The recovery engine for AI agents

Let your agents act.
Take it back when they shouldn't have.

Ripcord sits between your AI agents and the real world. It risk-scores every action, holds the dangerous ones, snapshots the destructive ones, and keeps everything reversible for as long as physics allows.

Working prototype: watch it stop a $48,200 mistake, then watch the agent come back with the W-9.
Gate today. Insure tomorrow: every gated action builds the first actuarial table for agent risk  ↓
Ripcord · action control● live
Pay Meridian Consulting LLC $48,200
ProcurementBot v4.1 · payments.transfer
risk 65
  • New beneficiary: agent has never paid this vendor
  • Amount is 4.7× this vendor category's normal payment
⛔ Fail-closed: auto-rejects in 1:21 without a human decision
Delete 4,382 records: snapshot created
Executed · rollback window open 23h 58m
Rolled back: 4,382 records restored
79%
of enterprises have already had to reverse an action taken by an AI agent
Kore.ai Agent Productivity Index, Jun 2026
62%
delayed agent deployments over governance worries. The problem isn't just losses, it's trapped ROI
Kore.ai Agent Productivity Index, Jun 2026
1,000
mistakes a month from a fleet that's 99.9% accurate and runs 1M actions: 33 every day, and one of them is a wire transfer
autonomy is gated by reversibility, not intelligence
The status quo

Everyone bought autonomy. Everyone is paying for supervision.

The agents work: 99%+ of their actions are perfect. But nobody can answer "what if it's wrong once?", so companies pick between three bad doors: stall the rollout (62% have delayed deployments), leash every action, or fly blind (70% couldn't trace a failure). Every door caps the ROI with fear, not model quality.

Today: the leash

  • The payments agent drafts: a human clicks send on every single one
  • The data agent proposes: someone executes it from a ticket, later
  • A mistake surfaces days late, via a complaint or a reconciliation
  • Forensics by archaeology across five log systems
  • Undo by hand: call the bank, restore the backup, apologize
  • Response: permissions amputated, leash shortened, ROI gone
The fear tax: every routine approval burns the labor the agent was meant to save.

With Ripcord: the dial

  • The routine 95% executes instantly, no human touches it
  • The unusual gets a 45-second hold: one glance, one tap
  • The dangerous waits, fail-closed, for a real decision
  • A rejection teaches the agent: it fixes the problem and resubmits
  • Wrong anyway? Snapshot rollback in milliseconds, not weekends
  • Every event in one audit trail: every approval makes the rules smarter
Trust becomes a dial, not a leap, and the dial only turns up.
One irreversible mistake used to cost a weekend, a vendor relationship, and the agent's permissions forever. Now it costs one click.
How it works

Everything you need to give agents real authority, safely

Your agents keep their tools. Ripcord sits in the middle and decides, action by action, what runs instantly, what waits, and what stays undoable.

Score every action

Every tool call gets a risk score with reasons a human can read, against baselines learned from your own history. Routine actions flow through with zero added friction.

Hold the dangerous ones

Medium risk fails open: a countdown a human can stop. High risk fails closed: nothing runs without a decision, and silence means no.

Reverse the rest

Snapshots before destruction, rollback windows after, and compensating actions when undo isn't physics.

Rejection is feedback

The reason goes back to the agent, and it fixes the problem and resubmits. Or take over: the task lands in your queue prefilled, the invoice open, the draft ready.

Or take it over

Some tasks shouldn't be agent-done at all. Take over hands you the work prefilled: the invoice open in your billing queue, the draft in your outbox. The agent did the prep; you do the last 5%.

It learns your judgment

Repeated approvals become standing rules so the asks get rarer. Dangerous patterns are unlearnable by design.

