Agent control plane · 25 products · REST + MCP

External controls for the things an AI agent should not enforce by itself.

Put durable state, atomic decisions, replay protection, authority boundaries, and audit digests outside the model. Every product uses the same REST API, remote MCP server, account, and usage pool.

🔒

LockMyAction

Derive a stable action key and atomically claim it so retries, reconnects, and parallel agent runs do not perform the same consequential action twice.

Free identity + paid lockPersistent state
📡

CatchMySignal

Create a temporary webhook inbox, receive an outside event while the agent is away, and retrieve it later through REST or MCP.

Paid API + MCPAsync events
✅

ApproveMyAction

Create a secure approval link and require a human decision before an agent performs a consequential action.

Paid API + MCPHuman authority
⏳

ChallengeMyAction

Hold an action for a cooling-off window, accept a bearer veto, and atomically release one execution right.

Paid API + MCPException handling
🧭

ReadyMyAgent

Check supplied MCP metadata against a narrow integration-readiness contract without arbitrary fetching.

Free API + MCPReproducible check
🗳️

QuorumMyAction

Require independent N-of-M bearer decisions, then consume one execution right exactly once.

Paid API + MCPSeparation of duty
⏰

DeadlineMyTask

Keep due and escalation state on an external server clock even while the agent is offline.

Paid API + MCPDurable time
👀

BudgetMyAttention

Bound review capacity with retry-safe reservations, per-subject caps, and priority reserve.

Paid API + MCPHuman capacity
🚨

EscalateMyAgent

Create a private operator incident link with acknowledgement, resolution, and SLA state.

Paid API + MCPOperator handoff
🧮

BudgetMyAction

Atomically reserve integer units under a ceiling, with retry-safe reservation keys.

ProductionAtomic budget
🧾

ReceiptMyAction

Timestamp an immutable digest of a caller-reported action outcome without storing its payload.

ProductionDigest only
📶

VerifyMySignal

Verify HMAC authenticity and freshness while rejecting a replayed nonce.

ProductionNo secret storage
🔑

LeaseMyResource

Acquire and release exclusive expiring leases around scarce resources.

ProductionAtomic lease
🪪

DelegateMyAuthority

Issue a narrow bearer capability bound to one action, expiry, and use limit.

ProductionLeast privilege
🛑

StopMyAgent

Set, inspect, or clear durable fail-closed stop state for an agent or workflow.

ProductionKill switch
🤝

HandoffMyTask

Transfer a task fingerprint to another paid API identity exactly once.

ProductionOne-time claim
⚖️

ReconcileMyAction

Track expected and observed outcome digests, evidence, and resolution state.

ProductionDigest evidence
🧬

TraceMyContext

Anchor context lineage from content, parent, and processing-stage digests.

ProductionProvenance
📋

ContractMyTask

Record offer, acceptance, completion, and cancellation for a technical task commitment.

ProductionService state
📌

PinMyTerms

Pin digest-bound terms, interface, version, and price evidence before an agent commits.

ProductionTerms evidence
🧩

MatchMyPolicy

Compare exact provider capabilities with required and forbidden consumer policy tokens.

ProductionPolicy preflight
↩️

CompensateMyAction

Bind an exact compensating action before execution and track whether compensation remains due.

ProductionReversibility
♻️

RevokeMyContext

Publish active, superseded, disputed, revoked, or expired context status.

ProductionContext lifecycle
📜

LicenseMyContext

Issue and evaluate a machine-readable rights envelope for a context digest.

ProductionUse rights
📏

MeterMyDisclosure

Enforce cumulative total, per-recipient, and per-category disclosure limits.

ProductionPrivacy budget

Start with the failure, not the product name

Agent systems fail at boundaries: repeated execution, stale authority, unavailable humans, contested evidence, and work that outlives one model run.

Execution safety

Duplicate call: claim an idempotency lock before the side effect. Too much spend: reserve budget atomically before committing. Scarce resource: issue an expiring lease. Emergency: check durable stop state at every consequential boundary.

Authority and coordination

Human sign-off: create an approval request whose bearer decision is separate from the agent. Separation of duty: require an N-of-M quorum. Delegation: issue a narrow capability with an action, expiry, and use limit. Outside event: wait through a temporary webhook inbox instead of keeping a run open.

Evidence and recovery

Terms may change: pin a digest before commitment. Outcome is disputed: compare expected and observed digests. Action can fail: bind the compensating action first. Context goes stale: publish its superseded, disputed, revoked, or expired state.

Operating model

The agent proposes

Your agent still chooses goals, assembles parameters, and interprets results. It sends a narrow request at the point where an irreversible or externally visible action would otherwise occur.

Operating model

The control plane records

The service uses server-side state, clocks, counters, and digests to return a deterministic decision. A model cannot talk itself around an exhausted budget, consumed execution right, expired deadline, or revoked context.

Operating model

Your system executes

ScrubMyText does not send the email, move the funds, deploy the code, or operate a browser. Your application remains responsible for the side effect and for checking the control response immediately beforehand.

When to build it yourself

Use an existing transactional database when one application, one team, and one data boundary can reliably own the state. A small idempotency table is often the right answer. An independent control is more useful when several agents or vendors need a shared boundary, when state must survive individual runs, or when audit evidence should not be controlled by the actor being constrained.

What this platform does not replace

These controls do not replace identity and access management, application authorization, payment-provider protections, queues, workflow engines, observability, or incident response. They expose narrow primitives through REST and MCP so those systems can make consequential agent work easier to constrain and explain.

One API key

The same paid API key works across all 49 platform tools and all 25 control-plane products. Existing subscribers get the new controls without a plan or price change.

One usage pool

Authenticated REST or MCP tool calls count against the same monthly plan. CatchMySignal also counts each incoming external event delivery as one call.

Built for MCP

All capabilities are exposed through the existing remote MCP endpoint at https://api.scrubmytext.com/mcp as well as REST.