EARLY BUILD — LIVE ENFORCEMENT API

Set Portable, Enforceable Boundaries for Every AI

AI should feel liberating, not like handing your life to a black box. Aegis is an early build of a human-first trust protocol: your data stays in your control, sensitive actions wait for your approval, and every agent can be stopped in one click.

Modeled for:OpenAI OperatorGoogle GeminiApple IntelligenceMeta LlamaStripePlaid

Conceptual cross-model architecture. No affiliation or current integration with these providers is implied.

Protocol
Not yet production security
Live
Sandbox calls the real API
Logged
Append-only decision log
AI
WHY THIS HAS TO EXIST

Not another AI assistant. The trust layer every agent will need.

Aegis is designed to let a person set portable, enforceable boundaries for every AI they use: what it may access and do, spending and sharing limits, when approval is mandatory, and a universal action receipt with a revoke button and a kill switch.

As agents take on more of representing people — across assistants, phones, banks, and everyday apps — someone has to hold that boundary. A platform that also builds the agent has a structural conflict of interest in also being the referee over it. They can ship a better chatbot; they can’t credibly own the neutral authority layer across their own rivals.

Today this exists as a working sandbox, not a live integration with any provider below — see “Modeled for” above and the honest capability table in /compare.

The urgency is real

57%

of consumers say data security and privacy would most increase their willingness to trust a personal AI assistant — ahead of transparency (48%) and human oversight (46%).

Zendesk / YouGov, 2026 CX Trends Report →
+63%

year-over-year rise in consumer demand for AI transparency — yet only 37% of organizations currently explain how their AI reaches a decision.

Zendesk, 2026 CX Trends Report →
NIST AI RMF

names transparency, accountability, and human oversight matched to risk as core requirements for trustworthy AI — exactly the properties a delegation boundary is built to enforce.

NIST AI Risk Management Framework →
“Unlikely to ever be fully solved”

is how OpenAI describes prompt injection for browser agents — malicious instructions hidden in ordinary web content that can hijack what an agent does next.

OpenAI, hardening ChatGPT Atlas →

The sandbox below talks to the live enforcement API. On your first action it creates a throwaway owner account and one API key per agent you try, kept in this browser. The kill switch revokes those keys on the server, so every later call is refused there, not just greyed out here.

Want your own durable account, agent keys and approval queue? Use the owner console.

LIVE POLICY SIMULATOR

Interactive Agent Governance Sandbox

Set boundaries, then fire sample agent actions. Each one is a real request to the live /api/enforce endpoint with a real agent key, decided server-side and written to a durable decision log. The actions themselves are samples: no email is sent and no money moves.

1. Select agent & set boundaries

Any agent can be targeted here — this list isn’t hardcoded to a fixed set of providers, and any of them can be granted access and killed the same way.

Daily spending limit$1000 / day
$50$1,000$2,000
Communication
Storage & Files
Finance & Transactions
Analytics & Insights
Sensitive Data
Boundaries set for OpenAI Operator / ChatGPT Agent: $1000/day · 8 scopes · approval over $100

2. Send agent actions

Live API
AEGIS ENFORCEMENT LOG
// Ready. Each action below is a real call to the live /api/enforce endpoint.
Waiting for agent action...IDLE
SYSTEM ARCHITECTURE

Four Pillars of Portable Agent Trust

The interface model for safely delegating authority to autonomous AI across competing tech ecosystems.

Access & Action Governance

Granular scope isolation. Specify exactly what APIs, files, and channels an agent can touch — regardless of which model runs it.

  • Scope isolation per vendor
  • Boundary defined before access

Spending & Time Caps

Rate limits, balance ceilings, and auto-expiring temporary delegation passes to stop runaway agent spending before it happens.

  • Daily / per-transaction caps
  • Auto-expiring access windows

Mandatory Approvals

Configurable human-in-the-loop triggers that force explicit sign-off for high-risk actions, transfers, or sensitive data exports.

  • Manual approval popups
  • Risk-based step-ups

One-Click Kill Switch

One click revokes an agent’s API key on the server; its very next enforcement call is blocked, and any approval it was waiting on is cancelled.

  • Single-click revoke
  • Visible, timestamped action log
DECISION LOG

Every decision, on the record

Each enforcement decision, approval, denial and revoke is written to an append-only table in Postgres with the actor and a server timestamp. The database rejects edits and deletes to it, including from the app itself. The rows on the right are your sandbox’s, read back from the server.

Single-use approvals

Approving a held action mints one token bound to the hash of that exact request. A different amount, recipient or agent is refused, and a second use is refused.

Honest limits

Aegis decides; it does not intercept. An agent that never calls the API is not stopped, and log entries are not cryptographically signed yet.

Open the owner console
SERVER DECISION LOGRUNNING
No entries yet. Run an action in the sandbox above.
THE AEGIS PROTOCOL · FUTURE VISION

The trust protocol agents will need.

Aegis imagines a future where every agent carries a human-readable mandate, receives only time-bound authority, emits a signed receipt, and can be revoked everywhere at once. Platforms build the intelligence; people keep the authority.

Governance vectorOpenAI / tech silosBig tech OS (Apple/Google)Aegis model (concept)
Cross-rival portabilityLocked to internal ecosystemRestricted to native OS APIsDesigned to be model-agnostic
Who defines the boundaryVendor-defined defaultsPlatform-defined defaultsThe person delegating, by design
Conflict of interestReferees its own agentReferees its own ecosystemNot a model vendor itself
Revocation scopePer-vendor onlyPer-OS onlyIntended to span providers

This table describes design intent for this concept, not certified or audited capabilities of any listed company’s products.

See how Aegis compares to what exists today

Real platforms already solve pieces of this problem for engineering teams. Read honest, researched comparisons before assuming this replaces them.

Compare Aegis to real platforms

Protect Human Sovereignty in the Age of Autonomous AI

A protocol concept built for the institutions and developers who will need this once agents act on their behalf across rival platforms — try the sandbox yourself, no signup required.