Skip to contentAitium

Platform / Agent runtime with guardrails

In development

Run agents with
enforceable boundaries.

Foxtail Harness sits between your agents and the tools they touch. It sets what each agent may reach, caps what it may spend, and reviews what it did — before anything breaks.

Where it sits

Between your agents and your systems

Agent

The AI agent doing the work — yours, from any framework.

Foxtail Harness

Policy, budget, review, and audit. Every request passes through; nothing reaches your systems unchecked.

Your systems

Tools, data, spend, and actions. Reached only through the harness, inside the limits you set.

Why it exists

Problems we are solving

Agents touch tools and data they were never meant to reach.

Every tool call passes through a registry. If the tool isn't registered with an active grant, the call doesn't run.

A runaway agent burns budget with nothing stopping it.

Spend is reserved before work starts. When the budget runs out, the run stops — not after the invoice arrives.

An agent reports 'done' and you can't verify it.

A reviewer checks the result after the run. A blocking finding stops approval.

When something goes wrong, there's no record of what the agent did.

Every decision is logged: what ran, what was decided, and why. Reconstruct any run.

Failed runs leak budget reservations.

Reservations roll back automatically when a run fails. Nothing leaks, nothing falsely exhausts.

Context bleeds across sessions.

Sessions are isolated. An agent sees only what its own session is allowed to see.

Revoking access mid-run leaves a window open.

Revocation takes effect at the next enforcement point. No gap between 'revoked' and 'stopped'.

How it works

Five controls, always on

Tool registry

Every tool is registered with an explicit grant before an agent can call it.

Agents can't reach tools you never approved.

Delegation scopes

Work runs inside a scope that defines what's allowed. Finished or denied scopes stay closed.

An agent's reach is bounded, and the boundary can't be reopened.

Budgets

Spend is reserved up front, settled on completion, rolled back on failure.

A runaway loop becomes a stopped run, not a surprise bill.

Review gates

High-risk actions pause for approval — by a person or by policy — before they commit.

Agents can prepare work without silently executing it.

Audit trail

The policy decision, budget state, reviewer, action, and result are recorded for every run.

Any incident can be reconstructed from the runtime record.

One request, end to end

What happens when an agent acts

  1. Agent requests

    The agent asks to call a tool with specific arguments.

  2. Policy checks

    The registry confirms the tool and grant; the scope confirms the agent may reach it.

  3. Budget reserves

    The expected spend is reserved. No reservation, no execution.

  4. Review gates

    High-risk actions pause for approval before they commit.

  5. Action executes

    The tool runs inside its scope and budget.

  6. Audit records

    The decision, spend, reviewer, and result are written to the trail.

Design guarantees

What the runtime promises

Fail-closed defaults

Doubt means no. Denied by default.

Atomic budgets

Reserved, settled, or rolled back. Never leaked.

Full audit trail

Every governed decision recorded.

Framework-agnostic

Works with agents from any framework.

Run agents with enforceable boundaries.

Request access to run your agents behind Foxtail Harness.

The platform that serves our models and governs agents.