allowing organizations to allow, deny, rate-limit or require approval for a call before it reaches the underlying system. The company also supports an observation mode in which administrators can test policies against real traffic before enforcing them.
This approach attempts to move AI governance closer to the point where an agent actually does something.
One Governance Layer Across Multiple AI Platforms
Another part of Palma.ai’s strategy is avoiding a governance architecture tied to a single AI vendor.
The platform is designed to work across AI applications including Claude, ChatGPT, Microsoft Copilot, Gemini, Cursor and other MCP-compatible environments. Palma says the same organizational permissions and Skills can therefore follow a user even as companies change which models or agent interfaces they use.
That could become increasingly important as enterprises adopt several AI systems simultaneously rather than standardizing on one provider.
Palma integrates with existing identity infrastructure rather than replacing it. Its website describes support for identity-provider groups through systems such as Microsoft Entra and Okta, allowing access to change as employees join, leave or move between teams.
Its concept of Skills adds another layer above raw tool access. A tool might give an agent the technical ability to send an email or update a database, while a Skill defines the organization’s approved procedure for using those capabilities in a specific workflow. Palma versions and scans those Skills before they are distributed.
Keeping Credentials Away From the Agent
Security becomes particularly important when agents move beyond retrieving information and gain write access to production systems.
According to Palma’s technical documentation, its governance layer can run inside a company’s own infrastructure using Docker, Kubernetes or bare-metal deployments. VPC, on-premises and fully air-gapped configurations are supported for organizations that do not want sensitive agent traffic passing through a multi-tenant cloud service.
The platform is also designed so downstream credentials do not need to be handed directly to the agent. Palma supports approaches including token exchange and credentials stored in enterprise vaults, with authentication brokered when an approved call is made.
Every governed request can also be attributed to three parties: the user, the agent acting for that user and the application through which the request originated. Allowed, rejected, rate-limited and approval-gated actions are recorded in the audit trail.
Importantly, Palma is not claiming to replace an enterprise’s existing security infrastructure. Its own documentation notes that the platform only governs traffic routed through its connector and cannot independently discover every unmanaged MCP server running elsewhere on employee devices. Identity providers, endpoint controls, network security and existing policy systems therefore remain part of the broader security model.
Investors Become Early Customers
The involvement of D11Z and Plug and Play as both investors and customers gives this funding round another dimension.
Both venture firms are using Palma.ai as part of efforts to provide their teams with AI agents capable of operating across internal systems while maintaining centralized permissions and oversight.
“Every company is about to give AI agents the keys to its systems,” said Palma.ai CEO and co-founder Patrick Eden. “The question is whether anyone is watching the door.”
Eden previously co-founded infrastructure monitoring company Replex, which was acquired by Cisco in 2021. Palma.ai CTO and co-founder Julian Kolbe has spent more than a decade building systems for European fintech and automotive companies, including infrastructure operating in regulated environments.
The startup says it has been live since early 2026.
Agent Governance Is Becoming Infrastructure
The timing of Palma.ai’s raise reflects a wider shift in the enterprise AI market.
Companies are increasingly experimenting with agents capable of taking actions rather than simply producing answers. At the same time, the ecosystem surrounding MCP is becoming more formalized. The Linux Foundation launched the Agentic AI Foundation in late 2025, and in September 2026 introduced its first official MCP certification covering architecture, execution, security and governance.
Regulation is adding another incentive for companies to understand how AI systems operate. The EU AI Act became broadly applicable on August 2, 2026, although requirements for some high-risk systems remain subject to later implementation dates.
For enterprises, however, the immediate challenge may be more operational than regulatory: once an AI agent can change a CRM record, access sensitive data or trigger a production workflow, organizations need controls that operate at machine speed without reducing every deployment to unrestricted access or constant manual approval.
Palma.ai is betting that the solution will be a common governance layer sitting between agents and the systems they increasingly control.
Its $1.8 million pre-seed round gives the company additional capital to test whether that layer can become a standard part of the enterprise AI stack as agents move from experiments into day-to-day operations.












