KIFF · control for AI agents in production

Change what your AI agents may do. Without a release.

The rules live on a card the business controls, not in the agent’s code.

owner console · refunds-agent

set by the owner

incoming request · 14:05

refunds-agent wants to refund €1,500 on a paid order. Already used today: €4,000.

RefusedOnly €1,000 left today.
AllowedYour system runs the refund.
RefusedThis card was revoked.

agent code changed0 linesevery changeon record

busy weekend · refunds limit €5,000 → €20,000

Same change. Two ways.

limits in the agent’s code
  1. Open a ticket
  2. Edit the prompt or config
  3. Review and test
  4. Deploy
  5. Monday: do it all again

2 releases

limits on a KIFF card
  1. Owner sets €20,000
  2. Monday: owner sets €5,000

0 releases

Both changes saved, with who made them.

2 a.m. · one agent misbehaves

Stop one agent. The rest keep working.

owner console · agents

tap an agent to revoke its card

Every agent holds its own cards. Revoking a card withdraws only the authority that card granted; other agents keep theirs.

the auditor asks · who allowed what, and when

Every change. On record.

statement · refunds-eu · today
limit€8,000
used€5,500
left€2,500

changes to this card

  • rev 314:20limit €5,000 → €8,000anna@retailer.example
  • rev 2Monlimit €20,000 → €5,000anna@retailer.example
  • rev 1Frilimit €5,000 → €20,000marc@retailer.example

owned by the business

Only an owner or admin can issue, change or revoke a card. The agent can only ask.

new models start small

Give a new model its own card with a low limit. Raise it when its statement looks right.

your system still acts

KIFF answers yes or no. Your code runs the refund, as it does today.

not a mockup · the real app, sample data

Open the owner’s console.

Explore the real KIFF appFully navigable · sample data

how teams adopt KIFF

Free to build. Paid when it runs your business.

build · free

Framework + Guard

Open source. Put KIFF in front of any agent action, on any stack. No contract, no procurement.

Start building →
run · KIFF Cloud Production

For the company

  • Company workspace
  • Owner controls for every card
  • Dashboard and statements
  • Full history and evidence
  • Grows with your agents
See pricing
launch · with us

Production Launch

We connect your first real action, issue the first cards, test the controls and hand it over.

Get it live with us →

Questions teams ask first.

Do I have to rewrite my agent?

No. You add one call before the action. If KIFF says no, your code stops. It works with Agno, LangGraph, OpenAI, Google ADK, Strands, n8n or your own code.

d = kiff.decide("issue_refund", order=order, amount=amount)
if not d.allowed:
    return d
payments.refund(order, amount)   # your code, unchanged
Can the agent raise its own limit?

No. The agent’s key can only ask for a decision. Only an owner or admin of your KIFF account can issue, change or revoke a card.

What if KIFF cannot read the balance?

The answer is no. An unknown balance is never treated as zero, and a retried request is only counted once.

Does KIFF run the action or touch payments?

No. KIFF only answers whether the action is allowed. Your system runs it, as it does today.

Is it only for money?

No. A card can limit amounts, or how many times something happens: three account deletions an hour, two deploys a day.

We build agents for clients. Does it fit?

Yes. Ship the same agent to every client. Each client holds its agents’ cards in its own KIFF account and changes them without calling you.

Give every agent a card.

ask AI about KIFF

Open your assistant with a prompt to read llms-full.txt and answer from it.