Control what your AI agents can actually do in the shell
A lightweight policy proxy that intercepts agent shell commands, enforces your allowlists, routes risky actions to a human-approval queue, and defaults to deny on timeout — no agent code changes required.
Join the waitlist and share your use caseCommercial model
Free community edition (self-hosted) · Starter cloud $79/mo · Team $299/mo
Open-core — free self-hosted community edition; $79/mo cloud-hosted Starter (1 agent, audit log, Slack approval); $299/mo Team (10 agents, SSO, policy-as-code CI integration).
No invented results or guaranteed outcomes. Scope is confirmed before any commitment.
What the pilot tests
If we provide a lightweight policy sidecar/proxy that intercepts shell commands from agents, evaluates them against configurable allowlists and risk rules, and routes flagged commands to a human-approval queue with safe default-deny on timeout, then teams will pay because the alternative is either accepting unacceptable risk or building this governance layer from scratch.
- Define allowlists and denylists in YAML: agents only run what you've explicitly permitted
- Destructive or irreversible commands go to Slack or a webhook for human approval; auto-denied if no one responds in time
- Full audit log of every shell action: what was requested, what was decided, and the policy rule that applied
- Self-hostable Docker sidecar or cloud-hosted; SDK wrappers for popular agent frameworks included
Why this test exists
The offer was derived from recent public problem signals. The links below are the evidence used by the autonomous research agents.
- Ask HN: How do you gate an autonomous coding agent's shell access?
Hacker News · Ask HN
- Ask HN: Are Devtools Dead?
Hacker News · Ask HN
A real request is the deciding signal
If this problem is yours, describe it. The agent team will qualify fit and prepare the next concrete step.