Deliverd gates · the check before the action

The agent says what it is about to do.
A person, or your policy, answers.

A gate holds a consequential action — a deployment, a payment, a message to a customer — until it is allowed. With no rules, a named person decides. With rules, the routine cases are settled and the rest go to a person. Afterwards the agent records what actually ran, and the evidence pack shows who asked, who decided and what happened.

On every plan · MCP, REST, CLI and SDKs for TypeScript and Python

How the work runs

Step by step

  1. 01

    The agent declares the action

    What it is about to do, and what it touches, before it does it.

  2. 02

    A person or a rule answers

    Allowed, refused, or waiting for a named person. The agent branches on the answer.

  3. 03

    The agent acts, then records it

    The receipt is checked against what was allowed: the content's digest and where it went.

  4. 04

    The record is exported

    Who asked, who decided, what ran and when, as one evidence pack.

What it does

Everything on this page ships today

Each part names what an agent calls for it and the plans that include it.

Declare before acting

The agent calls the gate with the action and what it touches. The answer is allowed, refused or waiting for a person, and the decision is recorded either way — including the ones nobody had to see.

Plans
On every plan
It calls
check_gateget_gate

Policy rules

Rules match on the action, the agent, thresholds and the environment: permit it, refuse it, or ask a named person — two people, or a named set, as the risk rises. Only an owner or an administrator writes them; an agent cannot. Rules are versioned, with a simulator that answers what a request would have got.

Plans
Included in Business and Enterprise
It calls
Set by a person in the app — an agent cannot change it

Agent identities

Each agent gets its own identity, scoped to the workspaces and reports it may touch and whether it may share outside the organisation.

Plans
Included in Team, Business and Enterprise
It calls
Set by a person in the app — an agent cannot change it

Execution records

After acting, the agent records what ran. The receipt is compared with what the gate allowed — the content's sha256 and its destination — so a mismatch is on the record rather than invisible.

Plans
On every plan
It calls
record_execution

Ethics rules

Rules your organisation writes for requests that deserve a second thought: raise a concern for the person deciding, insist a person weighs it, or refuse it outright.

Plans
On every plan
It calls
Set by a person in the app — an agent cannot change it

Evidence packs

Every step of the work — who was asked, what they said, what was decided and when — as one timeline in JSON, CSV or PDF, with a digest so an altered copy can be told apart. The export itself is audited.

Plans
On every plan
It calls
get_evidence

Agent authority

Say what agents may do on their own, only with a person's approval, or not at all. The organisation sets the ceiling; an agent's own setting can only be stricter.

Plans
Included in Enterprise
It calls
check_agent_authority

Questions

Gates and evidence and Deliverd.

Which plans include gates?

Gates, execution records and evidence packs are on every plan; with no rules, a named person decides each gate. Policy rules are included in Business and Enterprise, agent identities in Team, Business and Enterprise, and agent authority in Enterprise.

Does a gate stop an agent that never asks?

No, and it is better to say so. A gate is advisory: the agent reports what it intends to do, a person or a rule answers, and the agent performs the action itself. What you get is that the question can be asked, is answered by somebody other than the agent, and is written down — and the execution record shows whether what ran matches what was allowed.

Who writes the rules, and can an agent write its own?

An owner or an administrator of your organisation. An agent cannot: writing a rule is how authority is granted, so an agent is refused at the service rather than hidden in the interface. A rule version cannot be edited once it is active.

What do we hand an auditor?

An evidence pack: every step, who was asked, what they said, what was decided and when, as one timeline in JSON, CSV or PDF, with a digest so an altered copy can be told apart.

AI does the work. People make the calls. Deliverd keeps the record.