Agents touch tools and data they were never meant to reach.
Every tool call passes through a registry. If the tool isn't registered with an active grant, the call doesn't run.
Foxtail Harness sits between your agents and the tools they touch. It sets what each agent may reach, caps what it may spend, and reviews what it did — before anything breaks.
Where it sits
The AI agent doing the work — yours, from any framework.
Policy, budget, review, and audit. Every request passes through; nothing reaches your systems unchecked.
Tools, data, spend, and actions. Reached only through the harness, inside the limits you set.
Why it exists
Every tool call passes through a registry. If the tool isn't registered with an active grant, the call doesn't run.
Spend is reserved before work starts. When the budget runs out, the run stops — not after the invoice arrives.
A reviewer checks the result after the run. A blocking finding stops approval.
Every decision is logged: what ran, what was decided, and why. Reconstruct any run.
Reservations roll back automatically when a run fails. Nothing leaks, nothing falsely exhausts.
Sessions are isolated. An agent sees only what its own session is allowed to see.
Revocation takes effect at the next enforcement point. No gap between 'revoked' and 'stopped'.
How it works
Every tool is registered with an explicit grant before an agent can call it.
Agents can't reach tools you never approved.
Work runs inside a scope that defines what's allowed. Finished or denied scopes stay closed.
An agent's reach is bounded, and the boundary can't be reopened.
Spend is reserved up front, settled on completion, rolled back on failure.
A runaway loop becomes a stopped run, not a surprise bill.
High-risk actions pause for approval — by a person or by policy — before they commit.
Agents can prepare work without silently executing it.
The policy decision, budget state, reviewer, action, and result are recorded for every run.
Any incident can be reconstructed from the runtime record.
One request, end to end
The agent asks to call a tool with specific arguments.
The registry confirms the tool and grant; the scope confirms the agent may reach it.
The expected spend is reserved. No reservation, no execution.
High-risk actions pause for approval before they commit.
The tool runs inside its scope and budget.
The decision, spend, reviewer, and result are written to the trail.
Design guarantees
Doubt means no. Denied by default.
Reserved, settled, or rolled back. Never leaked.
Every governed decision recorded.
Works with agents from any framework.
Request access to run your agents behind Foxtail Harness.
The platform that serves our models and governs agents.