Design-partner program now open

• The control layer for AI agents

Let AI agents act. Keep humans in control.

Quantax sits between AI agents and your business systems. The Permission Firewall gives each agent short-lived access scoped to the step it's on. CommitLayer checks every high-risk action, from payments to deletions, against your rules, evidence and approvers before it's committed, and records every decision.

See how it works

• Try it

An agent's change is held at CommitLayer. You decide whether it commits.

commitlayer · supplier-update Illustrative example · mock data
  1. 01

    Propose

    Agent: update supplier bank details for "Acme Supplies Ltd"

    − payment_details •••• 4821 on file + payment_details •••• 9930 from invoice

    Evidence: Invoice INV-2041

  2. 02

    Check

    Policy: sensitive field "payment_details" → independent verification required · amount threshold · approver authority

  3. 03

    Decide

    Paused · awaiting approval by Finance Controller

  4. 04

    Record

    Audit logged: decision, evidence, system state, hash

  5. 05

    Recover

    Rollback available where the connected system permits

You are the Finance Controller:

• The problem

Agents can now touch real systems. Every high-risk action needs a checkpoint.

01

Agents have left the chat window. They are moving into ERPs, databases, payment tools and SaaS apps, where a single write can delete records, move money or change a supplier.

02

Standing admin keys turn one mistake into many. An agent holding a broad, permanent key can cause mass deletions or an unauthorized transfer in seconds, before anyone notices.

03

Payment details are a known target. Supplier bank-detail changes are a well-known route for business email compromise fraud, and an agent reading a forged invoice can be fooled too.

04

Guardrails check words, not changes. Existing tools inspect prompts and outputs. None look at the access an agent holds or the actual change about to be committed to your systems.

• The Quantax platform

Permission Firewall controls what an agent can reach. CommitLayer controls what it can commit.

Two controls around every high-risk agent action: payments, deletions, transfers and record changes.

BEFORE THE ACTION

Permission Firewall

Instead of a fixed admin key, each agent gets short-lived, step-by-step permissions scoped to what it is doing right now. Access expires when the step ends.

Scoped, just-in-time permission

In development

How grants work →

AT COMMIT

CommitLayer

Every high-risk change is checked against your rules and evidence, paused for a human where it matters, recorded, and recoverable.

Evidence · policy · human approval · audit · rollback

In development

How checks work →

• Speed and control

Routine work stays fast. Sensitive changes get a checkpoint.

Agents keep coding invoices, matching receipts and drafting vendor updates at machine speed. CommitLayer only steps in when a change touches something your controls care about.

commitlayer · today Illustrative · mock data
Agent changeRuleOutcome
Code invoice INV-2038 to 6100Within policyAllowed
Update supplier contact emailLow-risk fieldAllowed
Change payment_detailsSensitive fieldPaused
Approve INV-2044 above thresholdApprover authorityPaused
Release payment runMoney movementHuman only

• How it works

Six steps around every sensitive change.

  1. 01

    Propose

    The agent submits the change it wants to make, with the evidence behind it.

  2. 02

    Check

    CommitLayer tests the change against your policies, fields, thresholds and authority.

  3. 03

    Decide

    Allow · pause for a named approver · block.

  4. 04

    Record

    Every decision lands in a tamper-evident audit trail.

  5. 05

    Recover

    Reversal or compensating steps when something needs undoing.

  6. 06

    Govern live

    Policies are versioned, reviewed and reported on, like any other control.

• Architecture

Two controls between agents and the systems of record.

01 · SOURCE

AI agent

Acts step by step

↓ requests a step

02 · ACCESS

Permission Firewall

Scoped grants · short-lived · expire per step

↓ grant + change

03 · COMMIT

Quantax CommitLayer

Policy · evidence · approvals · audit

○ Human approver · allow / reject

↓ commit

04 · SYSTEMS

Business systems

ERP · Accounting · Payments · Databases · SaaS apps

High-level view. Integration details are shared privately with design partners.

• First workflow

Supplier and invoice changes in finance operations.

We start where the risk is concrete and the controls are well understood: the vendor master and the invoice approval chain.

Next: any system where an agent's mistake is expensive.

ActionCommitLayer requires
Prepare supplier-record updateAgent may propose
Change payment detailsIndependent verification
Approve invoice above thresholdNamed approver
Release moneyHuman approval, always

• Design principle

0 payments moved without a human.

A rule we build to, not a metric we report. Four commitments follow from it.

No autonomous money movement

CommitLayer never releases funds on an agent's say-so. Money moves only after a human approves it.

Details →

Workflow-aware, not generic guardrails

Rules are written in finance terms: fields, thresholds, segregation of duties and approver authority.

Details →

Audit by default

Every proposal, check and decision is recorded with its evidence, whether it was allowed, paused or blocked.

Details →

Security first, least-privilege

The Permission Firewall gives each agent only the access its current step needs, and takes it back when the step ends.

Details →

• Changelog

Recent milestones.

Full changelog →

  • OCT 2026

    quantax.space launched; design-partner program opened

  • MAY 2026

    CommitLayer prototype: supplier and invoice change workflow (propose → check → decide → record → recover)

  • DEC 2025

    Research began on AI-agent safety: permissions, approvals and audit for agents acting in real business systems

  • 2025

    Company incorporated (Delaware)

• Design partners

Help shape the first pilot: one agent, one accounting or ERP workflow, your rules.

We work closely with a small number of finance teams to define policies, test the approval flow and agree what good looks like before anything touches production.

Read the product overview