Built around one idea: verify the outcome, not the answer — in testing and in production. Here is the full list, grouped by when it works for you.
Every attempt acts on fresh fake accounts that mimic Stripe. No real users, data or charges — ever.
fresh fixture per attempt22 templates for refunds and cancellations; repeat runs catch flakiness, version diffs catch regressions.
versioned & approvedDescribe your agent; COLVO drafts scenarios — request, approved rule, starting data. A human approves before anything runs.
metered, advisoryGenerates hostile and edge inputs — injection attempts, boundary amounts, ambiguous cancels — and reports what got through.
blocked vs throughPASS / FAIL / INCONCLUSIVE from explicit checks against state. A semantic judge can comment; it never flips a FAIL.
no false greensRun the suite from CI or on a schedule; fail the build on FAIL; alert on regressions.
cli · cronEvery proposed action is evaluated against the mandate and returns ALLOW / REVIEW / HOLD / DENY with reasons.
before the writeRisky actions pause for a person, who signs an exact digest of what will happen.
human-in-the-loopCOLVO reads ground-truth state on its own and compares it to the rule. The reply is just a claim.
state, not textStable business keys, reservations and an outbox: a retry never creates a second refund.
exactly-once effectPrompt-injection and PII detection with redaction on input; groundedness and toxicity on output; enforce or advisory per rail.
input · outputActions and spend per customer in rolling windows — HOLD or DENY when a single end user exceeds them.
per subjectStop new writes for a project instantly; in-flight actions are held and reconciled, never lost.
one clickMISMATCH, UNVERIFIABLE and TEST_FAIL open incidents with evidence; Slack, email and webhook alerts.
open → resolvedAppend-only log of every request, decision, action and state snapshot. JSON, CSV and PDF per run.
JSON · CSV · PDFPer organisation and date range: decisions, approvals, guardrail hits, verifications — SHA-256 chained and recomputable.
tamper-evidentPass rate over time, flakiness, block rate, cost per run, where the agent keeps breaking.
trendsEvery AI call metered: known from the gateway or estimated from the catalog, never a hidden €0. Caps at org and platform level.
BYOK or managedProjects with owner / editor / viewer roles and strict per-organisation isolation on every resource.
multi-tenantWho did what and when — sign-ins, key changes, plan changes, decisions — for your team and for security review.
auditFree is Test-only with 100 runs a month. Test adds the CI gate and schedules. Guard adds live protection, guardrails, caps, compliance export and the red team. Compare plans →
Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.