Intercept
Freeze the proposed action and its exact arguments before a tool can run.
EXECUTION SECURITY FOR AI AGENTS
Praxel controls consequential actions before they execute, binding approval to the exact action and producing signed evidence of the outcome.
See exact-action authority in under 60 seconds.
Issue refund $750.00
$750.00
cus_123Approve this exact action once.
01 / PRODUCT IN ACTION
See Security & Evidence below for current scope and limits.
Book a demo02 / THE AUTHORITY GAP
Agents decide what to do dynamically. Access to a tool should not grant unlimited authority over every action that tool can perform.
“Can this identity access Stripe?”
“Can this agent issue this $750 refund to this customer, right now?”
03 / HOW IT WORKS
Freeze the proposed action and its exact arguments before a tool can run.
Evaluate policy. When approval is required, ask an authenticated local reviewer.
Consume valid approval once. Dispatch only the frozen arguments.
Sign linked authorization, approval and observed execution evidence.
The actions you cannot afford to leave ambient.
04 / SECURITY & EVIDENCE
Approval is bound to the disclosed action and arguments. A mismatch blocks dispatch.
Atomic consumption prevents replay of the same approval in the local protocol.
An approval must still be valid at consumption and immediately before dispatch.
Missing, denied or invalid approval blocks execution in tested protocol paths.
Export proof JSON and verify Ed25519 signatures offline with independently trusted keys.
Current scope and limits. This is an unreleased local approval MVP. Automated protocol tests are reported passing; real Chrome validation remains pending. The extension is unpublished. The MVP trusts its registered executor, host, clock, database and signing keys. Reviewer identity is session-authenticated. Receipts do not prove physical human presence, external settlement or correctness of a compromised host.
05 / FOR DEVELOPERS
Register your tool, configure policy and approval, then execute through Praxel. The local approval path uses the Python executor and explicitly registered tools.
Actual call from examples/approval_demo.py. Assumes a configured registry, policy, signer and local approval coordinator.
# Execute through the configured boundary
outcome = await executor.execute(
"issue_refund",
version="1",
context=demo_context(),
arguments={
"customer_id": "cus_123",
"amount": "750.00",
},
)06 / QUESTIONS, ANSWERED
No. Praxel sits at the execution boundary. Your agent proposes actions; the registered executor enforces the policy and approval path before invoking a tool.
IAM grants access to systems and resources. Praxel focuses on whether a specific consequential action within that access has authority to execute.
The executor validates the approval against the frozen action and consumes it atomically before dispatch. The resulting signed evidence links authorization, approval and the observed outcome. Consumption alone is not evidence of success.
The implemented local protocol rejects replay and mismatched actions. It provides at-most-one consumption of a particular approval, not distributed exactly-once settlement or deduplication of newly authorized requests.
The core approval protocol uses explicit policy, argument binding, signatures and state transitions. Its security checks do not depend on an agent judging its own actions.
No. Local reviewer identity is session-authenticated. The MVP trusts the host, clock, database and signing-key custody. It does not prove physical human presence, compromised-host truthfulness or external payment settlement.
The tested local approval path blocks dispatch without valid authority. If an approval was consumed but no signed outcome was recorded, the outcome remains unknown and requires manual recovery; it is not automatically retried.
BOUNDED AUTHORITY. MORE POSSIBILITY.
See Praxel stop, authorize and prove a consequential agent action.
Leave your work email. We’ll follow up to arrange a walkthrough.