EXECUTION SECURITY FOR AI AGENTS

Give AI agents
autonomy.
Not unlimited
authority.

Praxel controls consequential actions before they execute, binding approval to the exact action and producing signed evidence of the outcome.

See exact-action authority in under 60 seconds.

EXECUTION BOUNDARYINTERACTIVE PREVIEW
AGENT PROPOSES

Issue refund $750.00

Intercepted
Frozen before execution
PraxelLOCAL APPROVAL
ACTION REQUIRES APPROVAL

Issue refund

$750.00

Customercus_123
AuthorityExact action · single use

Approve this exact action once.

Simulated action. No money moves.
Scope and limits: Security & Evidence below.
REASON FREELY. EXECUTE WITH AUTHORITY.
Exact arguments One approvalSigned evidence

01 / PRODUCT IN ACTION

The agent proposes.
Praxel controls what can execute.

Try approve or deny above ↑
AGENTIssue refund $750
PRAXELExact-action authority
DECISIONApprove once / deny
TOOLFrozen arguments
PROOFSigned receipt

See Security & Evidence below for current scope and limits.

Book a demo

02 / THE AUTHORITY GAP

Access isn’t the
same as authority.

Agents decide what to do dynamically. Access to a tool should not grant unlimited authority over every action that tool can perform.

TRADITIONAL IAM ASKS

“Can this identity access Stripe?”

EXACT-ACTION AUTHORITY ASKS

“Can this agent issue this $750 refund to this customer, right now?”

03 / HOW IT WORKS

One boundary. Four deliberate steps.

01

Intercept

Freeze the proposed action and its exact arguments before a tool can run.

02

Authorize

Evaluate policy. When approval is required, ask an authenticated local reviewer.

03

Execute

Consume valid approval once. Dispatch only the frozen arguments.

04

Prove

Sign linked authorization, approval and observed execution evidence.

CONSEQUENTIAL BY DESIGN

The actions you cannot afford to leave ambient.

Sendmessages
Spendrefunds
Deployinfrastructure
Deleteresources
Publishcontent
Grantaccess
Illustrative action categories, not a list of shipped integrations.

04 / SECURITY & EVIDENCE

Authority you can verify.

SCOPE & TRUST ASSUMPTIONS

Argument binding

Approval is bound to the disclosed action and arguments. A mismatch blocks dispatch.

Single use

Atomic consumption prevents replay of the same approval in the local protocol.

Expiring authority

An approval must still be valid at consumption and immediately before dispatch.

Fail closed

Missing, denied or invalid approval blocks execution in tested protocol paths.

Signed evidence

Export proof JSON and verify Ed25519 signatures offline with independently trusted keys.

Current scope and limits. This is an unreleased local approval MVP. Automated protocol tests are reported passing; real Chrome validation remains pending. The extension is unpublished. The MVP trusts its registered executor, host, clock, database and signing keys. Reviewer identity is session-authenticated. Receipts do not prove physical human presence, external settlement or correctness of a compromised host.

05 / FOR DEVELOPERS

Add an explicit
execution boundary.

Register your tool, configure policy and approval, then execute through Praxel. The local approval path uses the Python executor and explicitly registered tools.

Actual call from examples/approval_demo.py. Assumes a configured registry, policy, signer and local approval coordinator.

Explore the integration
approval_demo.pyPYTHON
# Execute through the configured boundary
outcome = await executor.execute(
    "issue_refund",
    version="1",
    context=demo_context(),
    arguments={
        "customer_id": "cus_123",
        "amount": "750.00",
    },
)

06 / QUESTIONS, ANSWERED

Know the boundary.

Is this another agent framework?

No. Praxel sits at the execution boundary. Your agent proposes actions; the registered executor enforces the policy and approval path before invoking a tool.

How is this different from IAM?

IAM grants access to systems and resources. Praxel focuses on whether a specific consequential action within that access has authority to execute.

What happens after someone approves?

The executor validates the approval against the frozen action and consumes it atomically before dispatch. The resulting signed evidence links authorization, approval and the observed outcome. Consumption alone is not evidence of success.

Can an approval be reused, or its arguments changed?

The implemented local protocol rejects replay and mismatched actions. It provides at-most-one consumption of a particular approval, not distributed exactly-once settlement or deduplication of newly authorized requests.

Is an AI model deciding whether another AI is safe?

The core approval protocol uses explicit policy, argument binding, signatures and state transitions. Its security checks do not depend on an agent judging its own actions.

Does Praxel prove that a human physically clicked?

No. Local reviewer identity is session-authenticated. The MVP trusts the host, clock, database and signing-key custody. It does not prove physical human presence, compromised-host truthfulness or external payment settlement.

What if approval or execution is interrupted?

The tested local approval path blocks dispatch without valid authority. If an approval was consumed but no signed outcome was recorded, the outcome remains unknown and requires manual recovery; it is not automatically retried.

BOUNDED AUTHORITY. MORE POSSIBILITY.

Give agents authority.
Not a blank check.

See Praxel stop, authorize and prove a consequential agent action.

Request a demo

Leave your work email. We’ll follow up to arrange a walkthrough.