Four Steps · Every Action Recorded

Product

A Control Plane at the Agent's Action Boundary.

Most gateways inspect what goes into a model and what comes out of it. InterceptAI governs what happens next. It fronts your tools and stops every consequential action before a single side effect occurs, independently of the agent platform and the tools that platform calls.

product-pipeline · intercept → record
live4 verdicts
Agent
Intercept
Score
Enforce
Record
Verify
allowholdblockwrap

intercept → score → enforce → record · transport agnostic · vendor neutral

The Console

What You Actually Look At?

Agent Dashboard

Live verdicts across every registered agent, grouped by consequence band, so you can see at a glance what is running and what is waiting.

A Held Action

The action itself, the intent the agent was authorized to pursue, the policy that paused it, and the reviewer group it was routed to.

Policy Editor

First match rules on band, tool, and surface, with the active version and its history beside it.

Ledger Entry

One record, its chain state, and the previous hash it commits to.

The Pipeline

4 Steps Between an Agent and a Real Side Effect

Agent
Intercept
Score
Enforce
Record
Verify
STEP 1

Intercept

Catch each tool call at the boundary. Available over the Model Context Protocol today, with a software development kit and outbound traffic capture arriving next.

STEP 2

Score

Rate the consequence by how reversible the action is, how wide the blast radius reaches, and how far it has drifted from the intent that was delegated.

STEP 3

Enforce

Apply your policy and choose the response: allow, hold, block, or wrap with an undo.

allowholdblockwrap → undo
STEP 4

Record

Write a chained entry that only ever appends, showing what was authorized beside what actually ran.

The 4 Responses

One Decision Per Action, Matched to What That Action Could Cost You

allow

Low consequence work passes straight through. Recorded, never slowed. The fast path carries a tested budget of roughly 40 milliseconds of added overhead at the median.

hold

The action is parked until a person approves or denies it in the console. This is human in the loop AI done properly: because the hold is a row in the database, it survives a restart and routes to the reviewer group that should see it.

block

A destructive action is refused outright. No downstream call is made, and the record names the exact policy that stopped it.

wrap → undo

Let a write happen reversibly. We snapshot the state beforehand and offer a single click undo afterward, so a change that was permitted but wrong can be undone. No other layer in your stack can do this, because no other layer sees the action before it commits.

What is Inside?

Consequence Scoring, Delegated Intent, and Attribution Across Agents

Consequence First Scoring

A deterministic scorer rates reversibility, blast radius, and sensitivity. An optional judge adds a semantic reading of intent drift. The resulting band, from low through to critical, drives your policy.

Delegated Intent Envelopes

Sign what the agent was authorized to do, then measure every action against that signature. The record becomes authorized against actual actions rather than a plain list of things that ran.

Attribution Across Agent Chains

When one agent spawns another, the resolved delegation chain from originator down to actor is attached to every action. Liability stays traceable no matter how long the chain grows.

Policy You Can Author and Version

Write policy as first match rules on band, tool, and surface. Activate it, roll it back, or shadow test a candidate rule against real history before it enforces anything.

Operations

Self Hosted, Observable, and Safe Under Load

Self Hosting First

Docker Compose or Helm, running against your Postgres database and your identity provider. Nothing phones home, and the fast path pays no cost for features you have not switched on.

Fails Safe, Never Open

If scoring or the record becomes unavailable, a high consequence action holds rather than quietly proceeding. Health probes and graceful shutdown keep rolling deployments clean.

Observable

OpenTelemetry spans and metrics, structured logs, rate limiting per tenant, and a latency target you can assert inside your build pipeline.

The record is where accountability lives; see the security & trust story, or get started.

Integrations

Works With What You Already Run

Model Context Protocol. LangChain. AWS Bedrock. Google Vertex AI. Microsoft Foundry. OpenAI tool calling. Anthropic tool use. Custom HTTP tools.

How the ledger stays tamper evident · Deployment options and design partner access