Automated policy enforcement for AI agents

Control what your AI agents can do.

HaltState automatically checks connected agent actions against your policies before they execute—before money moves, data leaves or production systems change. Permitted actions proceed. Prohibited actions are blocked. Human approval is requested only when your policies require it.

AI-assisted policy setup. Deterministic enforcement. Signed audit evidence.

Automated enforcement. Human approval only where policy requires it.

Set the rules with AI assistance, review and activate them, then let HaltState enforce them automatically on connected actions.

  1. Set your policies

    Use the AI Policy Assistant to help draft controls. An authorised operator reviews and activates them.

  2. Enforce automatically

    The policy engine checks each connected action before execution. Actions that satisfy the rules proceed; prohibited actions are blocked.

  3. Review when required

    Actions needing human authorisation are held for review. Routine permitted actions do not wait for a click.

Reviewing a policy during setup is not the same as approving every action at runtime.

One policy, three clear outcomes

Illustrative refund policy—not live activity or your production settings.

Valid, non-duplicate refunds up to A$100 are permitted. Duplicate refunds are blocked. Valid, non-duplicate refunds above A$100 require human approval.

Automatically allowed

Proposed action
A valid A$80 refund with no duplicate
Policy rule
Within the configured automatic limit
Decision
ALLOW
Execution
Proceeds without manual review.

Automatically blocked

Proposed action
Another attempt to refund the same order
Policy rule
Duplicate refund is prohibited
Decision
DENY
Execution
Blocked before a second refund executes. No manual review.

Human review required

Proposed action
A valid A$350 refund with no duplicate
Policy rule
Above the configured automatic limit
Decision
APPROVAL_REQUIRED
Execution
Held. It does not execute unless the required authorisation is obtained.

QUARANTINE: Where configured, HaltState can stop further governed actions for an affected agent or session. This is a control over the integrated action path, not a claim to isolate an entire host.

HaltState governs the tool and API actions you connect. It is not a replacement for host security, network isolation or destination access controls.

Enforcement happens before execution. Signed Proof Packs provide verifiable evidence of governed decisions and recorded outcomes for later review.

Where do your agents take action?

Security and AI platforms

Apply your policies before connected agents export data, change records or call production APIs.

Explore agent security

Retail and customer operations

Automate permitted refunds and customer workflows while holding exceptions for review.

Explore retail controls

Building the integration? Integrate an agent.

Product overview

Watch the overview

The existing overview shows HaltState's controls and evidence. Human approval is the policy-required exception, not the default path for every connected action.

Watch the installation walkthrough

Watch HaltState overview on YouTube
Intercepttool calls before execution
Enforceallow, deny, approve, quarantine
Verify signed evidencewith record-level integrity and assurance metadata
Redactcustomer data stays protected

From first risky action to active runtime control.

HaltState starts with one concrete side effect, then guides the operator from SDK install through draft policy review and runtime evidence.

1Identify one risky action
2Install the SDK
3Let the Policy Assistant draft controls
4Test ALLOW, APPROVAL_REQUIRED and DENY
5Activate when ready

After installation, the onboarding wizard can detect or register the agent/action, guide risk selection, let the AI Policy Assistant draft policies, keep a human review step before publication, enforce at runtime, and preserve Proof Pack evidence. The public triage tool prepares a starter action map; it does not activate production policy.

Govern the actions that create real business risk.

Retail and customer operations agents can do real good and real harm. HaltState governs the business actions that affect your customers, your money, and your data.

refund.create

Refunds and credits

Require approval for high-value refunds. Deny suspicious refund loops. Preserve proof for audit.

payment.authorize

Payments and purchasing

Enforce thresholds, pause unusual spend, and quarantine runaway agents before money moves.

customer.pii.export

Customer data access

Block unnecessary PII exports, require approval for sensitive reads, and redact evidence safely.

customer.email.send

Customer communications

Review outbound emails and SMS, stop policy-violating messages, and keep generation-labelled decision evidence.

database.write

Production and database writes

Deny destructive operations, freeze writes during incident windows, and capture policy version and actor.

Runtime AI agent governance controls actions while they execute.

Runtime AI agent governance is the process of controlling autonomous agent actions while they are executing in production. Instead of relying only on prompts or pre-deployment tests, runtime governance intercepts tool calls — such as refunds, payments, data exports, database writes, or customer messages — and evaluates them against enforceable policy before the action reaches a real system.

HaltState provides this enforcement layer and preserves verifiable evidence of each decision, helping teams support incident response, internal controls, and regulatory alignment.

ALLOW refund.create USD 126 APPROVAL_REQUIRED refund.create USD 520 DENY customer.pii.export

Built for evidence-driven AI governance.

Regulators and enterprise customers increasingly expect more than policy documents. They expect proof that controls operate at runtime. HaltState helps teams preserve action-level evidence for internal audits, incident response, and governance programs aligned to frameworks such as California SB 53 / TFAIA, the EU AI Act, New York RAISE, NIST AI RMF, ISO/IEC 42001, SOC 2 control narratives, and state-level automated decision-making laws.

California SB 53 / TFAIA

Transparency and incident-response evidence for runtime decisions.

EU AI Act

Human oversight, logging, and action-control support.

New York RAISE

Evidence for frontier AI safety and reporting direction.

NIST / ISO / SOC 2

Operational evidence and control narratives.

State ADM laws

Automated decisioning transparency support.

Framework-agnostic by design.

HaltState wraps tool calls and business actions at the SDK/API boundary, so teams can start with Python async functions and expand to agent frameworks, custom orchestration layers, and internal tools.

See a refund agent get stopped before execution.

The public Retail Agent Control Room shows a sanitized refund workflow: low-risk refunds pass, high-risk refunds require approval or get denied, and each decision produces a Proof Pack without exposing customer data.

See HaltState live
OpenClaw runtime safety

Put policy between OpenClaw and its tools.

Use pre-execution checks, approvals, scoped stops, and evidence logs before an OpenClaw agent can delete files, send messages, spend money, or change production systems.

Explore HaltState for OpenClaw

Respond first if an agent already caused damage.

Stop the runtime, disconnect risky integrations, preserve logs, rotate exposed secrets, and restore from systems of record before restarting automation.

Open the agent emergency checklist