No prompt for every step.
Repeated prompts invite reflexive approval. The goal is to ask at selected consequential boundaries, not turn every tool call into a biometric ceremony.
Verifiable human authority for AI agents
Agents can act. Who gave them the authority?
We’re building an open-source foundation for bounded human authority.
Permission that travels with your agent, verified before the commitment.
Open source · Early development · Built in the open
Find routes that fit
your plans.
Weigh price, timing
and flexibility.
Bring the best option
back to you.
SFO to JFK
$480 total · Nonrefundable
One purchase · Expires in 2 minutes
Your approval is required
Passkey verification · Concept
Example only. No purchase or approval is performed.
Your policy defines when fresh approval is required. Routine work stays within the permissions you already granted.
The system we are building toward
The service enforces the boundary. The agent cannot widen your permission.
A small permission. A precise purpose.
In the Vollmacht design, a Human Mandate binds an agent to a specific action, resource and set of limits. The receiving service or trusted gateway checks that authority before committing the action.
Vollmacht is German for authority to act on someone else’s behalf. That is the idea: delegated authority, not unrestricted access.
A different itinerary or higher price falls outside this permission.
Beyond travel: protected merges, permanent deletion, and financial commitments.
Illustrative integrations in the target design. Each service applies its own policy.
Designed for meaningful oversight
Repeated prompts invite reflexive approval. The goal is to ask at selected consequential boundaries, not turn every tool call into a biometric ceremony.
Passkeys use Touch ID or another supported verification method. Vollmacht does not need your fingerprint. User verification is not proof of humanity or proof that you understood a request.
A mandate only helps when consequential actions pass through a trusted enforcement layer. It cannot stop an agent that can bypass that layer with its own credentials.