Stop clicking through what the agent already decided.
One thing to buy, and two that are free. Week one is €7,500 and ends with a governed action running. The framework and the Guard SDKs are MIT. Cloud is priced against what you actually govern.
Your agent drafts it. A human still clicks it.
Pick the action an agent already produces and a person still executes, a refund, a payout, a credit, an access change. We issue the agent a card for it, so the clear cases run against that card and a human only sees the exceptions, and we stay until it is live.
Week one changes nothing: KIFF decides and records against your real traffic while refusing nothing, so you can see the ratio, and what that agent would have drawn in a day, before you commit to enforcing it. If it shows almost everything needs a human anyway, we say so and you stop.
Week one
- 01 What your agents can already reach, measured
- 02 One action's states, authority and limits, defined
- 03 KIFF on the path, deciding and recording
- 04 Observe mode on real traffic, what it would allow, hold, refuse
- 05 Then enforce, and we stay until your team owns it
And separately: the runtime itself.
Everything below this line is a different purchase, made by a different person. The engagement above puts one action on rails and leaves it working. KIFF Cloud is the runtime a governed action runs through afterwards, if you decide you want one. Neither requires the other. A team that adopts the runtime never has to buy an engagement, and an engagement that concludes the ratio is not worth it still leaves you knowing your own numbers.
Priced against what you govern, after we have seen it.
Cloud runs the shared domains your agents operate against: hosted state, decisions, approvals, signed receipts, retention, and audit export. What that costs depends on how much of your operation runs through it, which is a conversation rather than a table, and one worth having before you commit to anything.
A 30-minute review
Bring a repository, or just the shape of your setup. We look at what your agents can reach without a decision on the path, what a card would have to say to bound it, and what evidence exists today if a customer, an auditor, or a regulator asks you to produce it.
You leave with the findings whether or not you buy anything. If KIFF is not the right answer for what we find, that is a useful outcome and we will say so.
Direct, not a queue: gabriel@kiff.dev
One governed operation.Exactly this.
A governed operation is one unique, authenticated action proposal that KIFF evaluates against the entity's current state and your active domain contract, then records with a terminal outcome. allowed, blocked, and approval_required all count because KIFF did the production work in each case.
What never counts: unauthenticated requests, malformed proposals rejected before evaluation, infrastructure failures where KIFF returns no decision, retries resolved from the same idempotency key, and reads such as receipt views, dashboard access, and domain authoring. A transport that retries ten times is still one billable operation.
The objects you build are free to create and connect. Domains, actions, agents, integrations, and environments are expansion vectors, not toll booths. Create as many as you need; they never appear on the bill. What you pay for is the verifiable evidence stream each operation produces: a signed, tamper-evident receipt. See RFC 029 for the consumption model.
propose ISSUE_REFUND → recorded