Platform
Platform Overview Observe Mode Enforce Mode Orchestrate Mode
Company
About Partners Contact
Resources
White Papers & Docs Blog ROI Calculator Pricing
▶ Try Live Demo Book a Session →
▶ Try Live Demo Book a Demo →
Songlines Control®
Songlines Control® · Production Ready

One pane of glass for
all your AI systems

From invisible cloud line-item to fully attributed AI spend in under 10 minutes. Purpose-built for Australian enterprise and government — with a clear upgrade path to full sovereign infrastructure.

Start Your 14-Day Control Baseline → Explore the Modules
40%
Average cost savings via intelligent routing
10 min
Time to first live AI workload from zero
0ms
Budget alert latency — fires on every ingest event
100%
Australian data residency — by architecture
The Songlines Journey

A clear upgrade path to full sovereign AI infrastructure

Songlines Control® is your entry point — immediate visibility and governance with zero infrastructure changes. From there, expand to full inline enforcement and ultimately a complete sovereign stack.

Step 1 — Start Here
Songlines Control®
Observe Mode
Immediate visibility and governance. Answers the board-level question about AI spend and compliance, delivered in hours.
  • ✓ Real-time cost attribution
  • ✓ Intelligent model routing
  • ✓ Immutable audit trail
  • ✓ Zero infrastructure changes
Step 2 — Expand
Enforce Mode
Enforce Mode
Inline enforcement and control. A mandatory transit point for all AI traffic — policy enforced before the request reaches any model.
  • ✓ Inline policy enforcement
  • ✓ PII auto-redaction
  • ✓ Prompt injection prevention
  • ✓ HITL approval workflows
Step 3 — Full Sovereign
Orchestrate Mode
Orchestrate Mode
The complete sovereign stack. audit evidence packages and air-gapped deployment for the most stringent government and defence requirements.
  • ✓ Air-gapped deployment
  • ✓ audit evidence packages
  • ✓ On-premises or private cloud
  • ✓ Full data sovereignty
Platform Modules

Ten Purpose-Built Modules. One Governance Platform.

Each module addresses a distinct dimension of enterprise AI control. Deploy individually or together — every module shares a single runtime layer, audit trail, and policy engine.

Observe

Economic Control

Real-time MTD spend, token consumption, cost savings rate, and model-level attribution across all vendors.

Observe

Workflow Economics

Step-level cost and latency breakdown per workflow run — so every AI initiative has a clear financial owner.

Enforce

Model Routing Engine

Intelligent routing rules: cost-optimise, latency-optimise, or enforce preferred models by policy — automatically.

Enforce

Policy Engine

Configurable guardrails: block models, cap spend, enforce data residency, and restrict access by role or workflow.

Observe

Observability

Latency percentiles, error rates, throughput, and anomaly detection with per-model and per-workflow drill-down.

All Modes

Audit & Compliance

Immutable, timestamped log of every AI request — full-text searchable and exportable for Privacy Act, APS AI Policy, and ISO 42001 review.

Orchestrate

Simulation Engine

Model what your costs and performance would look like under different routing strategies — before committing to a change.

All Modes

User Management

Role-based access control with per-user AI spend attribution — full visibility of who is consuming what, and at what cost.

Enforce

Budget Alerts

Configurable threshold rules with webhook and email delivery — guardrails that fire before you overspend, not after the invoice arrives.

Observe

Shadow AI Governance New

Automated discovery of 30+ known AI vendors, risk scoring 0–100, employee self-service declaration portal, and AI Risk Policy Builder — with Privacy Act and APS AI Policy 2024 alignment.

Observe

Sustainability & AASB S2 New

Token-level CO₂e measurement, AASB S2 one-click disclosure PDF, director liability assessment, supplier emissions ledger, and executive board pack — board-ready from day one.

Enforce

Runtime Guardrail Engine New

Real-time policy enforcement in under 5ms — PII redaction, model restrictions, token limits, topic blocklist, cost caps, and a guardrail sandbox for testing policies before deployment.

Enforce

Agent Identity & Access Management New

Register, authenticate, and govern every AI agent with least-privilege access controls. Credential vaulting with automatic rotation, time-bound sessions, agent-to-agent trust policies, and continuous risk scoring.