Pay Acme Supplies $1,200 (routine)risk 0 · ran
Email 2,000 customers "refund approved"risk 80 · blocked
Delete 4,382 customer recordsrisk 70 · snapshot
Send pricing proposal to one CFO20s unsend
$ ripcord hold #4821: payments.transfer $48,200
⏳ held 45s · notified: [email protected]
✓ approved by human at 00:31 remaining
$ ripcord fail-closed #4822: db.deleteRecords
✗ expired unapproved: silence means no
✓ audit trail: every step, timestamped
customers tablesnapshot · 24h window
$48,200 → Meridian LLCcompensation ready
Email to [email protected]unsent at 0:12
4,382 deleted recordsrestored ⟲
✗ rejected: Pay Meridian LLC $48,200 · risk 65
HUMAN FEEDBACK → "No W-9 on file, verify the vendor first."
◌ agent re-planning: requesting W-9, verifying banking details…
↩ resubmitted: vendor now verified · risk 65 → 20
✓ approved & executed: same task, done right
⤴ or take over: the invoice opens in your queue, prefilled
⤴ taken over: Pay Meridian LLC $48,200 · risk 65
Invoice opened in your billing queue, prefilled: $48,200 to Meridian Consulting LLC
Open invoice in your queue↗ prefilled
⤴ Always route new-vendor payments to a humanroute rule learned
💡 You've approved this pattern : payments to W-9-verified vendors. Create a standing rule so it stops asking?
⚡ Auto-approve W-9-verified vendor paymentsrule active
Pay Meridian LLC $48,200 (verified)auto-approved
Auto-approve unverified new vendorsunlearnable
The math

Auditable math, not vibes

Every number the engine produces is derived, legible, and defensible. The same mathematics that prices credit, detects money laundering, and settles insurance claims, running on every agent action.

points = ln P(x|bad)/P(x|good)

Log-odds scorecard

Signal weights are log-likelihood ratios on the credit-scoring convention: +15 points doubles the odds. Scores map to a calibrated P(flag), and every point stays a reason a human can argue with.

lineage: FICO, actuarial rating tables
Gate = P × $exposure × (1 − recoverability)

Expected-loss gating

Decisions minimize expected loss, and severity is discounted by our own ability to undo: a snapshot-protected deletion tolerates 5× the risk of an irreversible wire. The thesis, as an equation.

lineage: Bayesian decision theory
Σ flows(24h) > h ⇒ escalate

CUSUM velocity windows

Aggregates get scored, not just single actions. Five payments of $9,640 to one counterparty get caught as one $48,200: the structuring attack dies at payment two. Try it in the demo.

lineage: control charts, AML structuring detection
Beta(a,r) → P(approve) posterior

Principled rule learning

Rules are proposed when the Bayesian posterior clears the bar, not when a magic counter hits two. Next: SPRT-optimal hold durations, conformal release guarantees, EVT severity tails for underwriting.

lineage: Wald, conformal prediction, extreme value theory
Week one

First, we show you what we would have caught

Every deployment starts in shadow mode: Ripcord observes, gates nothing, and prices every near-miss in expected loss. At the end of week one you get the Near-Miss Report — the payments it would have held, the deletions it would have blocked, the dollars that never had to be at stake — before you've paid anything or changed a single workflow. Onboarding has exactly one metric: time to first save.

Enforcement

Prompts are suggestions. The gateway is physics.

Ripcord's decisions run at the tool boundary, outside the model. No jailbreak, injection, or "ignore previous instructions" can talk its way past a gate that isn't listening.

rate(agent, 60s) > h ⇒ freeze

Runaway tripwires

Per-agent velocity across every corridor, not just payments. An agent stuck in a retry loop gets frozen at action twelve, not action four thousand: everything it submits after that fails closed until a human thaws it.

same CUSUM family as the structuring detector
secrets ∉ agent

Keys stay home

Credentials are injected per request at the gateway: agents never hold the real keys. An agent that never had the credentials can't route around the gate, and can't leak what it never saw.

the credential chokepoint: what makes a gateway unbypassable
enforcement ∉ prompt

Outside the model

Guardrails written into a system prompt are requests to a language model. Ripcord's gates execute in the proxy, regardless of what any model decides: the policy holds even when the agent doesn't.

defense that survives the smartest attacker: indifference
Coverage

Honest about what can be undone

"Undo everything" would be a lie. Every action class gets the strongest recovery verb physics allows, and you always know which one that is, before the agent acts. On live gateway tools, Ripcord issues the compensating call itself — the agent is never part of its own undo.

