Your agents can act.
Keep authority in your hands.
For teams deploying agents to business clients. Connect supported runtime observations to an accountable owner, approve a reviewed tool and its scope, and keep signed evidence of what was allowed, blocked, and executed.
Start with one managed Linux workflow. Agree on the host, approved files, responsibilities, and success criteria before installation.
Keep authority as you delegate work.
- 01
Name the accountable owner
Connect the agent to your organization and the principal responsible for approving its work.
- 02
Approve the tools
Review evidence for the exact version before issuing a FLINT Stamp and Tool Passport. A scan alone grants no permission.
- 03
Enforce the mandate
Define approved actions, destinations, data access, and spending. Check current permission before supported execution.
- 04
Show what happened
Retain signed decisions and outcomes that connect the agent, approved tool, assignment, and policy.
Proven in our private Linux reader pilot: an approved public-file read returned exactly 54 bytes; an unapproved file was blocked; a request against the revoked assignment did not execute. Signed decisions and outcomes were retained. The boundary is a reviewed, immutable snapshot inside the managed sandbox. Unrelated host processes and arbitrary customer folders are outside coverage.
Give every agent an accountable owner.
See registered agents, inspect their mandates, and connect signed observations from installed sensors to identity records. Command separates what an agent claims it can do from what its principal permits and what its assigned tool supports. Coverage reflects connected sensors; it does not claim discovery of every agent on your network.

Registered agent inventory and status. Product preview.
Withdraw permission when the situation changes
Revoke one tool assignment to block its next online Gateway evaluation. The Agent Passport and original evidence remain intact; reapproval requires a new assignment. Freeze the Passport when its wider authority needs review. These controls do not cancel a call already authorized or running, or reverse a completed transaction.

Reversible Passport freeze at FLINT authorization checks. Product preview.
Answer “Who approved this?” with evidence
Show which agent requested access, which tool version was approved, which policy applied, and what happened after the decision. Command signs authorization and execution outcomes separately so permission is never mistaken for proof of completion. Search and export linked verification records in the Record Vault, and retain signed invocation evidence for review.

Records built to be read by anyone who asks. Product preview.
Make permission a condition of execution.
Define the actions an agent may take, the destinations it may contact, the data it may handle, and the amount it may spend. Command keeps approved authority and tool assignments versioned. A short-lived Gateway policy brings those permissions together and checks supported calls against their active intersection. Mandate X-ray lets operators inspect the agent's declared scope.
FLINT works where agents work
Start with a supported agent workflow. We scope how Command connects to your application, identity systems, and operating environment during pilot onboarding.
Inspect a tool before it gets access to your business.
A skill can contain instructions that redirect an agent. A tool can fetch code, read sensitive files, or attempt to send data somewhere you never approved. Detonate examines supported artifacts and observes their behavior in an isolated sandbox so you can review the evidence before deployment.
Inspect the artifact
Look for prompt injection, suspicious instructions, tool poisoning, and dependency risks. Coverage identifies which checks ran.
Observe its behavior
Exercise installation, loading, and use in an isolated environment. Review attempted network access, file activity, and unexpected execution.
Keep the evidence
Receive findings and a signed report tied to the exact version tested. Use it for your own review or submit it into Command’s separate approval process.
Start with a standalone assessment. Artifact support and pricing are confirmed before intake. Self-service payment per assessment, including x402 microtransactions, is planned. Assessment coverage is bounded; a passing result does not guarantee a tool is vulnerability-free.
Request a tool assessmentFLINT Command, answered.
What is FLINT Command?
FLINT Command helps teams deploying agents to business clients connect observed runtimes, accountable owners, approved tools, and signed execution evidence. Start with one scoped workflow on a supported Linux host. Managed pilots are available through a design partnership.
What does installation cover?
FLINT scopes the Linux host, visible processes, supported runtime versions, and one managed workflow before installation. The tested reader accesses an approved file in an immutable snapshot inside gVisor, with no host mounts or network. Registered Passports and sensor observations are shown separately. Unrelated host processes, arbitrary folders, and Windows or macOS monitoring are outside this pilot.
Can we start with tool screening alone?
Yes. Ask for a standalone assessment of a supported skill or tool. FLINT Detonate inspects the submitted version and observes behavior in an isolated sandbox, then produces findings and a signed report with explicit coverage. Contact us to confirm artifact support and pricing. Self-service per-assessment microtransactions are planned; they are not available as checkout on this page.
Does a passing scan automatically approve a tool?
No. A scan is evidence for review. A FLINT Stamp, Tool Passport, agent assignment, and current policy are separate steps. Approval is tied to the exact artifact version. A passing assessment is not a guarantee that a tool is free of vulnerabilities.
What evidence does FLINT Command produce for auditors and examiners?
Command signs the invocation decision and the execution outcome as separate records. They connect the agent, tool version, assignment, policy, and result. The Record Vault supports searching and exporting linked verification records; signed invocation and outcome evidence can also be retained for technical review.
What does the kill switch stop?
Revoke a tool assignment to block its subsequent online Gateway calls while preserving the Agent Passport and original evidence. Freeze the Passport when the agent’s wider authority needs review. Neither action cancels an already-authorized or running call, reverses a settled transaction, or controls traffic outside the governed path.
What has been demonstrated in production?
The private Linux reader pilot returned exactly 54 approved public bytes with signed ALLOW and successful outcome evidence. An unapproved file request returned BLOCK without execution. A later request against the revoked assignment returned signed ASSIGNMENT_REVOKED and not_executed; its tool and assignment had also expired. The separate fixed x402 adapter completed a $0.01 verification call on Base. These are bounded first-party pilots, not arbitrary customer-tool execution or proof of complete network discovery.
How do we get FLINT Command?
Request a tool assessment or scope a managed Command pilot for one agent workflow. We agree on supported tools, installation, operating responsibilities, and pricing before onboarding. SDK access and usage billing are part of the product direction; this page does not offer an already-released paid Command SDK.
Put your first agent workflow under governed control.
Bring one workflow and a named owner. Together, we confirm the supported Linux environment, review its tools, define its permissions, and demonstrate what happens when an agent requests something outside its approved scope. We agree on support, responsibilities, and pricing before onboarding.
- • An agent tied to an accountable principal.
- • A reviewed tool version and an explicit assignment.
- • An approved call that executes and a prohibited call that is blocked.
- • Signed evidence your security and operations teams can inspect.