Product
A Control Plane at the Agent's Action Boundary.
Most gateways inspect what goes into a model and what comes out of it. InterceptAI governs what happens next. It fronts your tools and stops every consequential action before a single side effect occurs, independently of the agent platform and the tools that platform calls.
intercept → score → enforce → record · transport agnostic · vendor neutral
The Console
What You Actually Look At?
Agent Dashboard
Live verdicts across every registered agent, grouped by consequence band, so you can see at a glance what is running and what is waiting.
A Held Action
The action itself, the intent the agent was authorized to pursue, the policy that paused it, and the reviewer group it was routed to.
Policy Editor
First match rules on band, tool, and surface, with the active version and its history beside it.
Ledger Entry
One record, its chain state, and the previous hash it commits to.
The Pipeline
4 Steps Between an Agent and a Real Side Effect
Intercept
Catch each tool call at the boundary. Available over the Model Context Protocol today, with a software development kit and outbound traffic capture arriving next.
Score
Rate the consequence by how reversible the action is, how wide the blast radius reaches, and how far it has drifted from the intent that was delegated.
Enforce
Apply your policy and choose the response: allow, hold, block, or wrap with an undo.
Record
Write a chained entry that only ever appends, showing what was authorized beside what actually ran.
The 4 Responses
One Decision Per Action, Matched to What That Action Could Cost You
allow
Low consequence work passes straight through. Recorded, never slowed. The fast path carries a tested budget of roughly 40 milliseconds of added overhead at the median.
hold
The action is parked until a person approves or denies it in the console. This is human in the loop AI done properly: because the hold is a row in the database, it survives a restart and routes to the reviewer group that should see it.
block
A destructive action is refused outright. No downstream call is made, and the record names the exact policy that stopped it.
wrap → undo
Let a write happen reversibly. We snapshot the state beforehand and offer a single click undo afterward, so a change that was permitted but wrong can be undone. No other layer in your stack can do this, because no other layer sees the action before it commits.
What is Inside?
Consequence Scoring, Delegated Intent, and Attribution Across Agents
Consequence First Scoring
A deterministic scorer rates reversibility, blast radius, and sensitivity. An optional judge adds a semantic reading of intent drift. The resulting band, from low through to critical, drives your policy.
Delegated Intent Envelopes
Sign what the agent was authorized to do, then measure every action against that signature. The record becomes authorized against actual actions rather than a plain list of things that ran.
Attribution Across Agent Chains
When one agent spawns another, the resolved delegation chain from originator down to actor is attached to every action. Liability stays traceable no matter how long the chain grows.
Policy You Can Author and Version
Write policy as first match rules on band, tool, and surface. Activate it, roll it back, or shadow test a candidate rule against real history before it enforces anything.
Operations
Self Hosted, Observable, and Safe Under Load
Self Hosting First
Docker Compose or Helm, running against your Postgres database and your identity provider. Nothing phones home, and the fast path pays no cost for features you have not switched on.
Fails Safe, Never Open
If scoring or the record becomes unavailable, a high consequence action holds rather than quietly proceeding. Health probes and graceful shutdown keep rolling deployments clean.
Observable
OpenTelemetry spans and metrics, structured logs, rate limiting per tenant, and a latency target you can assert inside your build pipeline.
The record is where accountability lives; see the security & trust story, or get started.
Integrations
Works With What You Already Run
Model Context Protocol. LangChain. AWS Bedrock. Google Vertex AI. Microsoft Foundry. OpenAI tool calling. Anthropic tool use. Custom HTTP tools.
How the ledger stays tamper evident · Deployment options and design partner access