Economic Control Layer

From invisible cloud line-item to fully attributed AI spend — in under 10 minutes

The Economic Overview dashboard gives you a live view of every dollar your organisation spends on AI — broken down by model, workflow, team, and user. 19-model pricing tables are built in across OpenAI, Anthropic, Azure, AWS Bedrock, and Google. Cost is calculated automatically from token counts on every ingest — no manual tagging required.

  • Real-time MTD spend with month-on-month trend comparison
  • Token consumption tracking across all models simultaneously
  • Cost savings rate via intelligent routing vs unoptimised baseline
  • Average cost per request with 6,700+ request tracking
  • CSV export for reconciliation with cloud billing and finance reporting
Songlines Control® — Economic Overview Dashboard
Economic Overview · Real-time AI cost tracking and budget management
Workflow Economics

Step-level cost breakdown — so every AI initiative has a clear financial owner

Workflow Economics drills below the top-line spend number to show you exactly which steps in each workflow are consuming cost and latency. Select any workflow from the dropdown and see a per-step cost and latency breakdown — instantly identifying where optimisation will have the greatest impact.

  • Per-step cost and latency breakdown for any workflow
  • Total cost, token count, latency, and step count per run
  • Cost per Step and Latency per Step charts side by side
  • Step-by-step breakdown with model, cost, latency, and token detail
  • Identify the most expensive steps for targeted optimisation
Songlines Control® — Workflow Economics
Workflow Economics · Step-level cost and latency breakdown per workflow run
Model Routing Engine

Intelligent routing delivers 40%+ cost reduction — automatically

Not every AI task requires GPT-4o or Claude 3.5 Sonnet. Without a routing layer, every call defaults to the most expensive model available. Songlines Control® fixes that at the API layer — with zero changes to your application code. Route by cost, latency, policy, or data residency requirements.

  • Sovereign Data Routing — PII and sensitive data to sovereign-compliant models only
  • Cost Optimisation — simple tasks routed to cheaper models automatically
  • High-Stakes Analysis — legal and financial workflows routed to premium models
  • Fallback rules — route to cheapest available model when budget threshold is reached
  • Live routing decisions feed with model, latency, and policy enforcement status
Songlines Control® — Model Routing Engine
Model Routing Engine · Dynamic model selection rules and live routing decisions
Observability

Complete visibility across every AI request — latency, errors, and throughput in real time

The Observability module gives you the same depth of telemetry for AI that you expect from your application performance monitoring stack. Latency percentiles, error rates, success rates, and token throughput — all live, all attributed to the model and workflow that generated them.

  • Live request traces with workflow, model, tokens, latency, cost, and policy status
  • Latency percentile charts (p50, p95, p99) over 24 hours
  • Error rate tracking with policy decision visibility (allowed / modified / blocked)
  • Success rate and average latency KPIs updated in real time
  • Per-model and per-workflow drill-down for root cause analysis
Songlines Control® — Observability
Observability · Real-time request traces, latency percentiles, and error monitoring
Audit & Compliance

An immutable audit trail built for Australian regulatory requirements

Every AI request is logged with a cryptographically signed, immutable record — including the model used, tokens consumed, cost, latency, routing decision, and policy outcome. The log is ISO 27001 aligned and audit-ready, meeting Australian government and enterprise compliance requirements out of the box.

  • Immutable, timestamped log — records cannot be modified or deleted
  • Full-text search across all audit fields — model, user, workflow, cost range
  • Date range filtering for regulatory submissions and legal discovery
  • One-click CSV export ready for Privacy Act, APS AI Policy, and ISO 42001 review
  • Aligned with Privacy Act 1988, APS AI Policy, and ISO/IEC 42001
Songlines Control® — Audit and Compliance
Audit & Compliance · Immutable audit trail for every AI interaction
Simulation Engine

Model what-if scenarios before committing to a routing change

The Simulation Engine lets you project the cost and performance impact of routing strategy changes before applying them to production. Compare current spend against projected spend under different scenarios — with risk ratings, latency impact, and quality impact calculated automatically from your actual usage patterns.

