Two agents, one limit, one refused.

Anlyon Vigil

A second reader for every approval.

Vigil reviews the requests your policies send to a person. Reviewers get a risk level, a suggestion and the reasons behind it. Routine requests can be approved inside limits you set. Your policies still decide first.

Opt-in, off by default

01

Your policies decide first

Vigil only sees approvals a deterministic policy already routed to a person. It cannot loosen a policy, and with it off, approvals behave exactly as before.

02

A suggestion, not a decision

Risk in words, a confidence, and up to three reasons built from the review's numbers. No model-written text reaches a reviewer, and agents never see it.

03

Auto-approve inside your limits

A second, separate opt-in. Every rule you set has to hold, or the request goes to a person. Vigil never denies, and never counts as one of several approvers.

04

Policies from your own decisions

Requests your approvers approved 20 times in 30 days without a denial become ordinary policies you can accept, replayed against your history first.

  • Policies settle most requests

    Allowed runs, denied stops. Vigil never sees either. Only what a policy sends to a person goes on.

  • A second reader, with reasons

    A risk level in words, a suggestion, a confidence, and the checks behind them.

  • Approved inside your limits

    Every limit must hold for Vigil to approve. Otherwise it waits for a person, with the reason.

  • Same call, same credential

    Whoever approved, Anlyon sends the frozen request with the credential bound to the action.

A second reader, in the places you already decide.

In the inbox, and in the Slack, Discord or email notification for the approval, labelled as a suggestion every time.

Risk in words
Routine, low, moderate, high, critical. Never colour alone.
Templated reasons
Up to three, built from the review's numbers. No model-written text reaches a reviewer.
Only for people
Suggestions go to people signed in to the console. Agents calling with keys never receive them.

Every rule holds, or a person decides.

A second, separate opt-in. Pick a request and watch the checks Vigil runs before it may approve on its own. It never denies, and a sample of what it approves waits for a person to audit.

Example requests

support-bot

refund_order

Order #4412 arrived damaged. Customer sent a photo.

Vigil suggestion · not a decision

Approve · risk routine · 94% sure

  • · Consistent with 212 approved and 0 denied requests in 30 days
  • · Amount is below this action's median of $61
  • · No sign of injected instructions (0.02)

Auto-approve rules0/8

  • Action is on your auto-approve listnot checked yet
  • Needs exactly one approvernot checked yet
  • Environment is not haltednot checked yet
  • Suggests approve, confidence ≥ 0.90not checked yet
  • Risk at or below your limitnot checked yet
  • No sign of injected instructionsnot checked yet
  • 20+ approvals by approvers, no denialsnot checked yet
  • Amount at or below your $100 capnot checked yet
Checking your limits…

Enough to review a request. Nothing it could act on.

Choose which fields stay private. Vigil reviews the redacted request and destination host, without access to your secret values.

Sent for a review

  • Action name, method, and destination host
  • The request input, with sensitive-looking keys redacted and your excluded fields removed, truncated to about 8 KB
  • The amount, if the request has one
  • The matched policy's name and explanation
  • A 30-day summary for this agent and action: approvals, denials, median and largest amount

Never sent

  • The URL path and query, which can carry input
  • Secret values. Payloads hold {{secret:NAME}} templates, never values
  • Approver identities
  • Anything from workspaces that have not opted in

Your own decisions, turned into rules. No model on their path.

When approvers approved the same kind of request at least 20 times in 30 days with no denial, Vigil suggests an ordinary policy, replayed against your history first. Accept it, edit it, or delete it later.

Caps

At the review cap, approvals still reach people, without a suggestion. At the approval cap, requests go to a person.

Keep auto-approve lists short and limits tight, and read the audit queue. Rely on policies for anything that must never happen. With Vigil off, approvals behave exactly as before.

PlanReviews a monthVigil approvals a day
Early Beta Access1,000100
Free (after beta)25025
Production (planned)25,0001,000
Growth (planned)150,0005,000
EnterpriseCustomCustom

Free tier, no credit card. One command if you use Claude or Cursor.

$ claude mcp add anlyon -- npx -y @anlyonhq/mcp-server