Access: what does it need?
Give each agent its own identity and scoped access. Use governed integrations to add credentials without handing the agent your provider keys.
Scope access to the work →A human decision at the moment it matters
Give your agents room to work and a clear point to bring you in. Review the deployment, the purchase, or the message to a customer before that step proceeds.
Free for individuals. No card. Your first request executes nothing.
From your coding agent
The update is ready for your review. This request covers one deployment to production.
You review. The agent waits.
Before you give an agent more responsibility
Your team may work across different AI providers. Give each agent its own limits and bring the decisions into one shared history.
Give each agent its own identity and scoped access. Use governed integrations to add credentials without handing the agent your provider keys.
Scope access to the work →Define which tools, capabilities, and expenses are allowed. Route actions through an enforcing integration when the limit must be applied before execution.
Set boundaries for new capabilities →Review the exact recipient, message, deployment, or expense. Approve that request once, without changing the standing rules.
Review a message before it leaves →Inspect requests and decisions, track budgets, and revoke access. A decision record shows what was authorized; it does not prove an external action ran.
Keep a shared decision history →For the people responsible
Choose the moments that need a person. Connect the relevant workflow so the agent asks before taking that step.
Your coding agent is ready to deploy. Review the proposed release and destination before authorizing that step.
Explore this use case →An agent needs more API credits or a paid tool. Review the amount and purpose before approving the expense.
Explore this use case →The draft is ready. Review the exact message and recipients before your agent sends or publishes it.
Explore this use case →Give a contractor’s agent its own scoped seat, budget, and expiry date. Keep access tied to the assignment.
Explore this use case →Bring agents from different providers under shared approval rules, with separate agent identities and a shared decision history.
Explore this use case →These workflows require a connected agent or integration. Sanction does not automatically intercept your AI host’s other tools.
One request. One decision.
Approve the action in front of you without giving the agent blanket permission for whatever comes next.
What it wants to do, where, and with which inputs. A reason gives you context; the exact request defines what you approve.
Approve or reject in the approval inbox, or in Slack when configured. Organizational rules still apply; approval cannot bypass a hard denial.
The agent redeems an expiring, one-use permission before proceeding. A changed request, expired permission, or rejection means stop.
The release and destination are specified.
The agent requests a human decision.
Review the exact action and approve or reject it.
Redeem before expiry. A different action needs a new decision.
Illustrative workflow. Approval records permission; it does not prove the deployment ran.
Start with a harmless request. The connection guide walks you through a synthetic approval that executes nothing.
Try one approval →For agents working autonomously
Give an agent a way to ask for what it needs, respect a refusal, and continue with permission tied to its own identity.
Explore the agent wallet →Escalate an expense above the review threshold. Hard budget limits still deny it; a human approval does not raise them.
Ask before acquiring a skill, plugin, or integration. Authorization does not install it.
Redeem a one-use grant for the identical request. Changed arguments require a new decision.
Route supported calls through the broker or model gateway, which adds vaulted credentials on the server.
Give each agent its own key, scope, and budget so authorization stays attributable across tools.
Fits the way you work
Start with a cooperative approval connection. Add enforcement in the paths you control as your workflow grows.
Use the approvals connection to request and check decisions. The agent must consult Sanction and honor the response.
Connection guide & host test status →Route tool calls through the MCP broker, check actions in your application integration, or route model usage through the budget gateway. Enforcement covers those connected paths.
Explore the platform →See which agent requested an action and how it was authorized. The record evidences the decision; it does not prove an external action ran.
Read the documentation →Start with one approval
One safe request. A human decision. A clear next step.