  • What-if scenario cards with current vs projected cost comparison
  • Risk ratings (Low / Medium / High) for each proposed routing change
  • Latency impact and quality impact projections per scenario
  • 6-month cost forecast across three routing strategies on a single chart
  • Apply Scenario button — changes only go live with explicit administrator approval
Songlines Control® — Simulation Engine
Simulation Engine · What-if scenarios and 6-month cost forecasting
User Management

Role-based access control with per-user AI spend attribution

User Management gives administrators complete visibility of who is consuming AI resources and at what cost. Assign admin or user roles, monitor per-user request counts, token consumption, and total spend — all from a single screen. Suspend accounts instantly when access needs to be revoked.

  • Per-user AI request count, tokens used, and total spend in real time
  • Admin and user role assignment with server-side enforcement
  • Account suspension with immediate access revocation
  • CSV export for finance reporting and cost allocation by team
  • Last sign-in tracking for access review and compliance audits
Songlines Control® — User Management
User Management · Roles, access, and AI spending attribution per user
Budget Alerts

Guardrails that fire before you overspend — not after the invoice arrives

Configure alert rules scoped to model, workflow, team, or organisation-wide with custom dollar thresholds. Deliver alerts via HMAC-signed webhooks to PagerDuty, Slack, or Teams — or via email to your finance team. Cooldown windows prevent alert fatigue once a threshold is crossed.

  • Configurable rules with monthly, daily, or hourly rolling windows
  • Multi-channel delivery — webhook (HMAC-signed) and email
  • Cooldown enforcement to prevent duplicate alerts during active incidents
  • Full delivery log with HTTP status, response body, and timing
  • 0ms alert latency on breach — fires on every telemetry ingest event
Songlines Control® — Budget Alerts
Budget Alerts · Configurable thresholds and real-time breach notifications
Governance Settings

Sovereign Mode, PII Auto-Redaction, and HITL Approval — all in one place

The Settings screen puts your most critical governance controls at your fingertips. Enable Sovereign Mode to enforce all AI traffic to sovereign-compliant endpoints only. Activate PII Auto-Redaction to automatically detect and redact personally identifiable information before it reaches any model. Require human approval for high-risk AI operations with HITL Approval Workflows.

  • Sovereign Mode — enforce all AI traffic to sovereign-compliant endpoints only
  • HITL Approval Workflows — human approval required for high-risk AI operations
  • PII Auto-Redaction — automatically detect and redact PII before sending to models
  • Prompt Injection Prevention — block prompt injection attempts in real time
  • Budget Threshold Alerts and notification preferences per user
Songlines Control® — Governance Settings
Governance Settings · Sovereign Mode, PII Auto-Redaction, and HITL controls
Agent Identity & Access Management New

The identity layer for your AI agent fleet

Organisations are deploying dozens of AI agents — copilots, orchestrators, autonomous research agents, third-party integrations — but have no centralised way to know how many agents are active, define what each can access, or enforce least-privilege. Agent IAM provides the identity, authentication, and authorisation layer for every AI agent operating within your enterprise.

  • Agent Identity Registry — register and lifecycle-manage every AI agent with type classification and deployment metadata
  • Permission Boundaries — define exactly which tools, data, and APIs each agent can access
  • Credential Vaulting — automatic rotation schedules, instant revocation, and full audit trail
  • Session Control — time-bound sessions with automatic privilege de-escalation on expiry
  • Agent-to-Agent Trust — prevent unauthorised delegation chains between agents
  • Risk Scoring & Attestation — continuous risk evaluation based on permissions scope and action history
Songlines Control® — Agent Identity & Access Management Dashboard
Agent IAM · Register, authenticate, and govern every AI agent

Guardrails

Six layers of enforcement — before, during, and after every AI call

Songlines Control® does not just observe your AI usage — it enforces policy at the proxy layer in real time. Every request passes through a configurable guardrail stack before it reaches a model, and every response is validated before it reaches your application.

Financial Guardrails

Set hard spend caps at the organisation, team, workflow, or user level. When a threshold is breached, requests are blocked or routed to a cheaper model automatically — no manual intervention required. Configurable rolling windows (hourly, daily, monthly) prevent runaway costs from a single agent loop or batch job.

