Control what your AI agents are allowed to do.

Give every AI agent an identity, define exactly what it may do, and require approval before sensitive actions execute.

Or create an account with email — Google sign-in is available on signup and login.

behalf · verify
Agentclaude-code-production
Requested actionstripe.refunds.create
VendorStripe
Resourcepayment_intent_3N8x...
Amount$8,400.00
Policy matchedProduction Finance Controls
Required authorityEngineering Lead
approval required

Refunds above the auto-approve threshold pause for a human with Engineering Lead authority. The action does not run until it is approved.

Fail-closed enforcement

Human approval gates

Google SSO for teams

Auditable decision records

Credentials provide access. They do not define authority.

Credentials open the system. They cannot decide whether a specific agent should perform a specific action.

  • Credentials are broader than authority.
  • Monitoring happens after execution.
  • Prompts are guidance, not enforcement.

Define authority. Enforce the decision. Preserve the evidence.

Scope every agent to explicit actions, resources, and production constraints.

Production Deployment AgentPolicy · applied to claude-code-production
Allowed actions
github.pull_requests.read
vercel.deployments.create
vercel.deployments.read
Blocked actions
github.repositories.delete
vercel.projects.delete
Constraints
Repositories:Protected repositories only
Production:Deploys require approval
Commands:Destructive flags are denied
Max amount:$1,000 per transaction
Required authority:Engineering Lead

Govern AI agents from one control plane.

Centralize identities, permissions, approvals, and decision history across your organization.

Centralized governance

Manage identities, permissions, and approvals from one workspace.

Google SSO

Sign in with Google for individuals, or enforce company-domain Google SSO for teams on Pro and higher.

Delegated authority

Assign who can define policy and approve sensitive requests.

Protected resources

Place production systems and repositories behind explicit controls.

Auditable decisions

Retain the evidence behind every allow, deny, and approval.

Your agents already have access. BehalfID determines whether they have authority.

Give every agent an identity, define its permissions, and require approval before sensitive actions are executed.