Agent Assurance for AI Implementers · Triodian

For AI implementers, automation agencies, MSPs & MSSPs

“What stops the agent doing something it shouldn’t?”

The agent doesn’t hold the keys. Triodian does.

Your client’s security or risk reviewer is asking that question about the agent you are about to deploy into their business systems. Prompts, permissions and guardrails are the answer implementers give today. The Agent Action-Control Gateway gives the reviewer an independent control point instead: every consequential action passes through a policy check, nominated actions wait for a human, and every decision is recorded where the reviewer can verify it.

Book a 20-minute call → See the five-action run ↓

The control, in three lines

Allow

Permitted actions pass

The agent requests an action; the gateway checks it against the client’s policy and executes it with credentials the agent never sees.

Deny

Prohibited actions stop

Actions the policy prohibits are blocked before they reach the system, with the constraint named in the record.

Require human approval

Nominated actions wait

Actions above a threshold or in a nominated category are held in the approval console until a named person releases them.

One policy, written as the client would write it

Payment reminders under $5,000 pass. Reminders between $5,000 and $25,000 need a manager’s approval. Changing a customer’s bank details is prohibited, full stop.

The demo

Five actions from an autonomous accounts-receivable agent.

Four routine actions pass without anyone looking. One is blocked with the constraint named. One waits for a manager and proceeds once approved. The run ends on the evidence log, where every decision is chained to the one before it. This is the same run we do live on the call, so the page and the call never disagree.

Action log · ar-agent-01 · policy AR-v3 6 events · hash-chained
#Requested actionPolicy ruleDecisionRecord
01Send payment reminder · INV-20418 · $1,240AR-01 · reminders < $5,000Allowe3b0…9a2f
02Send payment reminder · INV-20431 · $3,860AR-01 · reminders < $5,000Allow9a2f…c41d
03Update contact email · Fairbridge Pty LtdAR-03 · contact fields, non-financialAllowc41d…7b08
04Change settlement account · Fairbridge Pty LtdAR-07 · automated agents cannot modify settlement account detailsBlocked7b08…1e6a
05Send payment reminder · INV-20402 · $18,500AR-02 · $5,000–$25,000 requires manager approvalHeld → approved by J. Nair, 09:421e6a…f53c
06Log call outcome · INV-20402AR-04 · notes and activityAllowf53c…2d91

Illustrative run. Each record carries the hash of the record before it, so a removed or altered entry breaks the chain and the reviewer can see that it did.

Already running in production

We built and operate pinpole.cloud, a production service where out-of-set commands are unemittable and every output carries a signed record. The gateway applies the same design to agent actions in your clients’ systems.

The question a partner asks itself before it asks us is could we just build this? The hard part, enforcement and evidence under production load, has already been shipped and run by the same two founders. You would be reselling it, not competing with it.

Why a partner deploys this rather than building it

Your client’s reviewer gets a control you didn’t write. You get a faster sign-off.

For the client’s reviewer

  • An independent control point between the agent and the system, operated by neither the agent’s builder nor its vendor.
  • Policy written in the client’s own terms: amount thresholds, prohibited actions, who approves what.
  • An evidence log the implementer did not write and cannot quietly edit.

For you

  • A credible answer to the security review that does not depend on the reviewer trusting your prompt engineering.
  • A billable assurance line inside every agent engagement, priced per end client.
  • Works with the agents you already build: Copilot Studio, Agentforce, Power Platform, n8n, Make, Zapier, LangChain, CrewAI, MCP-based and custom agents, acting in Microsoft 365, Dynamics, Salesforce, HubSpot, Xero, NetSuite, ServiceNow or SAP.

How to engage

Two ways in.

Start here

Agent Assurance Pilot

Fixed fee · 30 days

One agent, three tools, ten to twenty rules, the approval workflow and the action log, on a named client deployment. You leave with a working control point and a record your client’s reviewer can inspect.

Ongoing

Partner subscription

Per end client · monthly

Partner-priced per client, resold inside your managed service or agent engagement, with the policy, approval console and evidence log run for each client you deploy for.

What it is, and what it is not

The sheet you can hand to your client’s CISO.

We would rather you know exactly what the gateway claims before the reviewer asks. These are the claims we make and the ones we do not.

It does

  • Hold the credentials, so the agent acts only through the gateway.
  • Enforce explicit permissions and action boundaries set by the client.
  • Check policy before each consequential call.
  • Route nominated actions to a human for approval.
  • Block prohibited actions and name the constraint.
  • Keep tamper-evident, hash-chained records of every decision.

It does not

  • Claim to be non-bypassable.
  • Claim to be hardware-enforced.
  • Guarantee regulatory compliance.
  • Prevent every possible rogue action.
  • Prove the semantic correctness of what the agent decides.
  • Replace your client’s own security review; it gives that review something to verify.

Book a 20-minute call

Bring the person who fields your client’s security questions, and the deployment that is in review or about to be.