Protect
Autonomy is only comfortable inside a boundary. You set the guardrails once, and the agent moves fast inside them while the spend, the deletes, and the blast radius stay exactly where you put them.
Guardrails you set once
What holds while it moves
Your project sits sealed at the center. Around it, four guardrails hold: one budget, your sign-off on anything destructive, isolation from every other project, and backups it can be brought back from. The agent can move all it likes. It cannot move the boundary.
The agent can approve a lot. It cannot approve its own deletes.
Schematic. Every guardrail shown here runs today.
Spend cap
Set one monthly budget. When you reach it, new scaling waits for your go, and nothing already running gets killed.
Human sign-off
Destructive actions need your explicit yes. The agent can't approve its own deletes.
Backups and restore
Scheduled backups, three restore modes, and an automatic safety snapshot taken before every restore.
Isolation per project
Every project runs walled off from the next, with its own secrets and its own backups.
Encrypted secrets
Secrets are encrypted before they ever leave your machine, and stay that way at rest.
Nothing to babysit
You are not watching a console. The guardrails do the holding, so autonomy does not cost you your evenings.
Contained by design
The agent moves fast. The blast radius doesn't move at all.
Speed and safety usually trade against each other. Here they don't: the agent is free precisely because the edges are fixed. A budget that holds, a delete that waits for you, a project that can't reach into another, and a backup to fall back on. That is what makes leaving it to run feel fine.
A 20-minute demo: set a spend cap and a sign-off rule, then watch the agent respect both.