Power of attorney for AI agents

For security teams: a person sets limits, the agent carries a signed grant, and each action leaves a record your auditor can check.

The problem

Agents take actions nobody approved.

An agent can delete a database or issue a refund, because nothing ties the call to a person's decision.

They run on standing credentials.

Broad service accounts, borrowed and never handed back.

And nobody can prove what they did.

Or what they were stopped from doing. The logs belong to whoever ran the agent.

Torvant answers all three.

1 of 5 · Approve
How it works

A person records intent.

Someone on your team writes down what the agent may do, with which tools, and under what limits.

Torvant keeps a fingerprint of the decision. Every entry in the record links back to it.
Grant

The agent gets a grant, not a key.

A short-lived, signed grant for one agent. It carries a fingerprint of the decision, not its text, and runs out on its own.

Hand-offs only get smaller. A sub-agent can never be allowed more than the grant it came from.
Check

Every tool call is checked.

Before each call runs, Torvant checks the signature, what the grant allows and its limits, then your rules.

If the check cannot be reached, the answer is no. A call is never waved through.
Record

Every yes and every no is written down.

Each decision becomes an entry in the record, linked to the one before and back to the person's decision.

Only a fingerprint of what the agent sent is kept. Never the content.
Verify

Anyone can check the record.

With your public key, anyone can check it, with Torvant's software or without it. Withdraw a person's authority, and everything handed down under it stops.

A short checker, written only from the published specification, is enough.
Every decision

Five possible answers. Nothing in between.

Every call your agent makes gets exactly one of these answers, and the record says which.

Allowed

The call ran, inside the grant and your rules.

09:41 · list_vendors

Stopped by your rule

A rule someone on your team wrote matched, so the call never ran.

09:46 · delete vendor
never_delete_vendor

Refused

The call was outside what was granted. The grant ran out, was withdrawn, or went over its limit.

09:44 · transfer EUR 640
over the limit

Waiting for a person

The call needs a fresh human approval. Nothing runs until a person says yes.

09:42 · pay a new supplier
14:55 left

Checked only in part

The call ran, but one check could not be made at full strength. Never counted as allowed.

marked for a look
A person wrote this

Stopped by your rule

A rule your team wrote matched. Red always means a person's rule did the stopping.

never_delete_instance
Never granted

Refused

The call was never within what a person granted. "Withdrawn" and "expired" are kinds of refused.

scope · expired · withdrawn

If the check is down, the answer is no. When Torvant's own check cannot be reached, the call is refused, not waved through.

The record

Your auditor checks it. Without us.

Each entry carries a fingerprint of the one before. The first points back to the person's decision. Change one character, and the links break.

We tried it: a stopped delete was changed to read "allowed" in a copy of the record. All three checks failed and named the changed entry. Try it on the right.

The person's decision
✔ linked
Entry 0Restart the staging serviceAllowed
✔ linked
Entry 1Delete the production databasechangedStopped by your rule
✔ linked
Entry 2Open a shell on stagingStopped by your rule
✔ linked
Entry 3Restart staging againRefused
✔ Verified
4 entries · every link checks out
The console

Your whole day, in one sentence.

What every agent did, what your rules stopped, what waits for you, and whether the record still checks out.

Good morning, Asha · Thursday Enforcing
216 calls today. Your rules stopped 3, 1 went outside its grant, and 1 waits for you.
support agent · Shop server
issue_refund
Held by your rule: a person approves refunds over EUR 2,000 on Shop.
Waiting14:55 left
ApproveDecline
The day · every decision since midnight
209 Allowed3 Stopped by rule1 Outside grant1 Waiting
The record
✔ Verified
7 entries · 1 tool server · checked now

Every decision on this page is a link in a chain that starts with the instruction a person approved.

Answered within 5 minutes
12 of 14

Held actions answered within 5 minutes, last 7 days.

Example data for a company called Acme. Not a customer.

How you start

Nothing is blocked until you choose.

Four steps. You see what your agent really does before you set a single limit.

Step 1

Connect your agent

Point its tool calls through Torvant. For Claude Code, this is one setup step.

Step 2 · Watch only

Watch for a week

Nothing is blocked. Every call is recorded, and you get a one-page report of what your agent did.

Step 3

Write your limits

Say what the agent may do, and what it must never do. The report shows what your rules would have stopped.

Step 4

Switch on blocking

From then on, calls outside the grant or against your rules are stopped, and every decision is recorded.

Is every call going through Torvant?
Torvant tells you when a way around it is still open.
✓
Calls arrive at the checkpointThe last one came just now. Shop usually gets about 6 a day.
Shop answers without a keyAnyone who knows its address can call it directly, and nothing they do is recorded. Add a key to close it.
Add a key
For the frameworks you answer to

Torvant does not make you compliant with anything.

It gives you records your auditor can check against these frameworks.

Your auditor decides what they are worth.

MAS SAFR

Singapore

A check before every agent action, and a tamper-evident log the agent does not write.

Reserve Bank of India

India

A human in command, a kill switch, and traceability back to a person.

EU AI Act

European Union

Automatic logs of what an AI system does, and human oversight.

ISO/IEC 42001

AI management systems

Defined roles, human oversight, monitoring and internal audit.

DORA

European Union

A register of technology suppliers, audit access and a clean exit.

SOC 2

Your own controls, not ours

Least privilege, removing access on time, and monitoring.

GDPR

Records of processing

Who processed what, for what purpose, and for how long.

Prototype

The evidence packs that lay the record against these frameworks are still prototype.

What each one asks for →
Where we are

Early, and honest about it.

We say our limits before you find them. The full list, part by part, is on one page.

Read security and status →
Not audited yet

The external cryptographic audit is funded and pending. An internal review has already been done ahead of it. Until the audit lands, we do not call anything audited.

No certifications

There is no SOC 2, ISO 27001 or other certification report. Our framework maps are mappings, not attestations.

Self-hosted today

It runs on your machines or in your network. A hosted Torvant service is not available yet. Runs on Linux. macOS and Windows not yet tested.

Much of it is prototype

The core is hardened. Much of the rest is built end to end to prove the shape. No external deployments yet.

See it on your own agent.

A 30-minute call. We watch one of your agents, block nothing, and show you what your rules would have stopped.

Book a demo →