Manifesto

The airbag for agents that can move money and data.

Autonomous AI is already in your stack — refunds, wires, deploys, database writes. Policy decks do not stop tool calls. We are here to ask, at enforcement time: what is this agent allowed to do, and who can prove it?

Five demands

  1. Demand 1

    Check before execution

    Every high-impact tool call passes a policy gate before it reaches your ledger, core API, or production database — not after, not in a quarterly review.

  2. Demand 2

    Name the rule

    Every allow, block, or escalate cites a rule name — not vibes. Risk and engineering read the same decision object.

  3. Demand 3

    Fail closed

    When policy is unclear, the default is block or escalate — not silent allow. Unmatched rules are not a green light.

  4. Demand 4

    Audit by default

    Every decision writes to an audit trail at runtime — not reconstructed from chat logs after something breaks.

  5. Demand 5

    Milliseconds, not meetings

    Governance runs at enforcement time — fast enough to be invisible, strong enough to matter. Not another slide deck.

You would not put someone in a car without an airbag. Do not deploy agents that move money and data without one.

Open to anyone whose agent has root access and no airbag.