HiveKey
Enforcement

Decide and act on every action.

Most agent tools watch and log. HiveKey decides and acts — allow, block, or approve — on every tool and MCP call, in the path, before anything happens. These are the capabilities that put your policy to work.

How it works

One decision, in the path, on every call.

Every capability below is the same four beats — only the rule in the middle changes. The agent attempts an action, HiveKey evaluates it against your policy, enforces a verdict before anything reaches the tool, and writes it to one trail.

01

Intercept

Catch the action in the path — nothing reaches the tool yet.

02

Evaluate

Check scope, ceilings, and signals against your policy.

03

Enforce

Allow, block, or route to a human — per action, per role.

04

Log

Write the verdict to one trail, attributable to the owner.

in the path
mail_send → digest to customer allow
payments_pay $42 (under cap) allow
deploy → prod (review not approved) block
key_rotate prod (awaiting 2nd approver) approve
payments_pay $5,000 → new vendor block
allow

Allow

The call is in scope and under every limit. It runs — and is logged.

block

Block

It breaks a rule — out of scope, over a cap, or wrong order. It never reaches the tool.

approve

Approve

Risky but legitimate. It's held for a human to release before anything happens.

One spine

Every capability rides Scope, Guard, and Log.

Enforcement isn't a separate product — it's what the spine does on each call. Scope sets what an agent could do, Guard decides this action in the path, Log makes it provable.

Put every agent under one policy — and enforce it.

See HiveKey decide, enforce, and log every action your agents take, in the path.