For AI engineering teams
Your agents act now.
Who said they could?
Agents have moved from answering to acting: they cross tools, change records and message customers. Every framework pauses for a person differently, and none of them decides who should answer or keeps what they said. Long sessions lose the goal, and the logs say what was called, not who allowed it. Deliverd gives every agent one way to ask, one place for the answer, and a task that outlives the session.
No card required · Unlimited readers · Secure by default
The situation
What this looks like today
Every framework pauses differently
The Claude Agent SDK calls a permission callback, LangGraph raises an interrupt, the OpenAI Agents SDK returns interruptions. Each stops the run; none of them knows who should answer, reaches them where they are, or keeps what they said.
Long sessions lose the goal
Forty turns into a debugging detour, nobody — the model included — can say what the work was for. Switch tools or models and the next one starts from a blank prompt and a pasted summary.
The trace says what ran, not who allowed it
Tracing records every tool call. When one of them turns out to matter, the question is who allowed it and what they were shown, and a trace was never built to answer that.
What changes
Deliverd for AI engineering teams
Everything below ships today. Where something needs a paid plan, it says so.
Your AI asks before it acts
An agent that needs a decision puts it to a named person and waits: what it wants to do, why, how risky it is, and what to read first. They approve, approve with changes, reject with a reason, or ask the agent a question — on the page, from an email link, in Slack or Teams, or from a push notification on a phone — and a colleague can cover their approvals while they are away. It can also ask for a review, or for information it is missing, the same way.
A check before the agent acts
Before a consequential action — a payment, a deployment, a message to a customer — the agent declares what it is about to do and waits for the answer. A named person decides, or your organisation's rules settle the routine cases and send the rest to a person; with no rules, every one goes to a person. Afterwards the agent records what ran, and the record is checked against what was allowed.
On every plan; policy rules included in Business and Enterprise
The work keeps its objective
A task holds what the work is for apart from the conversation doing it, with a short state — where it stands, the next action, what is in the way — that any agent reads when it resumes. Side tasks take a bug or a piece of research out of the main thread and come back with a result. Switch tool or model and the next one picks up where things stand instead of starting over, and only a person changes the objective.
Included in Team, Business and Enterprise
One pack for the auditor
Every step of a piece of work — who was asked, what they said, what was decided and when — exported as a single timeline in JSON, CSV or PDF. It carries a digest so an altered copy can be told apart, and the export itself is on the record.
Your AI cannot publish to the world
An agent identity can never grant public access — that is refused at the service, not hidden in the UI — and can be confined to named workspaces and audiences. Every refusal is written to the audit trail.
A second thought, where it matters
Your organisation writes rules for requests that touch someone's job, money, health or privacy, or that cannot be undone. When one matches, whoever decides sees the concern first and has to say why it is right to go ahead; a rule can also ask more people to agree, or refuse. Ethics rules only add oversight — none of them can approve anything — and they are on every plan.
Governance recorded as the work happens
Compliance Mode adds a register of the AI systems you use and, on governed work, the owners and the risk and data classification. That profile decides the controls: evidence or a person's approval meets each one, and an exception, with an owner and an expiry, shows as waived rather than met. The whole record exports as one evidence pack. It records how the work was governed — it does not certify compliance with any law or standard.
Included in Business and Enterprise
Review lands on the passage
A reader selects a sentence and comments on it. The thread stays anchored to that passage across new versions, so a review from two drafts ago still points at the right paragraph.
Every version kept, one URL
Reissuing updates the address and keeps what was there before. You can see what changed between two drafts and roll back if the new one is wrong.

Questions
AI engineering teams and Deliverd.
Which frameworks does it work with?
Anything that can make an HTTP request. Agents reach Deliverd over the MCP server, the REST API, the CLI, or the TypeScript and Python SDKs. The TypeScript SDK has adapters for the Claude Agent SDK, the AI SDK, the OpenAI Agents SDK and LangGraph, each written against that framework's own approval hook, so a tool call that needs a person goes to one without rewriting the agent.
Does a gate stop an agent that never asks?
No, and it is better to say so. A gate is advisory: the agent reports what it intends to do, a person or a rule answers, and the agent performs the action itself. What you get is that the question is asked, answered by somebody other than the agent and written down — and the execution record shows whether what ran matches what was allowed: the content's sha256 and where it went.
What happens when we switch models or tools halfway through?
The task carries on. An objective holds the outcome the work is for, and a short task state holds where it stands, the next action, open questions and what is in the way — which is what the next agent reads, whichever model or tool it is, instead of the whole history. Side tasks take a bug or a piece of research out of the main thread and come back with a result rather than a transcript. Tasks are included in Team, Business and Enterprise.
Can an agent approve its own request, or write its own rules?
No. The requester is removed from the approvers and an agent may not be an approver of anything. Writing a policy rule is how authority is granted, so an agent is refused at the service rather than hidden in the interface. And only a person changes a task's objective, so no model can redefine success and then meet it.
Can a destructive command get a second look first?
Yes. The starter ethics rule “Things that cannot be undone” flags requests that mention deleting everything, wiping, purging or dropping a table, and asks whoever decides whether there is a way back if it turns out to be wrong. It arrives switched off; once on, a flagged approval needs a reason before it goes ahead, and the concern goes into the evidence pack.
Let the agent act. Know who said it could.
One way to ask, one place for the answer, and a record of who allowed what — in the frameworks you already use.