  • Hard spend caps with automatic request blocking on breach
  • Soft threshold alerts via webhook and email before breach
  • Per-model, per-workflow, and per-user budget scoping
  • Hourly, daily, and monthly rolling windows

Data Sovereignty Guardrails

Sovereign Mode enforces that all AI traffic is routed exclusively to sovereign-compliant endpoints — Australian-hosted infrastructure only. Any request that would leave the approved data residency boundary is blocked at the proxy before it is sent. This is enforced architecturally, not by policy document.

  • Sovereign Mode — block all non-sovereign endpoints at the proxy
  • Per-workflow data residency rules (e.g., HR data stays onshore)
  • Audit log records residency compliance status on every request
  • Air-gap deployment option for classified or sensitive environments

Privacy & PII Guardrails

PII Auto-Redaction scans every outbound prompt for personally identifiable information — names, email addresses, phone numbers, Medicare numbers, TFNs, and more — and redacts it before the request is sent to any model. Redaction happens at the proxy layer, so your application code never needs to change.

  • Automatic detection and redaction of 20+ PII entity types
  • Redaction applied before data leaves your environment
  • Redaction events logged in the immutable audit trail
  • Configurable sensitivity levels per workflow or data classification

Model Access Guardrails

Define exactly which AI models each team, workflow, or user is permitted to call. Block access to unapproved models entirely, or restrict to a pre-approved allowlist. Prevent shadow AI usage — where teams call models directly, bypassing governance — by routing all AI traffic through the Songlines Control® proxy.

  • Per-team and per-workflow model allowlists and blocklists
  • Block unapproved model calls before they reach the provider
  • Prevent shadow AI by centralising all AI traffic through the proxy
  • Model version pinning to prevent silent capability changes

Prompt Integrity Guardrails

Prompt Injection Prevention detects and blocks attempts to override system instructions, extract sensitive data, or manipulate model behaviour through adversarial inputs. This is especially critical for customer-facing AI applications and agentic workflows where user input is passed directly into prompts.

  • Real-time prompt injection detection on every inbound request
  • Configurable sensitivity — warn, redact, or block on detection
  • Injection attempts logged with full prompt context for review
  • Protects agentic workflows from adversarial user inputs

Human-in-the-Loop Guardrails

HITL Approval Workflows require a designated human approver to review and authorise high-risk AI operations before they are executed. Define which workflows, models, or request types require approval, set escalation paths, and maintain a full approval audit trail — ensuring human oversight is embedded in your AI governance framework, not bolted on afterwards.

  • Configurable approval gates per workflow, model, or risk classification
  • Approval requests routed via email, Slack, or webhook
  • Full approval audit trail — who approved, when, and why
  • Timeout and escalation rules for time-sensitive operations
🛡️

Guardrails enforced at the proxy — not in your application code

Every guardrail in Songlines Control® operates at the API proxy layer. This means enforcement is consistent regardless of which team, tool, or application is making the AI call. There is no way to bypass a guardrail by changing application code — the policy is applied before the request ever reaches a model provider.


Integration

Instrument your first AI workload in under 10 minutes

No changes to your existing AI code. Add a single POST request after each AI response and your spend, tokens, latency, and model breakdown appear live on the dashboard within seconds.

1. Create an API Key

Log in to Songlines Control®, navigate to API Keys, and generate a key scoped to your application or team. Takes 30 seconds.

2. Wrap Your AI Call

Add a single POST to /api/ingest after each AI response. The SDK snippet handles model, tokens, latency, cost, and workflow attribution automatically.

3. Watch the Dashboard

Within seconds, your AI spend, token consumption, model breakdown, and request volume appear live on the Economic Overview dashboard.

# Add after every AI call — no changes to your existing AI code import requests, time # Your existing AI call (unchanged) start = time.time() response = openai.chat.completions.create(model="gpt-4o", messages=messages) elapsed_ms = int((time.time() - start) * 1000) # Instrument with Songlines Control® — add this single block requests.post("https://your-instance/api/ingest", headers={"Authorization": "Bearer sk-your-key"}, json={ "model": "gpt-4o", "input_tokens": response.usage.prompt_tokens, "output_tokens": response.usage.completion_tokens, "latency_ms": elapsed_ms, "workflow_id": "customer-support" })

TypeScript & Python SDK snippets available in the API Keys Quick Start guide. Works alongside any existing AI stack — OpenAI, Anthropic, Azure, AWS, Google.


