Your gateway
Authenticate callers, route traffic, enforce rate limits, and observe API, LLM, or MCP requests.
Keep Kong, Envoy, an MCP gateway, or your existing edge.Execution authority behind your agent gateway
Keep the gateway that authenticates and routes your traffic. BoundRunner controls the consequential step: the exact action, deterministic policy, independent approval when needed, narrow credentials, safe execution, and a signed outcome receipt.
request / 8f42…c9a1production / payments-apiA different layer
BoundRunner is not a model router or another MCP catalog. It is the independent transaction boundary after intent and before a consequential provider mutation.
Authenticate callers, route traffic, enforce rate limits, and observe API, LLM, or MCP requests.
Keep Kong, Envoy, an MCP gateway, or your existing edge.Normalize the exact side effect, apply policy, collect independent approval, reduce authority, and settle the execution.
This is the consequential-action boundary.Receive only the action and ephemeral authority that survived the complete control path.
Repository, cluster, cloud, security tool, or internal API.The proof is one bound record: actor and deployment, normalized action hash, policy revision, approval, credential scope, idempotency state, provider outcome, and signed evidence.
One control path
Every transition stays bound to the same tenant, principal, agent deployment, action, resource, environment, and policy version.
Resolve the human, workload, agent, and deployed artifact.
Evaluate a normalized action through versioned deterministic policy.
Pause the exact high-impact action for an eligible independent reviewer.
Issue only the short-lived scope needed for the approved operation.
Seal the decision and execution into a signed, verifiable chain.
Deterministic outcomes
These are real decision classes exercised by the BoundRunner policy suite. Caller-supplied risk never becomes authority.
Review the security modelkubernetes.workload.deployProduction mutation requires an independent platform operator.
production-guardrails / v1.4.2The operating result
Let low-risk work continue automatically while production, privileged, and destructive actions hit explicit control points.
Broker reduced, short-lived authority only after identity, policy, and approval checks succeed.
Tie every attempted side effect to an actor, deployment, policy version, approval, credential grant, and signed evidence event.
Built for the systems agents touch
Paid action map
In 10 business days, we map one exact action, its trust boundaries, approval and credential path, failure tests, and a go/no-go production-pilot plan.