For teamsearly access

Give your agents limits. Then give them the work.

Bounded reports recognized actions on the app and service paths you connect. Promote a matched route when it should be checked before firing; watched-only actions remain visible, not protected.

It starts by just watching.

Observe mode turns outbound calls into action stories: who did what, to whom, for how much, with values never captured. Once it has seen enough traffic, Bounded suggests boundaries from your real baselines.

PRIVATE BY CONSTRUCTION
values never leave your process

The sensor reports metadata and shape: field names and types, never values. No bodies, no headers, no query values on the wire.

Bounded learns the shape

The first stripped-down request teaches Bounded the shape of the route. Stories and suggestions come from shapes and safe fields, not payloads.

you disclose deliberately

Widening capture to a named field is an explicit policy change. The PII denylist is compiled into the sensor, so even a policy cannot reach into PII-shaped fields.

email · jwt · card numbers → [REDACTED] at ingest, counted and disclosedhow observe handles data

Watching is the start. The dashboard keeps pointing at the boundary you have not enforced yet.

Promote the boundary. Matched routed actions get a receipt.

Bounded suggests the boundary from your real baselines and replays your last seven days against it before you promote. After that, every matched action routed through the enforced boundary carries a verdict: allowed, declined with the rule named, or paused for a one-click approval. Over the cap is a click, not a redeploy; nothing fires until someone decides.

Proofs and runtime checks, named precisely.

Promoting a native spend or rate cap updates policy and runs its proof gate. Other escorted external-action boundaries are deterministic runtime checks, not formal proofs.

  • Enforced at the documented seam. Deployed data rules and invariants reject violating governed writes on their documented surfaces. Enforced Action Boundaries check matched routed calls before they fire; watched-only actions remain visible, not protected.
  • Checked before deploy. When a rule can fail, Bounded returns a concrete counterexample instead of a vague warning. A failing policy does not ship.
  • Audit trail. Prompt, diff, actor, approval, check result, action intent, and deployment records are captured for governed changes.
  • Private by construction. The sensor reports field names and types, never values. Bodies, headers, and query values never leave your process. Widening capture to a named field is an explicit policy change, and a compiled denylist keeps PII-shaped fields out.
  • Early access, honestly labeled. The observe-to-enforce ratchet is rolling out with design partners now. We install it together on a call. No self-serve signup pretends otherwise.

Keep your stack. Bound the dangerous actions.

Wrap your egress in about ten minutes: one interceptor, three ways in. Your app or agent keeps calling exactly as it does today; Bounded records the intent, checks the boundary, and fires or declines.

The full claim needs custody: it works best when the dangerous credential lives only inside Bounded. If the old key still exists somewhere else, Bounded can warn about drift, but it cannot honestly prevent that bypass. We set up the key custody with you in the pilot.

Every agent gets its own budget. Its own key. Its own limits.

Bounded discovers who acts and keeps the census: agents, services, people. Each gets a registry entry, its own budget, and its own key when it matters. Limits are data, changed without a redeploy. An agent can never raise its own. That includes your team’s AI use: connect your provider org read-only and see spend per member and team in ten minutes, with keys moving into custody when budgets must hold. The same boundaries govern prompt-made changes in internal tools.

Self-reported identity is enough to see. Budgets that must hold are built on key-bound identity. The dashboard grades which is which.

Loosen the limits as trust grows.

Three guarantee tiers, routed by policy: observe what matters, escort the dangerous, custody the keys. Reads never touch the inline path, and every route is labeled with the guarantee you are holding.

  • OBSERVEDObservedRecognized traffic on paths you connect, reported asynchronously as stories. Payload values stay out of telemetry, and coverage discloses what the sensor did and did not recognize.Visible, not enforced.may claim: “we can see it”
  • ESCORTEDEscortedMatched traffic you deliberately route goes through the boundary layer before it fires. A decline is a normal API error with the rule named. An old credential elsewhere can still bypass that seam; custody is the stronger per-rail posture.Checked before it fires.caveat, always: old credential still bypasses
  • CUSTODIEDCustodiedEscorted, plus the restricted key exists only at Bounded. Going around the boundary layer is not forbidden. It fails auth. Scoped to the rail in custody. Drift recon watches the rail for out-of-band changes.Non-bypassable, per rail.only tier that may say: “non-bypassable · per rail”

Drift is the honesty artifact: stated as facts and a delta, no siren. It is the one alert that can page, because a credential outside custody is the one thing an Escorted boundary cannot promise away.

Steady state

The weekly report, built to be forwarded.

The whole story fits in one screen of email.

Nothing in the report is a chart: counts, actors, and stories. The one “(approx.)” is on the counterfactual model-spend line, because that rail is counters-only. The page and the emailed version share this exact layout.

Bring us one action you’re scared to automate.

A fixed-scope pilot, about a week, around one action or one tool. We set up the key custody with you, put the first boundary in place, and measure whether your agents can safely move faster. We install observe mode while we’re on the call.