How it works
The guard
Runs in your process. When one agent hands work to another, the sub-agent gets only the permissions its task needs — a subset of its parent’s, never more. Hard limits, expiry, default deny on unknown tools. No proxy, and no network call in the deny path.
The engine
Computes the permission set from your declared roster and tool list — never from prompt text. You see and edit every permission before anything is enforced. Payments, mail, deletes and code execution are never granted automatically — only by a named person.
The console
See every run as a delegation graph, decide what stays held, and verify the audit log — offline, with our software absent.
observe (records only, blocks nothing) → shadow (evaluates, still blocks nothing) → enforce. One flag back.
Works with LangGraph, OpenAI Agents SDK, Google ADK, CrewAI, AutoGen, Claude Agent SDK, Pydantic AI, smolagents, AWS Strands, LlamaIndex, Semantic Kernel and Agno — integrated unmodified.
What’s proven — and what isn’t
- Twelve agent frameworks integrated without modifying them; three enforced live on real applications. Enforcement is structural — the same result on Haiku and on Sonnet.
- Zero benign denials across 21 evaluation scenarios on our own sample apps, after a one-time setup pass. About 30% of tools needed a human decision. Measured in our own onboarding runs — your operator’s number is the real one.
- Raw arguments, prompts and records never leave your process. The local audit log holds names, scope classes, quantity buckets and salted hashes; an export fails rather than ship a field it doesn’t recognise.
- No paying customers yet — you would be the first design partner. Instead of references, we hand your auditor an evidence pack they verify themselves.
- No SOC 2. Internal security review done; external review before anything runs in production. The audit log is tamper-evident, not tamper-proof — and we will tell you exactly who holds the signing key.
The 20 minutes
A screen-share on a nine-agent run: watch a sub-agent try a call outside its permissions and get denied with a readable reason; grant a held payment yourself and watch the same call pass; then export the audit log and verify it in a clean shell — with our software absent. Bring nothing.
If it looks like your problem, the next step is one week on one of your own apps — one operator on your side, observe first, one flag back — after we have looked at your handoffs together.