Sales deck · v0.5 · updated 2026-09-16, press ⌘P / Ctrl+P to save as PDF.

Your agent stops
at the refund.

It reads the case, checks the order, and proposes a refund. Then a person opens the same screens and presses the button.

keep the handoffEvery action waits.The agent can draft, but it cannot finish.
or
give it the keyEvery action can run.The tool can execute, but the key cannot express your limits.

What if it could finish only the actions you authorized?

Which decision still belongs to your team?

moneyRefund or payoutWhen is it valid, and how much authority can one actor use today?
accessGrant a roleWho can grant it, for how long, and in which state?
productionShip or roll backWhat must be true of the service before this runs?
Pick one consequential action.Which part is a rule, and which part is judgment?

An API key cannot answer that.

Current stateIs this action valid now?A paid invoice may be refundable. A refunded invoice is not.
AuthorityMay this actor do it?Tool access does not say who may act, when the grant expires, or what needs a person.
Total exposureWhat has already been authorized?Individually valid actions can exceed a shared ceiling together.

If a person must exercise judgment, keep the person. If the answer is a rule, why make them check it again and again?

The next refund looks fine. It still stops.

Illustrative: one agent, one day€1,100 authority
€42 authorized€990 authorized€68 left
Next refund: €88. Valid invoice. Permitted actor. €20 over the ceiling. KIFF refuses before execution.

An alert tomorrow would tell you what happened. This boundary decides what may happen now.

You set the limit. KIFF checks every proposal.

Your teamDefines the operation.Valid states, actions, actor permissions, human-review cases, and cumulative ceilings.
KIFFAnswers before execution.Allow, hold for a person, or refuse using the current state and the actor's authority.
Your systemPerforms the allowed action.Your code keeps the execution path. Your people keep the decisions that need judgment.

The rule survives the next agent.

today's agentnext agenthuman operator
one operational domainstate · actions · authoritylimits · decisions · evidence
ERPpaymentssupport

You can change the model or connect another service without rewriting the business rule around each one.

Buy one week for one action.

one action on rails€7,500fixed first week · founder-ledSee the engagement →
what you receive
  • A decision map. The action, state, actor, and limit your team would own.
  • An observed boundary. Your representative traffic stays on its existing execution path while you see allow, hold, and refuse decisions.
  • A go or no-go. Evidence of where a rule could replace a repeat check, and where judgment must stay human.

If the answer is no, stop after week one. You have not committed to a platform migration.

If the boundary earns its place, make it live.

We scope the follow-on implementation at a day rate. Your team owns the rule; KIFF checks it before your system executes. Signed decision records remain inspectable in the Control Room and portable proof pack.

You can self-host the MIT framework and Guard SDKs. KIFF Cloud is the separate recurring purchase for a hosted production decision path: platform fee plus governed-operation consumption, not a charge per agent, domain, action, or seat.

First, prove the boundary on your action.Then choose who runs it.

Bring us one action.

boundary review30 minfounder-led · no costBook the review →
bring three things
  • One action your agent proposes.
  • The rule a person applies today.
  • The system that would execute it.