Ripcord sits between your AI agents and the real world. It risk-scores every action, holds the dangerous ones, snapshots the destructive ones, and keeps everything reversible for as long as physics allows.
The agents work: 99%+ of their actions are perfect. But nobody can answer "what if it's wrong once?", so companies pick between three bad doors: stall the rollout (62% have delayed deployments), leash every action, or fly blind (70% couldn't trace a failure). Every door caps the ROI with fear, not model quality.
Your agents keep their tools. Ripcord sits in the middle and decides, action by action, what runs instantly, what waits, and what stays undoable.
Every tool call gets a risk score with reasons a human can read, against baselines learned from your own history. Routine actions flow through with zero added friction.
Medium risk fails open: a countdown a human can stop. High risk fails closed: nothing runs without a decision, and silence means no.
Snapshots before destruction, rollback windows after, and compensating actions when undo isn't physics.
The reason goes back to the agent, and it fixes the problem and resubmits. Or take over: the task lands in your queue prefilled, the invoice open, the draft ready.
Some tasks shouldn't be agent-done at all. Take over hands you the work prefilled: the invoice open in your billing queue, the draft in your outbox. The agent did the prep; you do the last 5%.
Repeated approvals become standing rules so the asks get rarer. Dangerous patterns are unlearnable by design.
Every number the engine produces is derived, legible, and defensible. The same mathematics that prices credit, detects money laundering, and settles insurance claims, running on every agent action.
Signal weights are log-likelihood ratios on the credit-scoring convention: +15 points doubles the odds. Scores map to a calibrated P(flag), and every point stays a reason a human can argue with.
Decisions minimize expected loss, and severity is discounted by our own ability to undo: a snapshot-protected deletion tolerates 5× the risk of an irreversible wire. The thesis, as an equation.
Aggregates get scored, not just single actions. Five payments of $9,640 to one counterparty get caught as one $48,200: the structuring attack dies at payment two. Try it in the demo.
Rules are proposed when the Bayesian posterior clears the bar, not when a magic counter hits two. Next: SPRT-optimal hold durations, conformal release guarantees, EVT severity tails for underwriting.
Every deployment starts in shadow mode: Ripcord observes, gates nothing, and prices every near-miss in expected loss. At the end of week one you get the Near-Miss Report — the payments it would have held, the deletions it would have blocked, the dollars that never had to be at stake — before you've paid anything or changed a single workflow. Onboarding has exactly one metric: time to first save.
Ripcord's decisions run at the tool boundary, outside the model. No jailbreak, injection, or "ignore previous instructions" can talk its way past a gate that isn't listening.
Per-agent velocity across every corridor, not just payments. An agent stuck in a retry loop gets frozen at action twelve, not action four thousand: everything it submits after that fails closed until a human thaws it.
Credentials are injected per request at the gateway: agents never hold the real keys. An agent that never had the credentials can't route around the gate, and can't leak what it never saw.
Guardrails written into a system prompt are requests to a language model. Ripcord's gates execute in the proxy, regardless of what any model decides: the policy holds even when the agent doesn't.
"Undo everything" would be a lie. Every action class gets the strongest recovery verb physics allows, and you always know which one that is, before the agent acts. On live gateway tools, Ripcord issues the compensating call itself — the agent is never part of its own undo.
Best-model-for-the-task is the new normal: one lab's agent for research, another's for code, a third's for ops. Lab-native controls each govern only their own agents. Three dashboards isn't governance three times; it's governance zero times.
Ripcord sits at the tool-call layer beneath every framework and every vendor. Switch models as often as the leaderboard flips: your risk policies, approval flows, and audit history stay exactly where they are. The control plane outlives every model choice.
Insurers learn about risk from claims: paperwork filed after the disaster. A prevented mistake never generates a claim, so the most predictive signal in risk: the near-miss: is invisible to them. Ripcord stands in the doorway every action walks through, and keeps the whole ledger:
Ripcord is building the AIG of the AGI economy: the insurance carrier for autonomous work. The way in is the recovery engine on this page — because the gateway that catches every near-miss is also writing the first actuarial table for agent risk.
Per agent under management, never per action. A safety layer that charges by use invites selective safety, and selective safety is how the mistake happens in the one corridor you didn't cover.
