Control plane for agentic AI
Agents change every quarter. Your controls shouldn't.
Your agents send the email, move the money, change the record. Fyder gates the effect itself, so swapping models and frameworks never moves the boundary.
Its C0 calls still pass unattended — the gate is on the effect.Routing ·Routing rotates automatically across supported model providers; the tool and gate above hold regardless of which model is active.
The trust gap
You don't have a technology problem. You have a trust problem.
Hand AI to your workforce with no boundaries and no record, and you've handed out power without accountability. That's the gap between what AI can do and what you can trust it to do.
Smarter models won't close it. Boundaries, scope, and a record around every action will. Not policies. Not guidelines. Guarantees.
Any surface. Any model.
Chat, CLI, remote tasks, standing agents — and whatever models and frameworks your people reach for next.
Class and scope resolve here.
Every tool is registered with the classes of effect it can produce. An agent cannot raise its own class.
One boundary, enforced.
Autonomy inside. Approval at the effect boundary. A named human beyond it.
What crossing means.
A write to a system of record, a transmission outward, a disclosure to a third party, or spend. There is no fifth.
The trail holds the context.
Sources consulted, tools invoked, content retrieved at the moment of the decision.
What the control plane holds
The controls don't live in the agent. They live in the path it has to take.
A control that lives inside a model is a request. A control that sits on the path between the agent and the system is a guarantee. One column below is expected to churn; the other does not move when it does.
Changes without warning
What you swap
- models and inference providers
- agent frameworks and harnesses
- tools, MCP servers, internal APIs
- the people running any of it
- whatever ships next quarter
Stays where you put it
What holds
- the action classes and what each one means
- which classes require a named human
- the scope an identity is entitled to
- the promotion path from user to team to org
- one record across all of it
Action classes
Four classes. The two that leave the sandbox stop at a person.
Classes sort on one question: has the effect left the agent's own workspace? Reading, drafting and iterating inside it run unattended. Anything that lands in a system other people depend on is a named human's decision. Gates attach to the class, never to the tool — an agent cannot escalate by finding another route to the same outcome, and approval is asked once per effect rather than once per tool call.
Four surfaces, one boundary
Wherever your people run agents, the line sits in the same place.
Chat
A browser agent with your approved tools and a workspace. Actions that reach your systems collect for a decision, then run.
Reviewed in seconds to minutes
CLI
Agents on your machine, at native speed, with centrally managed configuration and write approvals.
Blocking, immediate
Remote tasks
Long-running agent work in a sandbox on remote infrastructure, streamed back to the browser.
Reviewed in minutes to hours
Standing agents
Agents that wake on an event, do the work, and leave a proposal. Memory you can read and edit.
Reviewed hours to days later, out of band
What compounds
Discoveries stop dying in one person's terminal.
A flow that worked is captured as a skill and promoted upward under the same approval model as everything else. Knowledge outlives the model that produced it and the person who found it.
Next
Bring the tools your people already use.
A briefing walks through how a handful of your real tools would register, the action classes they reach, and where the gates would land across every surface you run.