Control plane for high-impact agent actions

Give agents autonomy.
Keep execution governed.

VetoLayer sits between an AI agent and the tools that can change production, move money, or affect customers. Hard policy runs deterministically. SERV handles contextual judgment. Humans resolve what remains uncertain. Every result is auditable.

01 Hard policy first02 Context only when needed03 Human review without overrides04 Receipt for every verdict
Product walkthrough · example data
Final outcome

Execution is waiting on one condition.

REVIEW
✓
Required CI passed

All three required checks are verified.

Rule
✓
Emergency exception is plausible

SERV matched the incident context to the documented exception.

SERV
!
Security approval is unresolved

The exception cannot complete until current human approval exists.

Evidence

The missing control layer

Access control asks whether an agent can act.
VetoLayer decides whether it should.

Credentials and permissions are necessary, but they do not understand why an action is happening now, whether required evidence is current, whether a policy exception actually applies, or what remains unresolved. VetoLayer makes that judgment explicit before execution.

Product

A control surface, not another agent framework.

Keep your existing agents and tools. Add a decision boundary in front of actions that deserve policy, evidence, contextual reasoning, or human judgment.

01

Policy Studio

Write hard deterministic controls and contextual policies without turning every rule into an LLM prompt.

02

Human Review

Route unresolved actions to people, capture their judgment as evidence, and re-run the full gate instead of overriding it.

03

Decision Receipts

Inspect policy findings, evidence, SERV traces, unresolved conditions, versions, timestamps, and a SHA-256 integrity marker.

04

Integration boundary

Put VetoLayer in front of GitHub or any server-side tool call without replacing the agent framework you already use.

Decision path

Every action takes the same explainable route.

Deterministic policy remains authoritative. SERV is invoked only where policy interpretation needs context. REVIEW is a first-class state, not a provider failure.

01

Proposed action

An agent asks to merge, deploy, refund, purchase, change permissions, or call another high-impact tool.

02

Deterministic policy

Hard rules verify permissions, thresholds, protected environments, required evidence, and explicit denies.

03

Contextual judgment

Only genuine ambiguity, evidence conflict, and documented exceptions are routed to SERV Reasoning.

04

Execution verdict

ALLOW, REVIEW, or BLOCK returns with an auditable Decision Receipt and requirements for changing the outcome.

Use cases

Start where a wrong action is expensive.

VetoLayer starts with coding and deployment agents, but its decision contract is intentionally horizontal: action, policy, evidence, judgment, verdict, receipt.

01

Developer agents

Gate pull-request merges, production deploys, infrastructure changes, protected configuration, and security-sensitive actions.

02

Customer operations

Control refunds, credits, cancellations, account changes, and exceptions where evidence and policy context matter.

03

Finance & procurement

Evaluate payments, invoices, vendor changes, approvals, and unusual transaction context before money moves.

Developers

Put one guard in front of the tool call.

Use the lightweight TypeScript SDK or call the evaluation API directly. Your agent proposes an action; VetoLayer evaluates it; your code executes only on ALLOW.

POST /api/v1/evaluateSDK @vetolayer/sdkVerdicts ALLOW · REVIEW · BLOCK
Open integration setup
TypeScriptserver-side
import { createVetoLayerClient, guardedToolCall } from "@vetolayer/sdk";

const veto = createVetoLayerClient({
  baseUrl: process.env.VETOLAYER_URL!,
  apiKey: process.env.VETOLAYER_API_KEY,
});

const result = await guardedToolCall({
  client: veto,
  evaluation,
  execute: () => highImpactToolCall(),
});

Safety architecture

Reasoning is constrained by policy, evidence, and failure rules.

VetoLayer does not hand the final word to a model. Its orchestration is designed so uncertainty creates friction rather than accidental execution.

Fail closed

Missing critical evidence, malformed provider output, and reasoning-provider failures never silently become ALLOW.

Hard rules stay authoritative

A contextual result cannot override an explicit deterministic BLOCK.

Server-owned boundaries

Workspace identity and production API boundaries are resolved server-side rather than trusted from browser headers.

Auditable outputs

Every evaluation can produce a receipt with decision lineage, evidence, findings, trace metadata, and tamper-evident hashing.

Govern execution

Let agents move fast without giving them the final word.