That dialog assumes a human is watching one agent in a terminal, in real time. Ripcord assumes nobody is watching fifty agents overnight. Built-in prompts also pattern-match the tool, not the stakes: they can't say "new beneficiary, 4.7× the normal amount." And approval is where their safety story ends: no risk scoring, no snapshot, no rollback, no learning, no cross-vendor audit trail. The button is the same; everything around the button is the product.
Each lab's controls govern only its own agents, and best-model-for-the-task means your fleet runs several. Three half-controls with three audit formats isn't governance three times; it's governance zero times. Ripcord sits at the tool-call layer beneath every vendor: one policy, one inbox, one record. And when something goes wrong, an independent audit trail counts for more than the lab's own record of its own agent: nobody believes the referee who plays for one of the teams.
A card limit is a wall, and walls don't read invoices. Give your procurement agent a $50k card limit: reasonable, real invoices run that size, and the $48,200 payment to a fraudulent vendor sails through inside the limit. Crank the limit down and legitimate invoices start failing back to human tickets: the leash returns, enforced by the card. Cards also govern the wrong rail (B2B money moves by wire and ACH) and answer one line of a six-line problem: they're silent on deletions, mass emails, and rollback. We like agent cards: they're the containment primitive for one corridor, and Ripcord happily uses them as defense-in-depth. A card caps how big the mistake can be. Ripcord works on whether it happens at all, and what happens after.
Ask why your CFO still can't wire $10M alone. A senior CFO almost never fat-fingers a transfer, yet segregation of duties, two-person rules, and audit trails exist anyway, because controls are about accountability and adversaries, not competence. A perfect agent still perfectly executes a wrong instruction, a forged invoice, or an attacker's injected prompt, and even perfect actions get disputed. Firewalls and flight recorders grew as systems got safer, because safety enabled volume. What fades is catching incompetence; what grows is authorization, containment, and evidence.
It will happen: a risk engine that catches everything is an oracle, and security's founding axiom is assume breach. What changes with Ripcord is everything around the miss: the action went through the gateway, so forensics is one query instead of weeks of archaeology; the blast radius: everything the compromised agent touched: is instantly visible, and whatever's still inside a rollback or compensation window comes back; the agent freezes with one policy flip; and the attack pattern is folded into the engine: it scores 80 tomorrow — live today per customer, and for every customer as the network grows. The money that's still gone is what the insurance layer exists to absorb: a loss despite reasonable controls is the definition of an insurable event, and the audit trail is the claims file that settles it in days, not months. Prevent, contain, recover, absorb. No loss goes unpriced.
Today: a log-odds scorecard (the same math as FICO and insurance rating tables) with an expected-loss gate: Gate = P(flag) × $exposure × (1 − recoverability). Named signals with weights (new beneficiary +45, 4.7× the vendor's normal +35), summed, calibrated to a probability, and itemized: every point is a reason a human can argue with, never a black-box probability. After your first shadow week, the baselines are learned from your own history, so abnormal means abnormal for you, and velocity windows score aggregates across actions (five payments of $9,640 get caught as one $48k). At network scale, every human verdict becomes a training label, and one customer's caught pattern raises everyone's score tomorrow. One more thing no other risk engine does: severity is discounted by our own ability to undo. A snapshot-protected deletion can tolerate more uncertainty than an irreversible wire.
Only badly-designed approval systems drown people. Here, medium risk fails open: a hold you can stop, not a queue you must clear, and only the genuinely scary tier waits for a decision. Repeated approvals become standing rules so the same question never gets asked twice, while dangerous patterns are unlearnable by design. The system's job is making every ask rarer and richer, until the ones that remain deserve real attention.
The reason goes back to the agent as information, and the agent re-plans. "No W-9 on file" doesn't kill the payment: it sends the agent to get the W-9 and resubmit at lower risk. Rejection is feedback, not death: the task survives, the risk doesn't, and the gateway becomes a conversation between agent judgment and human authority instead of a wall. And when a task shouldn't be agent-done at all, Take over hands it to you prefilled: the invoice open in your billing queue, the draft in your outbox. Take over the same pattern twice and Ripcord proposes a standing route-to-human rule: risky patterns can't earn auto-approval, but they can earn a permanent human lane.
Plenty, and we say so before the agent acts. A sent email, an executed wire, a served notice: physics wins. That's why every action class gets the strongest verb available: snapshots and rollback where we control the state, escrow holds where we control the timing, and instant compensating actions where we control neither. "Undo everything" would be a lie; maximizing the time every action stays reversible is an engineering discipline.