ClassActionWhat Ripcord does
ReversibleDatabase writes & deletionsAutomatic snapshot before execution, one-click rollback inside the window.
ReversibleFile & config changesThe same snapshot primitive as database writes: versioned before execution, restored inside the window.
DelayableOutbound email & messagesUnsend window before anything leaves the building.
DelayablePublishing & mass communicationEscrow hold for high-reach sends, then released in batches: stoppable at email #50, not #2,000.
CompensablePayments & transfersHold first; after execution, instant ledger reversal + recovery request.
CompensableCommitments & agreementsCorrection and withdrawal actions issued automatically, with full context.
Neutral by design

Your agents come from every lab. Your safety layer can't pick a side.

Best-model-for-the-task is the new normal: one lab's agent for research, another's for code, a third's for ops. Lab-native controls each govern only their own agents. Three dashboards isn't governance three times; it's governance zero times.

AGENTS · ANY LAB Claude Code Codex Cursor LangChain any MCP agent no keys, ever RIPCORD ACTION GATEWAY SCORE GATE UNDO LEARN keys injected per request · approvals routed to owners MONEY · COMPENSABLE wires · ACH Ramp · Bill Stripe DATA · REVERSIBLE Postgres Snowflake MongoDB COMMS · DELAYABLE Slack Gmail Teams PUBLIC · EXTERNAL X · social LinkedIn CMS · blog undo · rollback · compensation · regret windows · "rejected because…" → agents re-plan THE NEAR-MISS LEDGER every action · every near-miss · every verdict = the first actuarial table for agent risk

One policy. One inbox. One record.

Ripcord sits at the tool-call layer beneath every framework and every vendor. Switch models as often as the leaderboard flips: your risk policies, approval flows, and audit history stay exactly where they are. The control plane outlives every model choice.

One policy across every vendor and framework
One approval inbox, one immutable audit trail — append-only and hash-chained
Swap models without touching your safety config
ResearchBot: running on Claudegated
RefactorBot: running on Codexgated
OpsBot: running on Kimigated
Same policy · same inbox · same audit trailone ripcord
"Nobody believes the referee who plays for one of the teams."
Observability went multi-cloud: Datadog beat CloudWatch. Identity went cross-SaaS · Okta beat the natives. Agent governance goes cross-lab.
Who decides

Approvals route to the action's owner, not the agent's.

An intern can launch the procurement bot. The $48,200 approval still lands with your AP manager. Authority follows your org chart, imported from your identity provider, and it's enforced: below your tier, the approve button doesn't exist.

Roles, like the rest of your stack

Super admins set policy and approve standing rules. Corridor admins decide their lane: payments, data, comms. Operators watch, nudge, and escalate. Auditors read everything and touch nothing. One click sends any decision up the chain, and the clock resets so escalation never means expiry.

Action-owner routing: payments → AP manager, data → platform lead, email → support lead
SSO & SCIM: leavers auto-reroute, vacations delegate, two-person rules at the top tier
Learned routing: repeated takeovers become route-to-human rules for that pattern
Pay Meridian LLC $48,200 · risk 65fail-closed
⤴ routed to Sarah Kim · AP Managerright owner
Viewing as Jordan (Operator): approve is disabledNudge · Escalate ↑
Escalated → David Chen (CFO), approval clock resetlogged
Rubber-stamping dies when the only thumb that can approve owns the consequence.
Try it live in the demo: the "viewing as" switcher shows the same stream as a super admin, a corridor admin, an operator, and an auditor.
Why it compounds

Every near-miss makes the next one cheaper

"An insurer is a coroner. Ripcord is the family doctor."