Deployment

Flexible deployment — from SaaS to air-gapped on-premises

Deploy Songlines Control® in the model that matches your organisation's security classification, data residency requirements, and procurement constraints.

Option 01 · SaaS

Manus Cloud

Hosted on the Manus platform in Australian data centres. Fully managed infrastructure — no servers to provision, no updates to apply.

Setup time: Under 10 minutes
Best for: Fastest time to value · SME to mid-market
Data residency: Australian DC
Option 02 · Private Cloud

Your Tenancy

Deployed in your own AWS, Azure, or GCP tenancy in the ap-southeast-2 (Sydney) region. Full data isolation within your existing cloud investment.

Setup time: 1–3 days
Best for: Enterprise with existing cloud investment
Data residency: ap-southeast-2
Option 03 · Air-Gapped

On-Premises

Deployed in your own data centre. Supports fully air-gapped operation with no external network dependencies — meeting the most stringent security classifications.

Setup time: 1–2 weeks
Best for: Government · Defence · Highly regulated industries
Air-gap support: Full

Regulatory Alignment

Purpose-built for Australian regulatory requirements

Songlines Control® is designed from day one for the frameworks that matter to Australian enterprise and government — not bolted on after the fact.

Privacy Act 1988

Australian Privacy Principles compliance with PII auto-redaction, data residency enforcement, and full audit trail for every AI interaction involving personal information.

APS AI Policy

Meets Australian Public Service requirements for AI transparency, accountability, and human oversight — including HITL approval workflows for high-risk AI operations.

ISO/IEC 42001

Supports AI Management System certification with documented controls, risk records, and audit evidence exportable in a single click.

Essential Eight

ACSC mitigation strategies supported through application control, patch management visibility, and privileged access management via RBAC.

ISM Controls

Information Security Manual alignment with zero-trust architecture, SHA-256 hashed API keys, HMAC-signed payloads, and immutable audit logging.

Data Sovereignty

All telemetry data is processed and stored in Australian data centres. No data leaves Australian jurisdiction — by architecture, not just policy.

AASB S2 & Climate Disclosure

Mandatory climate-related financial disclosures for large Australian entities from FY2025. Songlines Control® automates Scope 3 Category 1 AI emissions measurement and generates a ready-to-lodge AASB S2 disclosure PDF from live telemetry.

APS AI Policy 2024

Australian Public Service agencies must maintain an inventory of AI tools in use. The Shadow AI Governance module provides automated discovery, risk scoring, and a sanctioned AI catalogue — meeting this requirement out of the box.

Privacy Act 1988 APS AI Policy 2024 AASB S2 ISO/IEC 42001 Essential Eight ISM Controls ISO 27001 Aligned Corporations Act 2001 Audit-Ready 100% Australian Data Residency
Sustainable AI

AI Governance and Emissions Reduction Are the Same Mechanism.

Under the GHG Protocol, every AI query your organisation sends to a third-party model is a Scope 3 Category 1 emission. Songlines Control® makes it measurable, reportable, and reducible — with AASB S2 mandatory disclosure beginning in FY2026.

Observe Mode
Scope 3 Baseline in 14 Days

Every AI interaction logged, attributed by team and model, and mapped to a CO₂e estimate. Auditor-ready data for AASB S2 mandatory disclosure — without changing a single workflow.

Enforce Mode
30–60% Emissions Reduction

Intelligent model routing directs each query to the most efficient model capable of handling it. The result is a 30–60% reduction in both token spend and AI-related Scope 3 emissions — simultaneously.

Orchestrate Mode
Zero Emissions on Cached Queries

Semantic caching serves repeated queries without sending any request to an external model. Cached queries generate zero inference emissions and zero cost.

Explore Sustainable AI → Download White Paper

"Your AI systems are already running. The question is whether you're in control of them."

See Songlines Control® live in your environment

2-week proof of concept, zero risk. We deploy, instrument your workloads, and deliver an executive readout — all within 10 business days.

Live Demo

See Songlines Control® in action

Explore the live platform — real dashboards, model routing, policy engine, and audit logs. No sign-up required.

▶ Try Live Demo →