Palma.ai Raises 1.8 Million Dollars To Give Enterprises A Watchdog For AI Agents

Palma.ai's Patrick Eden (CEO) and Julian Kolbe (CTO)
Image credit: Palma.ai
Palma.ai, a startup building a governance layer for enterprise AI agents, has raised 1.8 million dollars in pre seed funding to help companies control what autonomous agents are allowed to do once they are granted access to internal systems.
The round was led by D11Z, with participation from Plug and Play Ventures, Deel, and Scale Now Ventures, alongside angel investors that include executives from Cisco and Deel. Palma.ai was founded by chief executive Patrick Eden and chief technology officer Julian Kolbe to address a problem the founders see as inevitable rather than hypothetical: as companies move from AI chatbots to agents capable of independently executing tasks across internal tools, someone has to decide, and continuously enforce, which agent can touch which system, under which conditions.
Eden has framed the stakes bluntly, saying that every company is about to give AI agents the keys to its systems, and that the real question is whether anyone is watching the door. He has said Palma.ai was built so enterprises can hand agents genuine operational permissions while still knowing exactly who did what, with which tool, under which policy, across every platform the organization runs.
The product centers on the Model Context Protocol, an increasingly common standard that lets AI agents connect to a company's internal data and tools. According to Palma.ai, MCP itself only governs how a client authenticates to a server and how a given tool is described and called. It does not determine which specific employee or agent should be allowed to use which tool, does not pause a high risk action for human sign off before it executes, and does not produce the kind of tamper evident record an auditor would later ask for. Palma.ai positions itself as the layer that fills those gaps, assigning each employee a single governed connector through their identity provider, whether that is Microsoft Entra or Okta, that carries only the tools and internal skills they are specifically entitled to into whichever AI assistant they already use, be that Claude, ChatGPT, or Microsoft Copilot.
That identity based approach is designed to solve a practical lifecycle problem as much as a security one. Because access is tied directly to identity provider group membership, a new employee is automatically granted their connector on their first day, and an employee who leaves the company or changes roles loses that access the moment their group membership changes, without a security team having to manually track down and revoke permissions across a growing list of AI tools and integrations.
Beyond access control, Palma.ai's platform is built to enforce policy on the actual arguments of a given call an agent makes, not just on whether it is allowed to use a tool at all, and to pause higher risk actions for human approval before they execute. Every change to a governed configuration is captured as an immutable snapshot, meaning nothing shifts underneath an agent mid task and administrators can always roll back to an earlier state. The platform also lets a company keep certain skills private to one user, share them with named partners, or roll them out organization wide, and lets teams bundle a skill together with the specific tools it requires into what the company calls a pack, a reusable capability that can be handed to a single team or to thousands of employees without it ever landing somewhere lacking the access it assumes.
D11Z's decision to both lead the round and adopt the platform internally reflects a broader read on where the market is heading. The investor has said that while most companies building in this space are constructing MCP gateways sized for engineering teams of five or ten people, Palma.ai is designed for governance at genuine enterprise scale, which is part of why the firm chose not just to invest but to run the platform itself.
With the new capital, Palma.ai intends to expand its engineering and go to market teams as it works to bring the platform to a larger set of enterprise customers now deploying AI agents across multiple internal systems simultaneously. The raise lands amid a broader wave of AI agent security and governance startups drawing early stage capital, as companies race to give agents real operational authority faster than most existing identity and access management tooling was ever designed to track.
Topics
Stay informed
Startup news in your inbox
Get important funding rounds, founder stories, and startup updates.
No spam - only important startup updates.





