Use AI agents without worrying what they might do.
Control, observe, and analyze every action your AI agents take.
Works with agents you can and can't modify. If it acts through your systems, it is checked.
| Agent | Via | Tool, target, magnitude | Rule | Waiting on |
|---|
Transparent by design
The code that keeps your agents in check is open source. Read it, run the same checks we run, and keep every receipt in a format you own.
Trust is something you verify, not something we ask for.
$ ctrlrun verify ctrlrun verify — ctrlrun 0.12.2, catalogue ctrlrun.guarantees/v7 policy ctrlrun.yaml (ctrlrun.policy/v2, mode: enforce) store sqlite, scratch (created and destroyed for this run) G1 mutated approval refused PASS stripe.refund G2 replayed approval refused PASS stripe.refund G3 duplicate effect refused PASS stripe.refund G4 one winner under concurrency PASS stripe.refund (8 processes) G5 ambiguous blocks a blind retry PASS stripe.refund G7 no principal refused PASS stripe.refund G10 unknown exception is ambiguous PASS stripe.refund G11 an altered receipt is detected PASS stripe.refund G12 a byte written is ambiguous PASS stripe.refund … 20/20 declared guarantees pass. 12 not applicable: G8, G9, G13, G15, G17, G19, G22, G23, G24, G25, G26, G27.
Let it run. Ask a human. Or stop it cold.
Every action that leaves your agents, tools and workflows is normalized into one action, decided against your policy, held for a person where you require it, reserved so it cannot run twice, executed, resolved and recorded.
Your agents, tools and workflows
An action is about to run.
Any model, any framework. Existing code stays as it is.
- Agents you buy
- WhatsApp, Slack, Teams, Claude Code, Cursor, Codex, ChatGPT.
- Agents you build
- your own code, in-house or contracted, any framework, the OpenAI Agents SDK. Any agent you have.
- Three ways in
- gateway
- agents you can't modify, one MCP URL
- decorator
- your own code, one line
- adapter
- a framework's SDK, such as OpenAI Agents
ctrlrun, the execution boundary
The model guesses.
CTRLRun does not.
No rule for it
The action is blocked. Silence is never permission.
deniedArguments changed after sign-off
The old approval is void. A person signs again.
blockedOutcome unknown
No retry until a person resolves it. Nothing runs twice on a guess.
ambiguousYour systems
The action arrives already checked.
Allowed by your rules, approved where you require it, and never run twice.
Control
open source, UI in Personal and Business
Checked before it runs. Allowed, waiting, or blocked.
Observe
Personal and Business
Every attempt recorded, refusals included: live feed, approvals inbox, incidents, receipts and verify, in one dashboard.
The receipts themselves are yours in every plan.
Analyze
Personal and Business
Every agent's behaviour summarized: signals, insights, reports, with the receipts behind each one.
For one person
Personal
Your agents ask you first, in one inbox. Claude Code, Cursor, a connector, your own code.
When someone else has to say yes, that's Business.
Enterprise: shaped to you and built with you. Our engineers, with your team. Discuss your deployment