Grounded answers about the platform — no hype.
Hi, I'm Dewey — laibrary's website assistant. Ask me anything about laibrary. I answer only from what our team has published, and I point you to a human for anything I can't cover.
Try asking
AI-generated — don't enter confidential information. Privacy
laibrary exists for the gap between how fast organizations adopted AI agents and how slowly they gained any way to say what those agents are doing, who owns them, and whether it is allowed — in their industry, in the places they and their customers operate.
An AI agent is not a model. It is a piece of software with credentials, a budget, access to your data, and the ability to act without a person in the loop. Organizations acquired hundreds of them in a couple of years — through platform features, vendor add-ons, and individuals who simply started using something useful.
The governing apparatus did not keep up. Ask most organizations which agents they run, who owns each one, what data it can reach, what it cost last month, and whether it satisfies the regime they are about to be audited against, and the honest answer is assembled by hand, over weeks, and is out of date on delivery. Meanwhile the regimes multiplied: three comprehensive AI statutes in force, a treaty, a dozen material US state laws, sector rules for banks, insurers and hospitals, and the standards that sit under all of them.
A single governed record for every AI agent an organization runs — any agent, on any framework: registered with an owner and a risk tier, checked against policy before it acts, tracked for cost and behaviour while it runs, and evidenced against the frameworks that apply to it — which depend on its industry, on where it and its customers are, and on how far along it is. Not on which plan it bought. Hosted in the region you choose, isolated to the row.
The same record answers the operator's question, the auditor's question and the board's three: what agents do we have, are they compliant, are they performing. That is the whole design — one substrate, rendered differently for the person asking.
Reporting on an incident is not governance. The check has to happen before the action, which means sitting in the call path rather than reading logs after the fact.
Evidence gathered specially for an audit is expensive and, quietly, unreliable. If day-to-day operation produces a tamper-evident record, the audit is a query rather than a project.
Controls people route around are worse than no controls, because they also produce false assurance. Warn, block, or pause for approval — chosen per rule, by the people accountable for it.
There are hundreds of AI frameworks and roughly a dozen underlying obligations: an inventory, a risk classification, logging, human oversight, documentation, incident reporting. Nobody needs a new proprietary standard. The job is mapping what you run onto NIST AI RMF, ISO/IEC 42001, the EU AI Act, OWASP, SOC 2 — and whatever your regulator, your state or your sector adds next.
A bank in Frankfurt, an insurer selling into Colorado and a college in Ohio owe different things to different regulators. They should not get a generic product with a bigger price tag for the difference. Every tenant is shaped to its industry, its jurisdictions and its stage; the plan only decides how much of the estate is governed and how far the evidence goes.
laibrary is family-founded.
A library catalogues, classifies, and makes findable. The ai in the middle is the thing being catalogued — every AI thing your company runs, on the shelf, in its right place, with a card in the catalog.
That is the whole idea, and the name carries it. We started from the observation that organizations had adopted AI agents far faster than they had gained any way to account for them, and that the missing piece was not another dashboard but a record: one place where every agent, and everything it touches, is written down and kept current.