One decision engine governs spend, tools, and capability. Everything here is checked before an agent acts, and every change is a replayable revision.
Tool posture
0 blocked · 0 escalated
Capability rules
0 active rules
Token cost month
$0.00
Approval pressure
0 pending · 0 escalated
Curated baselines along the governance ladder. Preview replays a pack over your last 30 days before you commit; applying replaces the current policy.
Watch first — everything passes, everything is measured.
Watch before you govern — everything passes, everything is measured.
Your first week with agents: see real spend patterns before choosing limits.
Start with model-call metering and a hard stop before the provider sees over-budget traffic.
Teams already using LiteLLM, Vercel AI SDK, OpenAI-compatible clients, or a homegrown LLM gateway.
Ceilings — hard limits without a committee.
Sane guardrails for a small team's first production agents.
A few agents doing real work; you want a ceiling, not a committee.
Put allow, escalate, and deny rails around the MCP tools your agents discover.
Teams adding Sanction to Cursor, Claude Desktop, Claude Code, Windsurf, or custom MCP hosts.
Humans in the loop where it matters.
Departmental budgets, human escalation where it matters.
A team's shared wallet: real budgets, approvals for the unusual, room to work.
Let coding agents read and propose freely; escalate writes, deploys, and new tools.
Cursor, Claude Code, Codex, Cline, and OpenHands agents moving from sandbox to real repos.
The pool policy for one spending channel of an agent fleet — monthly envelope, pooled token cap, escalation line, outcome-ceiling ready.
Ops running a fleet where channels (paid media, content, outbound) are delegated pools and every seat spends. Apply to the channel pool, not the root; set outcome_kind + a ceiling once you report outcomes.
Fail closed, prove everything.
Fail closed — everything above a whisper asks a human.
Regulated work: every spend escalates, every new capability escalates, timeouts deny.
A launch policy an AI agency can hand to a client: visible spend, approval for risky work, evidence after.
AI agencies and consultants shipping agents into client accounts this week.
Hold policy and evidence in front of whichever payment rail the agent uses.
AP2, x402, checkout, procurement, and purchasing-agent pilots where money movement needs a mandate.
Only on-box tools pass — every cloud call is denied and logged for the assessor.
Sanction Local installs: regulated practices running local models where data must not leave the building.