No agent acts without authority.

Intercis sits between your agent's code and the Anthropic and OpenAI APIs and deletes a denied tool call from the response before your runtime can run it.

An agent asked to run rm -rf /var/app/releases. It did not run.

Its base URL and 2 headers were the only change, and 1 of them, the key, is required. How it works, in full

Talk to the sales team

Your message goes to the sales team at sales@intercis.io. Nothing changes in your agents until you say so.

Sent. It goes to the sales team at sales@intercis.io. Nothing about your agents has changed.

Check the chain yourself, one minute Start a 90-day pilot Read what it costs you first

What it governs
Tool calls that cross the Anthropic and OpenAI API wire.
What a deny does
The tool_use block is taken out of the response. Your runtime receives text.
What it does not see
Tools the provider runs on its own servers, including hosted MCP calls.
What leaves our boundary
When no rule matches, the classifier call goes to the provider on our account, carrying the tool name and the whole tool input.
What happens if we are down
Your agents stop. One deployment, no second region and no replica, and nothing queues.
What that trade is
What it gets wrong
On our own traffic it flags 737 of 4,764 calls that were fine.
See how that was counted
What it costs
$200 a month for the first agent, $190 for each one after it.
What you can run today
The chain verifier, a sample chain and the database trigger are published. Recompute the hashes on your own machine.
The three files and the check

Other tools return a verdict. This one takes the action off the wire.

A verdict is advice. Intercis edits the response, so the tool call is gone before your runtime reads the message.

What the model returned

{ "role": "assistant",
  "content": [
    { "type": "text",
      "text": "Clearing old releases." },
    { "type": "tool_use",
      "name": "bash",
      "input": {
        "command": "rm -rf /var/app/releases"
      } }
  ] }

The agent runtime would have run this block. Abridged in both panes.

What your agent runtime received

{ "role": "assistant",
  "content": [
    { "type": "text",
      "text": "⛔ Intercis blocked this
  action.\nPolicy: shell-rm\nThis tool
  call was denied by your organisation's
  AI governance policy and has been
  logged for audit review." }
  ],
  "stop_reason": "end_turn",
  "stop_sequence": null }

The exact text the proxy writes, with your policy name in place of shell-rm. No tool call is left to run.

The row it writes

created_at
2026-09-12T14:07:52Z
agent_id
your-agent-id
target
rm -rf /var/app/releases
verdict
deny
policy
shell-rm
event_hash
sha256 over this row and the hash of the row before it

A worked example, not a capture.

It did not run, and the record says why.

Watch a denial happen in the demo lab, on a real agent

What it costs you

5 costs, published before you pay. We are in the path, and a compromised process can change its base URL, so pair us with an egress rule. We see only the LLM API wire, not tools the provider runs on its own servers. A stream is held until it is judged. We are a new trust boundary, and hosted only. A new provider route is our work first. 3 gaps follow: if we are unreachable your agents stop, the classifier fails open, and the audit log can have holes.

What Intercis does not cover

Each cost and gap, at length

Read the full case

For the engineer you forward this to: the request path step by step, the counts with the command beside each, the price, each cost and gap at length, how we compare, and the chain check you can run in a minute.

How it works, the full case