None of this rests on an agent behaving well. It runs on a server that is yours, on keys that are yours, and the only actions it can take are the ones standing in a file you can read.
Last reviewed 26 August 2026
AI safety is not something we hand you finished. We harden the machine and the gate; you decide what the agent may touch. Both halves are written down, and both halves are checkable.
The gate reads the tool's own name. A name built on get, list, search, fetch or query reads, so it goes through. A name carrying one of twenty-eight words that mean change or send is refused. Anything the gate cannot place is refused too — that is the default, not the exception.
shopify.get_orderget
gmail.send_messagesend is one of the twenty-eight
shopify.list_productslist
gmail.delete_messagedelete is one of the twenty-eight
tracking.fetch_statusfetch
shopify.create_refundcreate and refund, both on the list
composio.execute_toolgmail.create_draftcreate and draft are both on the refuse list —
it runs only because a person put this one name in the file
A name has to carry one of these and none of the twenty-eight.
label and draft stand on this list, which is why the two actions the mail agent lives on had to be written down by name before they could run at all.
This is the mail agent's actual permission file during its learning period. Two actions may change something, both written out by name. Sending is not among them, so it cannot happen — not because the agent was told to behave, but because the name is not in the file.
{ "gmail": [ "GMAIL_FETCH_EMAILS", // reads "GMAIL_FETCH_MESSAGE_BY_MESSAGE_ID", // reads "GMAIL_LIST_LABELS", // reads "GMAIL_ADD_LABEL_TO_EMAIL", // changes something "GMAIL_CREATE_EMAIL_DRAFT" // changes something ], // The gate refuses every name above that changes or sends. // These two run only because they stand here, by name: "allowed_mutations": { "gmail": [ "GMAIL_CREATE_EMAIL_DRAFT", // write a reply as a draft "GMAIL_ADD_LABEL_TO_EMAIL" // put a label on a message ] } // Not here, and therefore refused before it runs: // GMAIL_SEND_EMAIL — sending anything at all // GMAIL_DELETE_MESSAGE — deleting or changing a message // everything else in the mailbox}
The build runs on its own instance, rented in your name, in a European data centre. Nothing else runs on it. Inside, the agent starts with inherited context switched off: what it knows arrives in four files and nothing else.
It picks up no house instructions and no settings lying around in the
environment — the runtime runs on settingSources: []. Four files, handed over
explicitly:
Nothing else comes with it. No shared prompt, no settings from our machines, no other business's file within reach.
The engine is the same for everyone; the fuel is yours. That is what makes the work portable — and what keeps one customer's configuration out of reach of every other machine.
Four parties, and that is the whole list:
The intake form on this site is a separate matter with its own answer, and it is on the privacy page.
A security page is worth reading only if the gaps are on it too:
A data processing agreement is signed before a single account is linked. The access list per agent is part of it: what it may read, the actions it may take by name, and what it can never do. If that list ever needs to grow, it grows the same way it was written — you see it, you agree to it, and it goes into version control.
Access is granted by you, from your own accounts, and withdrawn the same way. Your mailbox and your shop stay connected on permissions you issue and can pull back, which is what makes that sentence true rather than kind.
No sales pitch. The person who builds it, running the numbers on your operation.