XSI-AIMS for the Microsoft Agent Framework
Extended Systems Inc. · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
Multi-agent deployment has outpaced governance. Teams ship Microsoft Agent Framework agents into production faster than they can answer the questions that matter once those agents act: who approved this, what did it do, and can you prove it afterward?
XSI-AIMS for the Microsoft Agent Framework is the governance runtime for MAF agents — XSI-AIMS conformance brought to your Microsoft-stack agents as a runtime overlay. No application code changes for the core capabilities.
Show the rest of the publisher’s description (15 more lines)
What it does
XSI-AIMS is a substrate-agnostic supervisory-agent governance specification. This product is its conformant implementation on Microsoft Agent Framework. It adds three things to your MAF deployment:
- Supervisory archetypes — Orchestrator, Sustainer, Articulator, Executor, and the rest of the AIMS archetype set, mapped onto your existing MAF agents.
- The Witness Layer — a tamper-evident record of what every agent planned, decided, and did. Accountability you produce on demand, not reconstruct.
- Sovereign-deployment posture — governance that runs where your data lives: on-premises, sovereign cloud, or air-gapped, with no cloud round-trips.Who it's for
Teams running agents where "the agent did it" is not an answer an auditor accepts — telecom, public sector, finance, healthcare. If you build on Microsoft Agent Framework and need to show supervision and provenance, this is the conformance layer.
How AIMS governs
Three functional modes — Generative, Constraining, Integrative. Agents are supervised across four operational layers (intent, plan, form, execution), and a six-pattern safety substrate watches the failure modes that surface once agents coordinate. Behavior that is observed, constrained where it must be, and reconciled into one accountable record.
Availability
This is the Phase 1 listing. Onboarding is concierge — reach out and we bring your MAF deployment into XSI-AIMS conformance directly, with early-access pricing. Transactable tiers follow.
What it does not do yet
V1 is the governance runtime, not a validator — conformance testing is XSI-AIMS Advisor, our separate product. Runtimes for other agent frameworks are on the roadmap, not in this release.
Part of XSI-AIMS
XSI-AIMS is an open governance standard with commercial instruments from XSI. Read the standard at https://xtendedsystems.com/aims/ · on GitHub at https://github.com/Extended-Systems-Intelligence/aims · sibling instruments XSI-AIMS Atlas (memory routing, https://xtendedsystems.com/aims/atlas/) and XSI-AIMS Compass (model routing, https://xtendedsystems.com/aims/compass/).
Talk to us before your next agent goes to production. Contact me to start.
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Sources
Publisher resources
2 linksLinked repositories
1 repoUnknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






