How do I govern API requests from AI agents in a financial services environment?

Route API requests through Kastra. The Kastra proxy or SDK intercepts each API call before it executes, evaluates ABAC policy against the request attributes, environment, principal identity, and risk signals, and returns an allow, deny, redact, or human-approval decision. Financial services customers map controls directly to SOC 2, PCI DSS, SOX, FINRA, MiFID II.