Safe for your team. And your agents.
Every tool call and MCP invocation is risk-scored and graded ALLOW, REVIEW or BLOCK before it executes.
- REVIEW routes to a human approval queue with notifications — the agent waits, it does not guess.
- MCP server gating: allowlist which servers, and which tools within them, an agent may reach.
- Per-agent autonomy levels, a threat taxonomy, and a full activity thread behind every decision.
Graded before it runs.
read_file is fine. http.fetch deserves a look. shell.exec does not happen. Every tool call and every MCP invocation is risk-scored and stamped ALLOW, REVIEW or BLOCK while the agent is still waiting for an answer.
A queue, not a guess.
REVIEW sends the call to a human with the context attached, and the agent waits. Allowlist which MCP servers it can reach and which of their tools. Set how much autonomy it gets. Read the whole thread afterwards.