Tightened by default. Inspectable by design.
Agents start with the minimum access they need and nothing more. Every read, write, decision, and approval lands in an audit log you can replay.
Credentials
Members lend their own OAuth access to a Space. Nothing is shared with us in plaintext. Revoke yours and agents lose it immediately.
Scoped permissions
Per agent, per Space, per integration. Declarative — you describe what's allowed, not how to enforce it.
Approvals & gates
Risky actions pause at a gate until a human signs off. Sending email and delegating to another agent gate for everyone by default — even Leads.
Budgets
Per agent, per Space, per org. At 80% the Space is notified. At 100%, work pauses where it stands and resumes when budget returns.
Audit log
Every read, write, decision, approval, ask, and demotion. Replayable. Exportable. Searchable.
Memory you can edit
Every piece of memory is tied to a source. Open it, see where it came from, edit it, or remove it.
Hosting & data
Runs on Cloudflare's global edge. Data in Neon Postgres. SOC 2 Type II in progress.
Disclosure
Found something? Email security@moonage.ai. We respond within one business day.