No agent acts without authority.
Intercis sits between your agent's code and the Anthropic and OpenAI APIs and deletes a denied tool call from the response before your runtime can run it.
An agent asked to run rm -rf /var/app/releases.
It did not run.
Its base URL and 2 headers were the only change, and 1 of them, the key, is required. How it works, in full
Talk to the sales team
Your message goes to the sales team at sales@intercis.io. Nothing changes in your agents until you say so.
Sent. It goes to the sales team at sales@intercis.io. Nothing about your agents has changed.
That did not send. Email sales@intercis.io instead.
Check the chain yourself, one minute Start a 90-day pilot Read what it costs you first
- What it governs
- Tool calls that cross the Anthropic and OpenAI API wire.
- What a deny does
- The
tool_useblock is taken out of the response. Your runtime receives text. - What it does not see
- Tools the provider runs on its own servers, including hosted MCP calls.
- What leaves our boundary
- When no rule matches, the classifier call goes to the provider on our account, carrying the tool name and the whole tool input.
- What happens if we are down
-
Your agents stop. One deployment, no second region and no replica, and nothing queues.
What that trade is - What it gets wrong
-
On our own traffic it flags 737 of 4,764 calls that were fine.
See how that was counted - What it costs
- $200 a month for the first agent, $190 for each one after it.
- What you can run today
-
The chain verifier, a sample chain and the database trigger are published.
Recompute the hashes on your own machine.
The three files and the check
Other tools return a verdict. This one takes the action off the wire.
A verdict is advice. Intercis edits the response, so the tool call is gone before your runtime reads the message.
What the model returned
{ "role": "assistant",
"content": [
{ "type": "text",
"text": "Clearing old releases." },
{ "type": "tool_use",
"name": "bash",
"input": {
"command": "rm -rf /var/app/releases"
} }
] }
The agent runtime would have run this block. Abridged in both panes.
What your agent runtime received
{ "role": "assistant",
"content": [
{ "type": "text",
"text": "⛔ Intercis blocked this
action.\nPolicy: shell-rm\nThis tool
call was denied by your organisation's
AI governance policy and has been
logged for audit review." }
],
"stop_reason": "end_turn",
"stop_sequence": null }
The exact text the proxy writes, with your policy name in place of
shell-rm. No tool call is left to run.
The row it writes
- created_at
- 2026-09-12T14:07:52Z
- agent_id
- your-agent-id
- target
- rm -rf /var/app/releases
- verdict
- deny
- policy
- shell-rm
- event_hash
- sha256 over this row and the hash of the row before it
A worked example, not a capture.
It did not run, and the record says why.
What it costs you
5 costs, published before you pay. We are in the path, and a compromised process can change its base URL, so pair us with an egress rule. We see only the LLM API wire, not tools the provider runs on its own servers. A stream is held until it is judged. We are a new trust boundary, and hosted only. A new provider route is our work first. 3 gaps follow: if we are unreachable your agents stop, the classifier fails open, and the audit log can have holes.
Read the full case
For the engineer you forward this to: the request path step by step, the counts with the command beside each, the price, each cost and gap at length, how we compare, and the chain check you can run in a minute.