Your agents never sleep. Control them so you can.
Your agents act through model and tool calls. ACP records every one, learns the rules from the calls you approve, and controls what runs — across every agent and framework your team uses. Free up to five agents.
Prefer fully on-device? Add --local — no account, nothing leaves your machine. what each mode writes →
Control autonomous agents.
Every agent session traced action-by-action: each call’s cost, latency, and the policy decision it checked and enforced. When a run costs $50, you can see exactly why.
ACP uses your agent's real behavior to propose custom policy. Shadow mode replays your last week of real calls and shows what would have been denied before you apply it.
Deterministic allow, request approval, or deny on every single action. Set policy by person, agent, role, or tool.
Claude Code, Codex, Cursor, OpenCode, OpenClaw, CrewAI, LangGraph — each ships its own permission system, with its own rules in its own place. ACP is one set of rules, enforced across all of them. See every integration →
You shipped an agent. Now it's a black box.
You wrote checks to keep the agent from doing something dumb. They hold while you babysit it — and the whole point of handing off is that you stop watching. If any of these is you:
Same task, wildly different cost — and you find out from the invoice, not the run.
It reads your .env, pulls customer PII, pipes secrets straight into a prompt — and you can't see what left the building.
Every team ships in a different framework — and there's no one place to see or control them all.
What did it actually do all day?
When a run costs $50 or does something you didn't expect, you need to see what actually happened. ACP records every action in order — each model call and tool call with its latency, tokens, cost, and allow-or-deny decision, plus the real identity behind it. Click any event and see exactly what it did.
It's also where the bill comes from. The same task can run under a cent one time and hundreds of dollars the next, because cost tracks how much context the orchestration loop re-reads to decide its next move — and that scales with how far the run wanders. What is tool call economics? →
- The full timeline — loop, leaf, and tool calls, as they happened
- Per-event cost, latency, model, and the policy decision that gated it
- Loop vs leaf: the orchestration loop re-reading context is usually most of the bill
- Real identity and scopes carried through every delegation hop
- Budget caps that halt the run, deterministically — not just a warning
Your agents draft the rules. You sign them.
When policy blocks something an agent legitimately needs, it doesn’t work around the block — it proposes a rule: the tool, the tier, the permission, and why, written from the denial it just hit. Proposals queue in the console, and nothing is enforced until you confirm it.
- Each proposal is scoped to one tool and one tier — never a blanket exception
- The agent’s own rationale attached, so you review with context, not guesswork
- Confirm or reject in one click — the human stays the only one who can change policy
Your agent walked in holding 76 tools.
Every request a coding agent makes declares its full tool catalog — the model can't call what it can't see. A real Claude Code session declares 76 tools: the coding loop, yes — and tools that send messages, publish public web pages, schedule their own future runs, and drive your logged-in browser. Most were never invoked. All of them are standing open.
ACP captures the declared surface on the agent's first call — before anything runs — and turns it into a control table: every tool a click to allow, flag, or deny. When the surface drifts mid-session (we've watched one gain 21 tools in an afternoon), you hear about it.
- The full catalog, visible before first invocation
- One click per tool: allow · flag · deny · ask
- Drift detection — know when the surface grows
Control ships turnkey. Five ready policies at the level you already think — “an unattended agent that can’t touch the shell.” Assign one in shadow: it replays your last week of real calls and shows what it would have denied, and nothing blocks until you click enforce.
Runs unattended. Works freely — can’t rewrite its own memory, touch the shell, schedule itself, delegate, or read credentials.
Blocks nothing. Records everything — every call in the trail, PII redacted.
Codes beside you. Pauses before file deletes and credential reads; a secret headed out is denied.
Reads the world. Writes only inside its workspace — anything past that waits for your OK.
Ships things. Every deploy and infra change waits for a yes.
What each persona allows, pauses, and denies — attended and unattended →
Your first audit row in thirty seconds.
A coding agent in your IDE, a CrewAI pipeline, a LangGraph service, the OpenAI SDK in a script — pick the method that fits your stack. One install, no code changes, and every tool call is controlled. Free up to 5 agents — subagents free, calls unlimited.
One install per stack — the same control plane behind all of them. See every integration →
Open core, hosted control plane. The enforcement modules are six MIT-licensed npm packages you can read and self-host — the hosted control plane is how you run them in production.
You pay for agents that start work. Everything they delegate is free.
Free up to 5 initiating agents — identities that start work, like your coding agent or a scheduled bot. Subagents and delegation chains are free on every plan, and governed calls are unlimited. Flat monthly bands above: no call meters, no seats, no tax on coverage.
- 5 initiating agents · unlimited calls
- Subagents & delegation chains free
- See, control & price every call
- Hardline floor & approvals
- 30-day audit retention
- 25 initiating agents · unlimited calls
- Shared policies, approvals & roles
- Org-wide audit & cost rollup
- 1-year audit retention
- Named agent list on the bill — verify it yourself
- Unlimited initiating agents
- SSO / SAML · SCIM
- VPC / on-prem / self-host
- Unlimited audit retention
- SOC 2 evidence exports · DPA / BAA
All five tiers, the initiating-agent explainer, and the FAQ at /pricing →
Control every tool call your agents make.
Free up to 5 agents — no credit card, no call caps. See your first controlled tool call in about thirty seconds.
Prefer fully on-device? Add --local — no account, nothing leaves your machine.
Already installed? Open your console →
Rolling agents out across a team? See ACP for teams →
Or book 30 minutes — I’ll wire it into your agent with you, live.
— David Crowe, founder