Skip to content
Gated

Public preview guide

From agent intent to an authorized action.

Gated is a security boundary between AI intent and real-world action. This guide explains the controlled GitHub pilot; it is not a production-readiness claim.

What Gated is

A tool credential may allow more than one agent should do. Gated evaluates an explicit request against policy and routes the result through a trusted executor. The current private preview focuses on a narrow, non-critical GitHub workflow.

Authentication identifies the caller. Authorization decides whether that caller may perform this action on this resource. Gated applies action-level authorization to requests that actually pass through its controlled path.

How action control works

  1. The agent submits an action with its identity, target resource and environment.
  2. The policy engine returns allow, deny or require approval, with a recorded reason.
  3. If approval is required, a human reviews the specific request and confirms with a passkey.
  4. The executor uses scoped provider authority for the authorized operation. An approval alone is not evidence of execution.
  5. Execution records and provider readback establish the outcome. Replay protection and revocation bound subsequent use.

See the developer model and security approach.

What the GitHub preview can do

The verified operation creates one uniquely named branch at an exact existing commit in a selected pilot repository. A GitHub App provides temporary server-held authority; the executor constrains the broader provider permission to that operation.

Pull-request merge, force push, branch deletion and production deployment governance are not verified pilot capabilities. See the GitHub scope and requirements.

Policies and presets

Policies match the agent, requested action, resource and environment. Presets give the pilot a starting policy to review. Choosing a preset does not verify a provider connection or grant every action: inspect its rules, selected resources and approval requirements before use.

Recommendations and observed activity help a person review policy; they do not replace the authorization decision or human approval.

MCP awareness and agent routing

MCP describes how clients connect to tools. A tool connection does not by itself authorize every action. Gated’s MCP awareness and approval context concern actions routed through the controlled path; they do not turn Gated into a universal MCP proxy.

Claude Code and Codex use explicit project skills and scoped CLI routing in the preview. Their runtime rehearsals used safe mode; live GitHub writes were verified separately through the downloaded CLI.

Human approval for sensitive actions

When policy requires approval, the human checks the requested repository, branch and commit before the passkey step. Approval is tied to that request. Keep the distinction between a policy decision, human authorization and the provider’s execution result visible in the audit trail.

Where the boundary stops

An agent with independent GitHub credentials can use them outside Gated. Gated does not automatically intercept every tool, local process or network request. Use a non-critical repository and avoid giving the agent a parallel direct credential for the controlled workflow.

Gated is a controlled private pilot, not production-ready infrastructure. Other integrations may be planned or have adapter foundations without verified provider execution. Check the integration status directory before relying on a capability.

Your first pilot

Read the Founding 55 offer, then check application availability and submit your individual eligibility and intended use when admissions open. Human acceptance comes before access or any paid offer.

After acceptance, follow Set up Gated, sign in with the same individual account, select a non-critical repository, review scoped agent authority and policy, and attempt one governed branch request. Submit one substantive feedback action in the first 30 days; a human reviews it. There is no monthly feedback obligation.