Golden Gate Bridge, San Francisco

RUNTIME CONTROL FOR AI AGENT ACTIONS

Control agent actions
before they become records

Before an AI agent changes a system of record, TekCapitol checks the controls that matter and returns Allow, Pause, or Block.

Your existing identity, policy, approval, risk, and governance controls stay in place. Check Write™ evaluates the relevant evidence at the moment of action.

AGENT ACTION
Change payment beneficiary
Corporate payment · $240,000
CHECK WRITE™
Evaluate required controls and current evidence
IdentityPASS
AuthorityPASS
Transaction policyPASS
RiskREVIEW REQUIRED
ApprovalPASS
ALLOW · PAUSE · BLOCK
PAUSE
Reason: Risk threshold requires review

Illustrative decision. Your code still owns the write.

Call Check Write™ before the consequential action

It returns Allow, Pause, or Block. Your code still owns the action.

Allow Pause Block
Try Check Write™ → View developer docs →

npm i @tekcapitol/tc-protect-sdk · View on GitHub →

Agents write into systems of record. The stakes are real.

CRM, ERP, finance, ITSM, and databases already have identity, approval, and policy controls. An AI agent can still take a consequential action before those controls are evaluated for the write that is about to happen.

Call Check Write™ before the action. Allow, Pause, or Block. Your code still owns execution.

Four steps. One decision.

Call Check Write™ with the write intent. It resolves required controls, evaluates current evidence, and returns Allow, Pause, or Block.

  1. 1

    Declare intent

    What the agent wants to change, against which system, and with which context.

  2. 2

    Resolve controls

    Identity, policy, approval, risk, and governance requirements for that action.

  3. 3

    Evaluate evidence

    Each required control is checked against current evidence from your systems.

  4. 4

    Return decision

    Allow, Pause, or Block. Your application, harness, or orchestrator proceeds or refuses.

View architecture →

Called before the write. Decision returned. You execute.

Your application calls Check Write™ before the consequential action. Evaluation returns Allow, Pause, or Block with per-control detail. TekCapitol does not sit as a silent proxy between your systems.

Customer owns the controls and the write. Check Write™ returns the runtime decision.

Your frameworks, identity, approvals, risk, compliance, context, and systems of record stay yours.

Check Write™ resolves required controls, evaluates evidence, returns Allow, Pause, or Block, and records decision evidence (Trace).

Diagnose. Fix. Protect.

The broader TekCapitol approach for moving agent workflows into production safely. Check Write™ is the developer call inside TC Protect™.

TC Diagnose™

Know what controls are required.

Assess the workflow, suggest required controls, and promote them into Protect after human confirmation.

TC Fix™

Close the control gaps.

Generate remediation guidance and control packs.

TC Protect™

Runtime protection for agent actions.

Check Write™ evaluates required controls and current evidence before consequential actions. Your code still owns the write.

Check Write™ The developer-facing runtime call. One API call. Allow. Pause. Block.
Try Check Write™ →

Hosted evaluation. Private production when you need it.

TekCapitol SaaS

Build and evaluate

  • TC Diagnose™
  • Developer onboarding
  • Sandbox
  • Policy configuration
  • Control design

Private Runtime

Decide inside your trust boundary

  • TC Protect™
  • Check Write™
  • Customer VPC
  • Private cloud
  • On-prem
  • Regulated environments
  • Customer-owned enterprise controls
  • Customer-owned write

Same decision logic. Different trust boundary.

Ready to control one agent action?

Start with one consequential action. Call Check Write™ before the write.

Try Check Write™ → View developer docs →

GitHub · Docs · Plans

TekCapitol · TC360 · San Jose, CA · Runtime control for AI agent actions

Data access

Metadata-first by default. Private deployment is available when control evidence or enforcement must remain inside your environment.

Details and access models: Security & deployment.

How we assess

TC Diagnose™ scores one AI agent workflow when you still need a map before wiring TC Protect™. The end state is Check Write before consequential actions. Details: Security & data handling.