Routine actions fly
The full check — intent, context, policy — clears in under 100 milliseconds. Your agents don't slow down: in production, a routine decision takes a median of 24 milliseconds.
How It Works
Three steps between agents-on-hope and agents-under-control — and the first week costs nothing and changes nothing.
GaaS works in three steps: install the SDK with one command and add one governance call before each agent action; set your rules in plain language through the Claude-powered dashboard; and let it gate — every agent action is allowed, fixed, held, or blocked against your rules in under 100 milliseconds, with a tamper-evident receipt.
| Time | Agent | Action | Verdict | Latency |
|---|---|---|---|---|
| 09:41:02 | payments-agent | initiate_payment → inv_2026_0044 $320 | APPROVE | 21ms |
| 09:41:00 | payments-agent | initiate_payment → inv_2026_0051 $1,240 | ESCALATE | 50.5s |
| 09:40:56 | cx-agent | send_email → external_domain (customer data) | BLOCK | 36ms |
| 09:40:54 | marketing-bot | post_to_social → pricing_update | ESCALATE | 26ms |
| 09:40:50 | cx-agent | send_email → order_confirmation | APPROVE | 37ms |
| 09:40:48 | content-agent | post_to_social → disclosure_added | MODIFY | 30ms |
| 09:40:44 | payments-agent | initiate_payment → vendor_account_9912 | APPROVE | 25ms |
| 09:40:42 | support-agent | export_report → outside_org | BLOCK | 30ms |
Simulated feed. Actual decisions include full audit records with hash-chain verification.
Step 1 · Install
A developer wires this in an afternoon. The agent declares what it intends to do; GaaS returns the verdict:
from gaas_sdk import GaaSClient, build_intent, ActionType, TargetType async with GaaSClient("https://api.gaas.is", headers={"X-API-Key": "gsk_..."}) as client: intent = build_intent( agent_id="my-agent-v1", action_type=ActionType.TRANSACT, verb="initiate_payment", target_type=TargetType.ACCOUNT, target_identifier="vendor_account_9912", summary="Pay invoice INV-2026-0044", content={"invoice": "INV-2026-0044"}, ) response = await client.submit_intent(intent) print(response.data.verdict) # approve | approve_modified | escalate | block
The real Python SDK; TypeScript, cURL, and the framework plugins are documented at gaas.to. Plugins for LangChain, OpenAI Agents, CrewAI, Pydantic AI, Vercel AI, Microsoft Agent Framework, and MCP hook the pipeline in automatically.
Step 2 · Set Your Rules
The dashboard is conversational, powered by Claude. Say the rule the way you'd brief an employee, and it exists — versioned, enforced, and testable:
"Hold any payment over $500 for my approval."
"Never send customer data to anyone outside the company."
"Posts about pricing wait for marketing's sign-off."
Step 3 · Let It Gate
From then on, every consequential action your agents take passes the gate first:
The full check — intent, context, policy — clears in under 100 milliseconds. Your agents don't slow down: in production, a routine decision takes a median of 24 milliseconds.
When your rules say a required change — a disclosure, a cap, a safer phrasing — is enough, the action executes with that modification instead of waiting.
High-stakes actions get deeper deliberation and, when your rules say so, a human yes before anything happens.
Nothing that breaks a rule executes — and every block carries its reasoning chain: which policy, which condition, what would make it compliant.
Every verdict lands in a tamper-evident, hash-chained audit record — the receipt for everything your agents did and were never allowed to do.
The Zero-Risk Start
You don't flip enforcement on day one. In Shadow Mode, the full pipeline runs on your real agent actions and enforces nothing — every would-have-been verdict is recorded and shown to you. When the would-have-blocked list matches your instincts, going live is a single flag change.
Start with just an email. No credit card, no commitment, zero operational risk.
FAQ
Route their actions through an external check. With GaaS: install the SDK (one command, then one call per action), describe your rules in plain language, and every action is evaluated before it executes — allowed through, held for your approval, or blocked. Start in Shadow Mode and it enforces nothing while showing you what it would have done.
An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.
No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.
No. Start in Shadow Mode with just an email; it runs the full pipeline on real actions without enforcing anything, so there is zero operational risk. A developer wires the SDK in an afternoon, and you author policies in plain language.
Start free in Shadow Mode, no card. There is a free tier, then plans from $99 a month, and under a cent per governed action at scale. Nonprofits, NGOs, and veteran-owned businesses govern free for life. See pricing.
Routine actions clear in well under a tenth of a second. Only high-stakes decisions take longer, and only because you asked them to.
No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.
The opposite. A self-governing agent spends about 14,700 tokens of context on every routine governed action; with GaaS it spends 0 through a framework plugin (74 when an action is blocked), or about 2,470 through MCP. On a 200K-token model, self-governance fills 30% of the window after about 14 governed actions and 60% after about 28. See The Context Dividend.
Prompt guardrails live inside the model, get re-read on every call, and can be argued away. GaaS is external and enforced; the agent cannot talk it out of a block.
Start free in Shadow Mode — real actions, real verdicts, zero enforcement, no credit card. Install, describe one rule, and watch what the gate would have caught this week.
Prefer the plain-language overview first? Read What Is GaaS?