KIFF · control for AI agents in production
Change what your AI agents may do. Without a release.
The rules live on a card the business controls, not in the agent’s code.
set by the owner
refunds-agent wants to refund €1,500 on a paid order. Already used today: €4,000.
agent code changed0 linesevery changeon record
busy weekend · refunds limit €5,000 → €20,000
Same change. Two ways.
- Open a ticket
- Edit the prompt or config
- Review and test
- Deploy
- Monday: do it all again
2 releases
- Owner sets €20,000
- Monday: owner sets €5,000
0 releases
Both changes saved, with who made them.
2 a.m. · one agent misbehaves
Stop one agent. The rest keep working.
tap an agent to revoke its card
Every agent holds its own cards. Revoking a card withdraws only the authority that card granted; other agents keep theirs.
the auditor asks · who allowed what, and when
Every change. On record.
changes to this card
- rev 314:20limit €5,000 → €8,000anna@retailer.example
- rev 2Monlimit €20,000 → €5,000anna@retailer.example
- rev 1Frilimit €5,000 → €20,000marc@retailer.example
owned by the business
Only an owner or admin can issue, change or revoke a card. The agent can only ask.
new models start small
Give a new model its own card with a low limit. Raise it when its statement looks right.
your system still acts
KIFF answers yes or no. Your code runs the refund, as it does today.
not a mockup · the real app, sample data
Open the owner’s console.
how teams adopt KIFF
Free to build. Paid when it runs your business.
Framework + Guard
Open source. Put KIFF in front of any agent action, on any stack. No contract, no procurement.
Start building →For the company
- Company workspace
- Owner controls for every card
- Dashboard and statements
- Full history and evidence
- Grows with your agents
Production Launch
We connect your first real action, issue the first cards, test the controls and hand it over.
Get it live with us →Questions teams ask first.
Do I have to rewrite my agent?
No. You add one call before the action. If KIFF says no, your code stops. It works with Agno, LangGraph, OpenAI, Google ADK, Strands, n8n or your own code.
d = kiff.decide("issue_refund", order=order, amount=amount)
if not d.allowed:
return d
payments.refund(order, amount) # your code, unchangedCan the agent raise its own limit?
No. The agent’s key can only ask for a decision. Only an owner or admin of your KIFF account can issue, change or revoke a card.
What if KIFF cannot read the balance?
The answer is no. An unknown balance is never treated as zero, and a retried request is only counted once.
Does KIFF run the action or touch payments?
No. KIFF only answers whether the action is allowed. Your system runs it, as it does today.
Is it only for money?
No. A card can limit amounts, or how many times something happens: three account deletions an hour, two deploys a day.
We build agents for clients. Does it fit?
Yes. Ship the same agent to every client. Each client holds its agents’ cards in its own KIFF account and changes them without calling you.
Give every agent a card.
Open your assistant with a prompt to read llms-full.txt and answer from it.