Insurers learn about risk from claims: paperwork filed after the disaster. A prevented mistake never generates a claim, so the most predictive signal in risk: the near-miss: is invisible to them. Ripcord stands in the doorway every action walks through, and keeps the whole ledger:

10,000,000 actions gated: the denominator no insurer has
180,000 blocked before anything happened
70,000 rolled back: mistakes caught in time
2,000 became real losses: the only line an insurer ever sees
Their dataset is the last line. Ours is the whole ledger, and this month's near-miss rate predicts next quarter's losses. Every other road to agent insurance rents both the balance sheet and the data. Ripcord rents only the paper: the table is generated by the product itself.
01Observe , every consequential action, gated
02Prevent , holds & rollbacks catch the near-misses
03Predict , the near-miss dataset trains the risk engine
04Underwrite , residual risk, priced by whoever sees the most
PHASE 1 · TODAYThe "Ripcord Certified" risk report: exportable proof of your controls and near-miss rates, formatted for your insurer.
PHASE 2 · THE COALITION MOTIONCarrier partnerships: gated fleets earn premium discounts. The gateway pays for itself before the first mistake.
PHASE 3 · THE LONG GAMEUnderwrite the residual risk ourselves: priced from the only dataset that sees every action, not just the losses.
WHERE THIS GOES

Every AGI needs an AIG.

Ripcord is building the AIG of the AGI economy: the insurance carrier for autonomous work. The way in is the recovery engine on this page — because the gateway that catches every near-miss is also writing the first actuarial table for agent risk.

Pricing

Priced so you gate everything

Per agent under management, never per action. A safety layer that charges by use invites selective safety, and selective safety is how the mistake happens in the one corridor you didn't cover.

Free
$0
1 agent, forever: for the developer who wants to feel it
  • Full risk engine, all six verbs
  • Holds, snapshots, rollback & compensation
  • 7-day audit history
  • Community support
Start free
Business
$79 /agent/mo · min $1,500
Growing fleets: cheaper per agent as you gate more
  • Policy-as-code & custom risk models
  • SSO, roles & two-person rules
  • 1-year immutable audit, compliance exports
  • Priority support
Talk to us
Enterprise
Custom
Self-hosted, regulated, insured
  • "Ripcord Certified" risk report: take it to your insurer
  • Self-hosted gateway & custom escalation
  • Unlimited audit retention
  • SLAs & dedicated support
Get a quote
One caught $48,200 mistake pays for 40 agent-years of gating.
79% of enterprises have already eaten an agent mistake (Kore.ai, 2026). The only question is whether Ripcord was in the path when it happened.
Objections, welcomed

The questions skeptics ask

Isn't this just the approve/deny prompt Claude Code already has?

That dialog assumes a human is watching one agent in a terminal, in real time. Ripcord assumes nobody is watching fifty agents overnight. Built-in prompts also pattern-match the tool, not the stakes: they can't say "new beneficiary, 4.7× the normal amount." And approval is where their safety story ends: no risk scoring, no snapshot, no rollback, no learning, no cross-vendor audit trail. The button is the same; everything around the button is the product.

My agents come from different labs. Doesn't each lab handle this?

Each lab's controls govern only its own agents, and best-model-for-the-task means your fleet runs several. Three half-controls with three audit formats isn't governance three times; it's governance zero times. Ripcord sits at the tool-call layer beneath every vendor: one policy, one inbox, one record. And when something goes wrong, an independent audit trail counts for more than the lab's own record of its own agent: nobody believes the referee who plays for one of the teams.

Don't agent debit cards already solve the payments part?

