AI should feel liberating, not like handing your life to a black box. Aegis is an early build of a human-first trust protocol: your data stays in your control, sensitive actions wait for your approval, and every agent can be stopped in one click.
Conceptual cross-model architecture. No affiliation or current integration with these providers is implied.
Aegis is designed to let a person set portable, enforceable boundaries for every AI they use: what it may access and do, spending and sharing limits, when approval is mandatory, and a universal action receipt with a revoke button and a kill switch.
As agents take on more of representing people — across assistants, phones, banks, and everyday apps — someone has to hold that boundary. A platform that also builds the agent has a structural conflict of interest in also being the referee over it. They can ship a better chatbot; they can’t credibly own the neutral authority layer across their own rivals.
Today this exists as a working sandbox, not a live integration with any provider below — see “Modeled for” above and the honest capability table in /compare.
of consumers say data security and privacy would most increase their willingness to trust a personal AI assistant — ahead of transparency (48%) and human oversight (46%).
Zendesk / YouGov, 2026 CX Trends Report →year-over-year rise in consumer demand for AI transparency — yet only 37% of organizations currently explain how their AI reaches a decision.
Zendesk, 2026 CX Trends Report →names transparency, accountability, and human oversight matched to risk as core requirements for trustworthy AI — exactly the properties a delegation boundary is built to enforce.
NIST AI Risk Management Framework →is how OpenAI describes prompt injection for browser agents — malicious instructions hidden in ordinary web content that can hijack what an agent does next.
OpenAI, hardening ChatGPT Atlas →The sandbox below talks to the live enforcement API. On your first action it creates a throwaway owner account and one API key per agent you try, kept in this browser. The kill switch revokes those keys on the server, so every later call is refused there, not just greyed out here.
Want your own durable account, agent keys and approval queue? Use the owner console.
Set boundaries, then fire sample agent actions. Each one is a real request to the live /api/enforce endpoint with a real agent key, decided server-side and written to a durable decision log. The actions themselves are samples: no email is sent and no money moves.
Any agent can be targeted here — this list isn’t hardcoded to a fixed set of providers, and any of them can be granted access and killed the same way.
The interface model for safely delegating authority to autonomous AI across competing tech ecosystems.
Granular scope isolation. Specify exactly what APIs, files, and channels an agent can touch — regardless of which model runs it.
Rate limits, balance ceilings, and auto-expiring temporary delegation passes to stop runaway agent spending before it happens.
Configurable human-in-the-loop triggers that force explicit sign-off for high-risk actions, transfers, or sensitive data exports.
One click revokes an agent’s API key on the server; its very next enforcement call is blocked, and any approval it was waiting on is cancelled.
Each enforcement decision, approval, denial and revoke is written to an append-only table in Postgres with the actor and a server timestamp. The database rejects edits and deletes to it, including from the app itself. The rows on the right are your sandbox’s, read back from the server.
Approving a held action mints one token bound to the hash of that exact request. A different amount, recipient or agent is refused, and a second use is refused.
Aegis decides; it does not intercept. An agent that never calls the API is not stopped, and log entries are not cryptographically signed yet.
Aegis imagines a future where every agent carries a human-readable mandate, receives only time-bound authority, emits a signed receipt, and can be revoked everywhere at once. Platforms build the intelligence; people keep the authority.
| Governance vector | OpenAI / tech silos | Big tech OS (Apple/Google) | Aegis model (concept) |
|---|---|---|---|
| Cross-rival portability | Locked to internal ecosystem | Restricted to native OS APIs | Designed to be model-agnostic |
| Who defines the boundary | Vendor-defined defaults | Platform-defined defaults | The person delegating, by design |
| Conflict of interest | Referees its own agent | Referees its own ecosystem | Not a model vendor itself |
| Revocation scope | Per-vendor only | Per-OS only | Intended to span providers |
This table describes design intent for this concept, not certified or audited capabilities of any listed company’s products.
Real platforms already solve pieces of this problem for engineering teams. Read honest, researched comparisons before assuming this replaces them.
Compare Aegis to real platformsA protocol concept built for the institutions and developers who will need this once agents act on their behalf across rival platforms — try the sandbox yourself, no signup required.