Alfred · governance for AI agents
Alfred holds the keys
Your AI (artificial intelligence) agents propose the risky action. Alfred decides, holds the keys, and keeps the receipts.

Alfred. He holds the keys, keeps the books, and hands you the receipt. Your agents propose. He is the one who acts.
01 · What it is
The trusted house manager
The name fits on purpose. Alfred is the reliable operator who holds the keys, keeps the books, and will not do something reckless just because he was asked to.
Your agents are brilliant, tireless new hires. You would not give a new hire the company card and the master keys on day one. Alfred is the layer that lets them work at full speed while the keys, the rules, and the record stay in hands you can vouch for.
Thinking is free. Doing is checked. Let your agents read, draft, summarise and plan all day, because none of that needs a gatekeeper. The gate closes only around the small number of actions that cost money, touch a customer, or cannot be undone.
02 · What it does
Five jobs, nothing more
Alfred never touches the work itself. It governs the handful of moments where the work reaches the outside world.
Checks the action
Before anything consequential happens, Alfred confirms it is allowed: the right agent, the right reason, inside the limits you set. If it is not, it stops there.
Holds the keys
The password to your billing system, your email, your membership platform: Alfred holds it, not the agent. A hacked or confused agent simply cannot do the dangerous thing. This is the heart of it.
Writes a sealed receipt
Every decision becomes a tamper proof record, signed like a notarised document. You can prove what your AI did, and what it chose not to do.
Pauses for a human
Large refund, or something you cannot reverse? Alfred holds the action and asks a person to approve it, with a deadline so nothing hangs forever.
Stops what is running
If something starts going wrong halfway through, Alfred halts it, cuts off that agent's access, and hands you a clean record of what happened.
03 · What it is not
Three things it will not be
Not another AI that does your work
Alfred does not answer customers or write content. It governs the agents that do.
Not a dashboard you read afterwards
It acts before the action, not in a report you open the next morning.
Not a rip and replace
It slots in beside the tools you already run. Nothing gets thrown out.
04 · Rollout
Start with your scariest action
You do not govern everything on day one. You get safer one step at a time, and each step stands on its own.
01
Name the risky handful
List the few actions that actually worry you: issuing refunds, changing a membership, sending mass email, deleting records. That short list is the whole job.
02
Move one key into Alfred
Take the password for your riskiest system out of your automation and give it to Alfred. That action is now governed, and your agents can no longer take it alone.
03
Turn on the receipts
Every decision flows into a record you keep. From here, the question 'what did our AI do?' has a provable answer.
04
Repeat for the next one
Add the next risky action, then the next. Coverage grows without a single large migration, and you can stop when it is enough.
05 · Connecting your tools
Three ways to plug something in
Ask Alfred first
For your automation tools. You drop one step in front of the risky action, and the workflow continues only if Alfred says yes. Simplest place to start.
Hand Alfred the key
Strongest, and the one to aim for. For billing, payments, membership and email, give Alfred the credential instead of your agents. No key, no action. This is a guarantee, not a rule.
Give the model a permission tool
For the AI models themselves. Your models are handed Alfred as a tool they must call to get an action approved. They can ask. They cannot act.
Where it runs. Your keys and your records stay under your control, inside your own environment. Nothing has to leave your walls.
06 · The payoff
What you can now say
A customer, an auditor or an investor will ask how you keep your AI from doing something it should not. In 2026 that question becomes a deal gate.
You do not point at a policy document and hope. You show them signed receipts of every decision your AI made, and you explain that the risky actions are not blocked by good intentions. They are blocked by the fact that your agents never held the keys in the first place.
“We told it not to.”
It literally cannot.
Plain-language overview. Engineering detail available on request.
Two ways to start: see what your agents are already doing, or prove a decision you would have to defend.