Deliverd gates · the check before the action
The agent says what it is about to do.
A person, or your policy, answers.
A gate holds a consequential action — a deployment, a payment, a message to a customer — until it is allowed. With no rules, a named person decides. With rules, the routine cases are settled and the rest go to a person. Afterwards the agent records what actually ran, and the evidence pack shows who asked, who decided and what happened.
On every plan · MCP, REST, CLI and SDKs for TypeScript and Python
How the work runs
Step by step
- 01
The agent declares the action
What it is about to do, and what it touches, before it does it.
- 02
A person or a rule answers
Allowed, refused, or waiting for a named person. The agent branches on the answer.
- 03
The agent acts, then records it
The receipt is checked against what was allowed: the content's digest and where it went.
- 04
The record is exported
Who asked, who decided, what ran and when, as one evidence pack.
What it does
Everything on this page ships today
Each part names what an agent calls for it and the plans that include it.
Declare before acting
The agent calls the gate with the action and what it touches. The answer is allowed, refused or waiting for a person, and the decision is recorded either way — including the ones nobody had to see.
- Plans
- On every plan
- It calls
check_gateget_gate
Policy rules
Rules match on the action, the agent, thresholds and the environment: permit it, refuse it, or ask a named person — two people, or a named set, as the risk rises. Only an owner or an administrator writes them; an agent cannot. Rules are versioned, with a simulator that answers what a request would have got.
- Plans
- Included in Business and Enterprise
- It calls
- Set by a person in the app — an agent cannot change it
Agent identities
Each agent gets its own identity, scoped to the workspaces and reports it may touch and whether it may share outside the organisation.
- Plans
- Included in Team, Business and Enterprise
- It calls
- Set by a person in the app — an agent cannot change it
Execution records
After acting, the agent records what ran. The receipt is compared with what the gate allowed — the content's sha256 and its destination — so a mismatch is on the record rather than invisible.
- Plans
- On every plan
- It calls
record_execution
Ethics rules
Rules your organisation writes for requests that deserve a second thought: raise a concern for the person deciding, insist a person weighs it, or refuse it outright.
- Plans
- On every plan
- It calls
- Set by a person in the app — an agent cannot change it
Evidence packs
Every step of the work — who was asked, what they said, what was decided and when — as one timeline in JSON, CSV or PDF, with a digest so an altered copy can be told apart. The export itself is audited.
- Plans
- On every plan
- It calls
get_evidence
Agent authority
Say what agents may do on their own, only with a person's approval, or not at all. The organisation sets the ceiling; an agent's own setting can only be stricter.
- Plans
- Included in Enterprise
- It calls
check_agent_authority
Questions
Gates and evidence and Deliverd.
Which plans include gates?
Gates, execution records and evidence packs are on every plan; with no rules, a named person decides each gate. Policy rules are included in Business and Enterprise, agent identities in Team, Business and Enterprise, and agent authority in Enterprise.
Does a gate stop an agent that never asks?
No, and it is better to say so. A gate is advisory: the agent reports what it intends to do, a person or a rule answers, and the agent performs the action itself. What you get is that the question can be asked, is answered by somebody other than the agent, and is written down — and the execution record shows whether what ran matches what was allowed.
Who writes the rules, and can an agent write its own?
An owner or an administrator of your organisation. An agent cannot: writing a rule is how authority is granted, so an agent is refused at the service rather than hidden in the interface. A rule version cannot be edited once it is active.
What do we hand an auditor?
An evidence pack: every step, who was asked, what they said, what was decided and when, as one timeline in JSON, CSV or PDF, with a digest so an altered copy can be told apart.
AI does the work. People make the calls. Deliverd keeps the record.
- Tasks— Stop losing the thread
- Compliance Mode— Govern AI work