pakt
Built and operated by BOB
Request a demo

Bespoke Agent Guardrails for
True Enterprise Autonomy

Two things keep agents from running on their own: the approval gate a person still has to clear, and the judgement lapse or hallucination nobody can rule out. Pakt removes both. Your limits and compliance rules are enforced in code on every trade, payment and payout, so the agent cannot act outside them and no one has to sit in the queue to check.

Refund request · Support agent
#A-88213
Requested amount$180.00
Refunded in last 12 months$460.00
Annual cap for this customer$500.00
Order matched and within policy windowPass
Amount within original transactionPass
Within annual refund capFail
Refund declined
Approving would take this customer $140 over the annual cap. Routed to a human reviewer.
No reviewer
Approvals run end to end inside limits you set once, not a queue that scales with volume
< 200ms
Decision time, so automation stays as fast as the agent's own tool calls
3 prompts
To add a payment rail, exchange or system of record we don't already support

Take the human out of the loop without taking on the risk

Today
Throughput capped by reviewer headcount
Agent proposes
Refund, payout, order, invoice
Review queue
Every action waits for a person
Human approves
Judgement, under time pressure
Action executes
Hours later, if at all
With pakt
Throughput capped by nothing
Agent proposes
Refund, payout, order, invoice
pakt evaluates
Limits, exposure and eligibility, in code, under 200ms
Within policy → executes
No person involved
Outside policy → refused
Escalated only if your rules say so
Evidence recorded
The rule and totals behind every decision

Wherever an agent can
already move money.

Function
What goes wrong
What Pakt enforces
Accounts payable
Invoices paid to a bank account changed by whoever emailed last, above PO value, or twice for the same document.
Three-way match against PO and receipt, duplicate-invoice detection, payee-change holds, approval tiers by amount.
Customer support
Refunds issued outside policy, twice on the same order, or well past what a customer is entitled to.
Order and window checks, no double refunds, per-customer annual and lifetime caps.
Paid media
Runaway spend overnight: a feedback loop puts six figures behind a campaign that converts nothing.
Daily and monthly ceilings per campaign, per account and in aggregate; automatic freeze on spend anomalies.
Disputes
Provisional credit granted on a claim narrative written by the person who benefits from it.
Credit ceilings per dispute and per customer, mandatory review thresholds, new-account holds.
Claims
Payouts above the policy limit, on uncovered perils, or on cover that had already lapsed.
Limit and coverage checks, deductible always applied, human adjuster above a set severity.
Trading desks
Agent judgement drifts from its strategy parameters as the context window grows: positions creep past mandate, concentration builds, and a drawdown runs with no floor under it.
Notional, leverage and concentration ceilings held outside the model, plus loss limits and kill-switch thresholds checked on every order regardless of how long the agent has been running.
Exchanges
Most of their AI product stops at advice. Users get a bot that suggests a trade and then asks them to go press the button, because nothing stops an autonomous agent from doing real damage to a real account.
Per-user mandates the exchange defines and the user sets: size, asset, leverage and loss limits enforced on every order, so the agent can trade for the user instead of advising them.

How the engagement runs

Configuration is a one-time exercise we run with your team. We write the policy, integrate with your systems of record, and prove it against history. Then the agent runs on its own.

Step 1
We write your policy with you
Working sessions with the people who own the number. The rulebook reads back in plain English for sign-off.
Step 2
We integrate with your systems
API, MCP or SDK, with adapters for your systems of record. Your agent asks Pakt before it acts.
Step 3
We replay history, then go live
A month of real decisions run against the policy first, so you see what would have been stopped before anything is enforced.

Deployment and control

Run Pakt wherever your security review requires.

Self-hosted. Runs entirely inside your perimeter, so no customer record leaves your infrastructure.
Hybrid. We evaluate policy; the credentials that authorize actions stay with you.
Fully managed. Fastest path to production, with enforcement isolated from our operators.
Fails closed
If Pakt is unreachable, nothing is authorized. An outage stops approvals; it never invents one.
Injection-proof by design
Enforcement reads facts from your systems of record, not text the claimant wrote. There is nothing in the prompt to attack.
Immutable records
Exports your auditors and clients can re-check without asking your engineers.
Escalation by exception
A person sees only the cases your policy says require one, not the volume the agent could have closed itself.

See what your agent could run unsupervised

Thirty minutes. We encode one of your policies, replay a month of real approvals against it, and show you how much of that queue never needed a person.