before you turn them on

Stop clicking through what the agent already decided.

One thing to buy, and two that are free. Week one is €7,500 and ends with a governed action running. The framework and the Guard SDKs are MIT. Cloud is priced against what you actually govern.

Your agent drafts it. A human still clicks it.

Pick the action an agent already produces and a person still executes, a refund, a payout, a credit, an access change. We issue the agent a card for it, so the clear cases run against that card and a human only sees the exceptions, and we stay until it is live.

one action week one, observing then until it ships

Week one changes nothing: KIFF decides and records against your real traffic while refusing nothing, so you can see the ratio, and what that agent would have drawn in a day, before you commit to enforcing it. If it shows almost everything needs a human anyway, we say so and you stop.

founder-led engagement

Week one

€7,500then a day rate
  • 01 What your agents can already reach, measured
  • 02 One action's states, authority and limits, defined
  • 03 KIFF on the path, deciding and recording
  • 04 Observe mode on real traffic, what it would allow, hold, refuse
  • 05 Then enforce, and we stay until your team owns it
Put an action on rails →

How the week runs, and the number to count first →

And separately: the runtime itself.

Everything below this line is a different purchase, made by a different person. The engagement above puts one action on rails and leaves it working. KIFF Cloud is the runtime a governed action runs through afterwards, if you decide you want one. Neither requires the other. A team that adopts the runtime never has to buy an engagement, and an engagement that concludes the ratio is not worth it still leaves you knowing your own numbers.

integrate yourself · free forever
$0
Use the MIT framework and Guard to build a shared domain and connect agents yourself. No guided launch required.
then, when the action goes live
KIFF Cloud
hosted runtime ↓
cloud · production runtime
consumption
Cloud operates the shared domains your agents use: hosted state, decisions, approvals, receipts, retention, and audit export.

Priced against what you govern, after we have seen it.

Cloud runs the shared domains your agents operate against: hosted state, decisions, approvals, signed receipts, retention, and audit export. What that costs depends on how much of your operation runs through it, which is a conversation rather than a table, and one worth having before you commit to anything.

A 30-minute review

Bring a repository, or just the shape of your setup. We look at what your agents can reach without a decision on the path, what a card would have to say to bound it, and what evidence exists today if a customer, an auditor, or a regulator asks you to produce it.

You leave with the findings whether or not you buy anything. If KIFF is not the right answer for what we find, that is a useful outcome and we will say so.

Direct, not a queue: gabriel@kiff.dev

One governed operation.Exactly this.

A governed operation is one unique, authenticated action proposal that KIFF evaluates against the entity's current state and your active domain contract, then records with a terminal outcome. allowed, blocked, and approval_required all count because KIFF did the production work in each case.

What never counts: unauthenticated requests, malformed proposals rejected before evaluation, infrastructure failures where KIFF returns no decision, retries resolved from the same idempotency key, and reads such as receipt views, dashboard access, and domain authoring. A transport that retries ten times is still one billable operation.

The objects you build are free to create and connect. Domains, actions, agents, integrations, and environments are expansion vectors, not toll booths. Create as many as you need; they never appear on the bill. What you pay for is the verifiable evidence stream each operation produces: a signed, tamper-evident receipt. See RFC 029 for the consumption model.

example governed operation
finance / prod / refund-agent
propose ISSUE_REFUND → recorded
proposal authenticated
evaluated vs state + domain
outcome allowed · blocked · approval
retries idempotent · not re-billed
receipt signed
billable once

Questions worth asking.

What is a governed operation?
One unique, authenticated action proposal KIFF evaluates against current state and the active domain contract and records with an outcome. allowed, blocked, and approval_required all count; idempotent retries and reads do not.
Why meter operations, not controls or agents?
Domains, actions, and agents are the things KIFF wants you to create and reuse freely. Charging per object would tax the architecture. Operations track the production work Cloud actually performs, so the bill follows real use.
Is there a limit on how many domains I can create?
No. Domains, actions, agents, and environments are uncapped. Build as many as you want. The bill only ever tracks governed operations, so there is nothing to gain by limiting the objects you model.
Usage-based sounds unpredictable. How do I stay in control?
The same way you do on Twilio or Stripe: usage is metered per governed operation, and spend is bounded by budgets and alerts you set, so you are notified as you approach a limit instead of surprised by the invoice. Domains, agents, and actions stay unlimited, so scaling what you govern is a decision you make with the meter in view.
Is Cloud Growth self-serve today?
Not yet. Growth is private beta: the monthly cap is disclosed up front and raised manually before your traffic reaches it. Public self-serve and automatic overage ship after the paid-plan grace path lands, so a billing limit never becomes a production outage.
What happens when I cross the allowance?
During private beta we raise the cap by hand before you reach it. Once metering ships, paid usage above the allowance becomes overage with alerts and budgets instead of a hard stop on a production decision. Free Developer keeps a clearly disclosed cap.
Do receipts or retention cost extra?
Not at launch. Receipts and standard retention are bundled. Evidence is a protocol output, not a separately metered product; longer or customer-managed retention is a Scale/Enterprise option.
Are the prices final?
No. They are provisional while the first production tenants prove the unit economics, and they will change as real usage comes in. We would rather publish a provisional number than pretend the economics are settled.

What is not a line on the bill.

not per protected control
A control is one action-shaped view into a domain. KIFF no longer bills per control; it meters the operations Cloud performs.
not per domain or action
Build and compose as many domains and actions as you want. Modularity is the point, not a billing optimization problem.
not per agent or seat
Agents are meant to be replaceable and humans are not the traffic. Neither is a price dimension.
not per receipt
Evidence is a protocol output. Charging per record would push you to record less, which is the opposite of what KIFF is for.
not token or model pricing
We do not proxy LLM calls or sit on the model layer. Token volume is not our meter.
not flat unlimited SaaS
A platform fee pays for the standing runtime; consumption follows real production work, so cost aligns with value at any scale.

Build, connect, operate, prove.One path.

01
Build
Define the domain once in Studio, or draft it from a guard runtime KIFF observed.
02
Connect
Point agents, humans, and services at the same contract over the Cloud runtime API.
03
Operate
Cloud decides before each consequential action runs and records a signed receipt.
04
Prove
Export the complete decision record for every governed operation in the retained window.