Guardrail products block bad text. Gate enforces what your institution actually cares about: who may do what, within which limits, under whose approval — at the same gateway that already sees everything.
autonomy tiers from Observe to Act-Autonomously
kill-switch propagation across every enforcement point
MCP permissions: read / write / deny
attached to every human approval
Agents get API keys, not permissions. One over-scoped credential is a breach waiting for a prompt.
35% of enterprises admit they couldn’t shut down a rogue agent. "Find the engineer who deployed it" is not a kill switch.
Material AI actions approved in Slack threads and inboxes — unsearchable, unauditable, unenforceable.
Role-scoped access to models, tools, and data — including per-tool read/write/deny on MCP connections, with end-user identity forwarded through every hop of delegation.
Act-with-Approval agents route material actions to the right human — by role, amount, or action type — with full context attached and every intervention filed as evidence.
Token and dollar budgets, action-rate limits, and session caps per agent — with instant suspension that propagates across every enforcement point at once.
Enforcement points deploy as plugins for the gateways you have — LiteLLM, Portkey, Kong, Azure APIM — plus SDK hooks for LangGraph, CrewAI, AutoGen, and MCP. No rip-and-replace, no mandatory proxy in your critical path.
Every agent gets an identity with role-scoped access to knowledge, tools, and data — including per-tool read/write/deny granularity on MCP connections, with end-user identity forwarded through every hop of agent-to-agent delegation.
Action limits, approval thresholds, and topic boundaries derive from your centrally defined policies — not scattered per-tool settings. When the policy changes, the control changes.
Prompt injection and jailbreak detection — including multi-turn attack patterns — poisoned tool results, PII and secrets masking, with allow / block / transform / alert enforcement modes. Findings stream to your SIEM as OCSF.
Act-with-Approval agents route material actions to the right human — by role, by amount, by policy provision — with full context attached. Interventions are recorded as evidence automatically.
Token and dollar budgets per agent, team, and tool with automatic cutoff; action-rate limits; session caps; instant suspension that propagates across every enforcement point at once.
Observation and policy-aware flagging run today on the Clarity tier. Inline enforcement — permissions, queues, caps, kill switch — ships with the Control tier in 2027.
Checks run at the gateway in the same sub-100ms budget as Secure. Approval waits are policy choices, not performance costs.
The agent’s identity is suspended at every enforcement point, in-flight actions inside reversal windows are rolled back, and the whole event is filed as evidence.
Enforcement arrives on the same gateway — no migration later.
Start free