How It Works

Install. Set your rules. Let it gate.

Three steps between agents-on-hope and agents-under-control — and the first week costs nothing and changes nothing.

GaaS works in three steps: install the SDK with one command and add one governance call before each agent action; set your rules in plain language through the Claude-powered dashboard; and let it gate — every agent action is allowed, fixed, held, or blocked against your rules in under 100 milliseconds, with a tamper-evident receipt.

org_demo · live actions
Simulated
TimeAgentActionVerdictLatency
09:41:02payments-agentinitiate_payment → inv_2026_0044 $320APPROVE21ms
09:41:00payments-agentinitiate_payment → inv_2026_0051 $1,240ESCALATE50.5s
09:40:56cx-agentsend_email → external_domain (customer data)BLOCK36ms
09:40:54marketing-botpost_to_social → pricing_updateESCALATE26ms
09:40:50cx-agentsend_email → order_confirmationAPPROVE37ms
09:40:48content-agentpost_to_social → disclosure_addedMODIFY30ms
09:40:44payments-agentinitiate_payment → vendor_account_9912APPROVE25ms
09:40:42support-agentexport_report → outside_orgBLOCK30ms
GOVERNING
27,015 decisions

Simulated feed. Actual decisions include full audit records with hash-chain verification.

Step 1 · Install

Govern your first agent action this afternoon.

A developer wires this in an afternoon. The agent declares what it intends to do; GaaS returns the verdict:

govern_payment.py
from gaas_sdk import GaaSClient, build_intent, ActionType, TargetType

            async with GaaSClient("https://api.gaas.is", headers={"X-API-Key": "gsk_..."}) as client:
                intent = build_intent(
                    agent_id="my-agent-v1",
                    action_type=ActionType.TRANSACT, verb="initiate_payment",
                    target_type=TargetType.ACCOUNT, target_identifier="vendor_account_9912",
                    summary="Pay invoice INV-2026-0044",
                    content={"invoice": "INV-2026-0044"},
                )
                response = await client.submit_intent(intent)
                print(response.data.verdict)   # approve | approve_modified | escalate | block

The real Python SDK; TypeScript, cURL, and the framework plugins are documented at gaas.to. Plugins for LangChain, OpenAI Agents, CrewAI, Pydantic AI, Vercel AI, Microsoft Agent Framework, and MCP hook the pipeline in automatically.

Step 2 · Set Your Rules

Describe the policy. Don't program it.

The dashboard is conversational, powered by Claude. Say the rule the way you'd brief an employee, and it exists — versioned, enforced, and testable:

"Hold any payment over $500 for my approval."
→ Everything under flows; everything over waits for your yes.
"Never send customer data to anyone outside the company."
→ Detected and blocked on every channel, every time.
"Posts about pricing wait for marketing's sign-off."
→ Escalations land with the right person, not a queue of everything.

Step 3 · Let It Gate

Every action, decided in milliseconds.

From then on, every consequential action your agents take passes the gate first:

Allow

Routine actions fly

The full check — intent, context, policy — clears in under 100 milliseconds. Your agents don't slow down: in production, a routine decision takes a median of 24 milliseconds.

Modify

Small fixes applied

When your rules say a required change — a disclosure, a cap, a safer phrasing — is enough, the action executes with that modification instead of waiting.

Escalate

Judgment calls wait

High-stakes actions get deeper deliberation and, when your rules say so, a human yes before anything happens.

Block

Line-crossers stop

Nothing that breaks a rule executes — and every block carries its reasoning chain: which policy, which condition, what would make it compliant.

Every verdict lands in a tamper-evident, hash-chained audit record — the receipt for everything your agents did and were never allowed to do.

The Zero-Risk Start

Shadow Mode: watch before you enforce.

You don't flip enforcement on day one. In Shadow Mode, the full pipeline runs on your real agent actions and enforces nothing — every would-have-been verdict is recorded and shown to you. When the would-have-blocked list matches your instincts, going live is a single flag change.

Start with just an email. No credit card, no commitment, zero operational risk.

FAQ

Every objection, answered.

How do I control what my AI agents do?

Route their actions through an external check. With GaaS: install the SDK (one command, then one call per action), describe your rules in plain language, and every action is evaluated before it executes — allowed through, held for your approval, or blocked. Start in Shadow Mode and it enforces nothing while showing you what it would have done.

What is GaaS, in one sentence?

An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

Do I have to be a regulated business?

No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.

Is it hard to set up?

No. Start in Shadow Mode with just an email; it runs the full pipeline on real actions without enforcing anything, so there is zero operational risk. A developer wires the SDK in an afternoon, and you author policies in plain language.

What does it cost?

Start free in Shadow Mode, no card. There is a free tier, then plans from $99 a month, and under a cent per governed action at scale. Nonprofits, NGOs, and veteran-owned businesses govern free for life. See pricing.

Will it slow my agents down?

Routine actions clear in well under a tenth of a second. Only high-stakes decisions take longer, and only because you asked them to.

Do I have to change my agent or my model?

No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.

Doesn't governance cost me tokens?

The opposite. A self-governing agent spends about 14,700 tokens of context on every routine governed action; with GaaS it spends 0 through a framework plugin (74 when an action is blocked), or about 2,470 through MCP. On a 200K-token model, self-governance fills 30% of the window after about 14 governed actions and 60% after about 28. See The Context Dividend.

I already have prompt guardrails. Why GaaS?

Prompt guardrails live inside the model, get re-read on every call, and can be argued away. GaaS is external and enforced; the agent cannot talk it out of a block.

Step 1 takes an afternoon. Start it today.

Start free in Shadow Mode — real actions, real verdicts, zero enforcement, no credit card. Install, describe one rule, and watch what the gate would have caught this week.