Capability, policy, shield, budget, audit — in that order — on every tool call, every payment, every write, before it happens.
Every action passes through this gate before it runs. An agent cannot do anything Maverick didn't watch and record.
The runtime that runs and governs the work. It holds without the shield, never requires it.
Inspects each action for the dangerous call and the prompt injection before it clears the gate.
How work comes in and goes out — the governed surface between agents and your systems.
Inboxes and sign-off. Where a person reviews, certifies, and releases what an agent produced.
An MCP server. Run Maverick from Claude Code, Cursor, or any MCP client.
The closed, audited loop that lets the workforce improve — and prove it.
Memory scoped per department, plus fleet memory that governs external agents.
Attenuate-only. An agent narrows its rights to the task in front of it — and can never widen them.
Allow, deny, or require a human — bound to every action, not bolted on after the fact.
A successful prompt injection still can't move data out. There is no required path off your environment.
Tamper-evident and verifiable offline. Each entry signs the one before it — alter a row and the chain breaks.
Hard budget caps on tokens, dollars, wall-clock, and tool calls. The sandbox runs network-off by default.
A closed, audited loop: offline consolidation (“dreaming”), hindsight, and proof, with per-department memory feeding a causal flywheel. Every causal claim survives a placebo test before it changes behavior, and every change is reversible — snapshot and rollback.
Run domains-lint yourself.
A live golden path refuses the dangerous action and leaves a receipt for every decision. One command signs an offline-verifiable evidence bundle.
A goal's result renders as a typed deliverable, routes to a per-role inbox, and waits for a human to certify it — then routes into Salesforce or ServiceNow, signed and audited.
Self-host or air-gap, on your data. 8 PyPI packages · Docker, K8s, or VPS · MCP server · GitHub Action · plugin SDK · native installers.
We're working with a small number of design partners in regulated industries. If that's you, let's scope one workflow.