Two agents, one limit, one refused.

Approvals

Your agent is one bad call away from production

Approval gates, environment isolation, and a kill switch, on the actions your agent takes through Anlyon.

agent.ts
const { data } = await anlyon.actions.invoke("send-invoice", {  customer: "acme",  amount: 420000,});if (data!.pendingApproval) {  // Parked until you or a teammate decides in the dashboard.  console.log("Waiting on approval:", data!.approvalId);}

How it works

An inbox for the calls you gate, a decision the requesting credential cannot make, and an action that runs on your yes.

The inbox

An inbox, not a webhook you have to build

Pending approvals land in your dashboard with the full payload: what the agent wants to do, to whom, for how much. Approve or deny in one click.

The decider

The agent can’t approve itself

The credential that asked can never be the one that decides. No scope grants it and no policy relaxes it.

The dispatch

Runs on your yes, not on a poll

On approval, Anlyon runs the parked call itself against the request snapshot frozen when it was asked for. Destination bindings are checked again at dispatch.

The switch

A kill switch within reach

One switch stops the agent acting and stops anything leaving the environment. No deploy needed.

25 April 2026

Public reports say a coding agent deleted PocketOS’s production volume and the backups stored inside it. They describe no pause for a human, no environment boundary, and a token with far more authority than its task. The controls beside this apply to actions routed through Anlyon.

Read the full teardown
01

Environment isolation

A staging key cannot reach production data. It resolves its environment from the credential.

02

Scoped credentials

For an action routed through Anlyon, the key is in the vault and the model never sees it.

03

Approval gates

A gated call waits for a person before it is dispatched.

Oversight

The EU AI Act's high-risk obligations apply from December 2027 and August 2028. Article 14 asks for human oversight, including a way to stop the system. Article 12 asks for automatic logging. Both act at the point a side effect leaves. For an action routed through Anlyon, that point is on our side.

Article 14(4): human oversight

A person must be able to understand, override, and intervene or stop the system.

Anlyon makes the call, so it can hold it. A gated action parks for a human. Policy routes what needs review, and a rule can require N distinct approvers. N counts distinct credentials for API-key deciders and distinct users for dashboard and OAuth deciders. Halt stops the agent acting and stops anything leaving. A request another server already accepted is not recalled.

Article 12: record-keeping

Automatic logging of events relevant to risk identification and traceability.

Every run is a trace: model calls, invocations Anlyon made on the agent's behalf, approval waits and decisions, who decided, when, under which policy version. Exportable as OpenTelemetry, so your records outlive any vendor.

Article 9: risk management

Identify and control the risks the system poses in production.

Environment isolation bounds the blast radius: a staging key can't resolve to production. A protected environment needs explicit confirmation to change. Budgets cap the Anlyon operations a key may perform. Versioned action definitions let you pin what an agent version shipped with, and a rollback puts the previous definitions back for what happens next.

Anlyon provides oversight and logging capabilities. Whether your system is in scope and compliant is a determination for your counsel.

FAQ

The ones that decide whether this is worth an afternoon. Answered plainly, including the one where the answer is no.

Anything still unanswered is worth an email.

support@anlyon.com

Email us

Because then the credential is in the process the model is driving, and the only thing standing between a prompt injection and a refund is your own code remembering to check. Route the call through Anlyon and the key never leaves our side, policy runs on every invocation, a human can be required, the exact definition is pinned to a version, and one switch stops the environment dispatching anything further.

No. Anlyon is an API you call from code you already have. There is a TypeScript SDK and a Python SDK, or one command if you use Claude or Cursor. Replacing a direct HTTP call with an action invocation does not change how the rest of your agent is written.

Then use the local approval gate: an SDK wrapper that waits for a decision before your function runs. Be clear about what it is. Your process still executes the call with your credential, so it gives you the human decision and the record, not the credential isolation.

You can. It is a credential broker, a policy evaluator on the hot path, an approval queue with a dashboard behind it, versioned tool definitions, a limit shared across agents, and a record of what each call did. Most teams get three of those half-built. None of them is your product.

Yes. An impact limit caps the money your agents' governed actions move. Every agent, session and key in the environment draws from the same limit, reserved before dispatch. A new session or key does not get a new allowance. A limit can also count any unit you declare, such as emails or rows. Limits cover governed actions routed through Anlyon inside one environment, and an operator with the impact-limits:write scope can raise, lower or archive one.

Requests the cap covers stop with a 429 and the error code BUDGET_EXCEEDED. Never a silent drop, and never a surprise charge. The cap is on Anlyon operations, not on the money an approved action moves. During Early Beta Access nothing is charged at a limit. Paid plans arrive after the beta.

Your traces export as OpenTelemetry, so the audit record outlives any vendor, including this one. That is the part that is painful to lose, so it is the part we made portable.

No. Anlyon is a hosted service. There is no self-hosting today and no bring-your-own-vault. If that is a hard requirement, email support@anlyon.com and say why.

Free tier, no credit card. One command if you use Claude or Cursor.

$ claude mcp add anlyon -- npx -y @anlyonhq/mcp-server