Use AI agents without worrying what they might do.

Control, observe, and analyze every action your AI agents take.

Works with agents you can and can't modify. If it acts through your systems, it is checked.

Approvals6 waitingSample data
today: Allowed 1,204, Waiting 6, Blocked 17
AgentViaTool, target, magnitudeRuleWaiting on

Transparent by design

The code that keeps your agents in check is open source. Read it, run the same checks we run, and keep every receipt in a format you own.

Trust is something you verify, not something we ask for.

Read the code on GitHub

$ ctrlrun verify
ctrlrun verify — ctrlrun 0.12.2, catalogue ctrlrun.guarantees/v7
policy     ctrlrun.yaml (ctrlrun.policy/v2, mode: enforce)
store      sqlite, scratch (created and destroyed for this run)

G1   mutated approval refused         PASS  stripe.refund
G2   replayed approval refused        PASS  stripe.refund
G3   duplicate effect refused         PASS  stripe.refund
G4   one winner under concurrency     PASS  stripe.refund (8 processes)
G5   ambiguous blocks a blind retry   PASS  stripe.refund
G7   no principal refused             PASS  stripe.refund
G10  unknown exception is ambiguous   PASS  stripe.refund
G11  an altered receipt is detected   PASS  stripe.refund
G12  a byte written is ambiguous      PASS  stripe.refund
…
20/20 declared guarantees pass. 12 not applicable: G8, G9, G13, G15, G17, G19, G22, G23, G24, G25, G26, G27.

Let it run. Ask a human. Or stop it cold.

Every action that leaves your agents, tools and workflows is normalized into one action, decided against your policy, held for a person where you require it, reserved so it cannot run twice, executed, resolved and recorded.

Your agents, tools and workflows

An action is about to run.

Any model, any framework. Existing code stays as it is.

Agents you buy
WhatsApp, Slack, Teams, Claude Code, Cursor, Codex, ChatGPT.
Agents you build
your own code, in-house or contracted, any framework, the OpenAI Agents SDK. Any agent you have.
Three ways in
gateway
agents you can't modify, one MCP URL
decorator
your own code, one line
adapter
a framework's SDK, such as OpenAI Agents

ctrlrun, the execution boundary

one receipt, as it is writtensample

The model guesses.
CTRLRun does not.

WhenWhat happensresult

No rule for it

The action is blocked. Silence is never permission.

denied

Arguments changed after sign-off

The old approval is void. A person signs again.

blocked

Outcome unknown

No retry until a person resolves it. Nothing runs twice on a guess.

ambiguous

Your systems

The action arrives already checked.

Allowed by your rules, approved where you require it, and never run twice.

Control

open source, UI in Personal and Business

Checked before it runs. Allowed, waiting, or blocked.

Observe

Personal and Business

Every attempt recorded, refusals included: live feed, approvals inbox, incidents, receipts and verify, in one dashboard.

The receipts themselves are yours in every plan.

Analyze

Personal and Business

Every agent's behaviour summarized: signals, insights, reports, with the receipts behind each one.

Read the docs

For one person

Personal

Your agents ask you first, in one inbox. Claude Code, Cursor, a connector, your own code.

Start Personal

For a company, in two sizes

Business

Integrate, analyze, protect. One dashboard.

Start free trial

When someone else has to say yes, that's Business.

Enterprise: shaped to you and built with you. Our engineers, with your team. Discuss your deployment

See pricing