Actwarden henry@actwarden.com

Early prototype

Approvals and limits for AI agents that change real systems.

Actwarden sits between an AI agent and the systems it acts on. The agent proposes an action, such as a refund or temporary access to a group. Your written rules decide what happens next, the right people approve when the rules say so, and every step is recorded.

Talk to me about it

How it works

  1. The agent proposes. It sends the exact action it wants, with its parameters. It cannot carry anything out by itself.
  2. Rules decide. A versioned policy allows it, denies it, or asks for approval. The same request and the same facts always get the same answer.
  3. People approve. Approvers see exactly what they are approving. If the agent changes the request, the approval no longer counts.
  4. It runs, and it is checked. Approved actions are carried out once, then compared with what the other system actually did.

What the prototype does today

  • Refunds and time-limited group access, decided by rules
  • Approvals that bind to one exact version of a request
  • Limits on many small requests that add up: per agent per day, per payment, per customer over 30 days, and per person for access
  • Policy changes reviewed by two people when they could loosen a rule
  • Agent credentials that expire, rotate, are rate limited and can be limited to less than the agent may do
  • Agents connect through the Model Context Protocol (MCP) or a plain HTTP API
  • A sealed audit log: editing or deleting events with database access alone is caught, and an exported log can be checked against earlier receipts without Actwarden
  • Sign-in authenticator keys stored encrypted, with the key kept outside the data folder
  • A trial that puts a real language model in the agent's seat on fictional support tickets and scores what it tried

What it is not, yet

Actwarden runs on one computer against simulated payment and directory systems, with fictional data. It has not been used in production, reviewed by an outside security firm, or assessed against any compliance standard.

I want to learn what would need to be true before anyone relied on it.

Are you putting AI agents in front of real systems?

Or deciding not to? I would like to hear what is holding you back, what you already use, and what you would need to see.

henry@actwarden.com

Henry James