A card limit is a wall, and walls don't read invoices. Give your procurement agent a $50k card limit: reasonable, real invoices run that size, and the $48,200 payment to a fraudulent vendor sails through inside the limit. Crank the limit down and legitimate invoices start failing back to human tickets: the leash returns, enforced by the card. Cards also govern the wrong rail (B2B money moves by wire and ACH) and answer one line of a six-line problem: they're silent on deletions, mass emails, and rollback. We like agent cards: they're the containment primitive for one corridor, and Ripcord happily uses them as defense-in-depth. A card caps how big the mistake can be. Ripcord works on whether it happens at all, and what happens after.

What happens in three years, when agents stop making mistakes?

Ask why your CFO still can't wire $10M alone. A senior CFO almost never fat-fingers a transfer, yet segregation of duties, two-person rules, and audit trails exist anyway, because controls are about accountability and adversaries, not competence. A perfect agent still perfectly executes a wrong instruction, a forged invoice, or an attacker's injected prompt, and even perfect actions get disputed. Firewalls and flight recorders grew as systems got safer, because safety enabled volume. What fades is catching incompetence; what grows is authorization, containment, and evidence.

What happens when a sophisticated attack fools the risk engine?

It will happen: a risk engine that catches everything is an oracle, and security's founding axiom is assume breach. What changes with Ripcord is everything around the miss: the action went through the gateway, so forensics is one query instead of weeks of archaeology; the blast radius: everything the compromised agent touched: is instantly visible, and whatever's still inside a rollback or compensation window comes back; the agent freezes with one policy flip; and the attack pattern is folded into the engine: it scores 80 tomorrow — live today per customer, and for every customer as the network grows. The money that's still gone is what the insurance layer exists to absorb: a loss despite reasonable controls is the definition of an insurable event, and the audit trail is the claims file that settles it in days, not months. Prevent, contain, recover, absorb. No loss goes unpriced.

How do you actually calculate the risk score?

Today: a log-odds scorecard (the same math as FICO and insurance rating tables) with an expected-loss gate: Gate = P(flag) × $exposure × (1 − recoverability). Named signals with weights (new beneficiary +45, 4.7× the vendor's normal +35), summed, calibrated to a probability, and itemized: every point is a reason a human can argue with, never a black-box probability. After your first shadow week, the baselines are learned from your own history, so abnormal means abnormal for you, and velocity windows score aggregates across actions (five payments of $9,640 get caught as one $48k). At network scale, every human verdict becomes a training label, and one customer's caught pattern raises everyone's score tomorrow. One more thing no other risk engine does: severity is discounted by our own ability to undo. A snapshot-protected deletion can tolerate more uncertainty than an irreversible wire.

Won't humans just end up rubber-stamping everything?

Only badly-designed approval systems drown people. Here, medium risk fails open: a hold you can stop, not a queue you must clear, and only the genuinely scary tier waits for a decision. Repeated approvals become standing rules so the same question never gets asked twice, while dangerous patterns are unlearnable by design. The system's job is making every ask rarer and richer, until the ones that remain deserve real attention.

What happens when a human rejects an action?

The reason goes back to the agent as information, and the agent re-plans. "No W-9 on file" doesn't kill the payment: it sends the agent to get the W-9 and resubmit at lower risk. Rejection is feedback, not death: the task survives, the risk doesn't, and the gateway becomes a conversation between agent judgment and human authority instead of a wall. And when a task shouldn't be agent-done at all, Take over hands it to you prefilled: the invoice open in your billing queue, the draft in your outbox. Take over the same pattern twice and Ripcord proposes a standing route-to-human rule: risky patterns can't earn auto-approval, but they can earn a permanent human lane.

What genuinely can't be undone?

Plenty, and we say so before the agent acts. A sent email, an executed wire, a served notice: physics wins. That's why every action class gets the strongest verb available: snapshots and rollback where we control the state, escrow holds where we control the timing, and instant compensating actions where we control neither. "Undo everything" would be a lie; maximizing the time every action stays reversible is an engineering discipline.

It's time to pull the ripcord

Watch it stop a $48,200 mistake, roll back 4,382 deleted records, and unsend an email: live, right now.

Open the live demo →