New Business Rules in the AI Agentic Age Get the free whitepaper
The authority layer for agentic AI

Authority is earned.
Even by AI.

AI agents no longer just answer questions. They make decisions and execute actions on your behalf: they refund, deploy, email and delete, with no human in the moment. TapPass is the layer that decides what each agent may do: gradually, per tool, with every step on the record.

EU hosted · EU AI Act ready · works with your stack
staging.tappass.ai · today
Sound familiar?
How much did you Allow without reading it?

Every connection starts with a dialog like this one. Nobody reads it, everyone allows it. Across your company, agents already hold 0 tools. Their jobs used 0 of them last month.

Allow github-mcp?
The agent will get access to 34 tools, including read_all_repos, create_issue, delete_branch, admin_settings and 30 more.
Allow always Allow once Decline
Every dot is a granted tool. The green ones are the only ones used last month.
There is a better way

From watched, to held, to trusted

01

Watching

See everything first

The agent works, TapPass observes. Nothing is blocked while you learn what it actually does and which rules you're missing.

02

Holding

Pause what matters

Sensitive calls stop and wait for a person. One tap to approve or deny, in milliseconds, with the reason spelled out.

03

Enforcing

Rules that always fire

Proven policies become deterministic. Not a prompt, not a suggestion: a rule enforced on every call, every time.

One layer, four controls

Everything an agent does,
on your terms

Your policies, your words

Policy, in your language

You don't adapt to our platform. We understand yours. Write the rule the way your business already says it, "refunds above €500 need my sign-off", and it becomes enforced reality on every agent call.

"Refunds above €500 need finance approval."
refund > €500require approval · finance
your words, enforced
Intent coverage

Think in outcomes,
never in tools

You should never have to know what an MCP server is. Say which outcomes need control, "issuing refunds", and TapPass covers every technical path that could reach that outcome.

payments.refund
credit_notes.create
invoices.adjust
one rule · "issuing refunds"
Least privilege · progressive authority

Only what they need,
only when they've earned it

Our two safety principles. Each agent gets the tools its job requires and nothing more, and its authority grows step by step as it proves itself, from watched, to held, to trusted.

🔒
🔒
🔒
3 granted · more when earned
Fully deterministic

The same input,
the same decision

Every policy compiles to a deterministic check that runs the same way on every call, so the same request always gets the same decision. Enforcement is code you can inspect, not a model's opinion, which makes every outcome repeatable and explainable to an auditor.

refund €8,200require approval
refund €8,200require approvalIDENTICAL
same input · same result
And, as you'd expect

Everything else enterprises need — handled

Complete audit trailEvery action, hold and approval on one tamper-evident record — produced in seconds when anyone asks.
Human oversight & approvalsPeople stay in the loop on the calls that matter, with sign-off routed to the right person.
Team, role & org controlsOrganisation-wide policy, RBAC and SSO — manage authority across every team from one place.
EU-hosted, your dataHosted in your European region under European law. Your data stays yours.
For the people accountable

Business writes. Security verifies.
Engineering ships.

Agents act on behalf of your whole company. TapPass gives each role direct control over what agents may do, without tickets and without waiting on each other.

Role-based control over what agents may do
Finance lead
"I write the rule in a sentence. It fires on every call."
No policy language, no tickets. The €500 refund rule she wrote at 9:12 was enforced by 9:13.
A refund-limit rule written and enforced automatically
CISO
"Any agent action, traced to a rule and a person. In seconds."
When the board asks what the agents did, he answers with signed evidence, not a reconstruction.
Signed evidence of what the agents did
Platform engineer
"One layer in front of every model and MCP server. Done."
She stopped maintaining allowlists per server. Agents get scoped mandates, and the gateway does the rest.

Let agents ruin
your business.

Yours kept working through lunch. The only thing that reached a human was the one call that needed one.

support-agent answered 214 ticketspass
billing-agent issued 12 refunds under €500pass
research-agent summarized 40 supplier contractspass
hr-agent export held · personal dataheld
billing-agent wants to refund €8,200 to Maria L.
Over finance's €500 limit. Held for a person.
ApproveDenyexpires in 3m
A layer, not another tool

A portable rulebook.
One European hub, every platform.

This is the vision: authority for AI lives in one place you own, hosted in Europe under European law. Agents earn authority progressively and hold the least privilege their job allows. You define the rules once, in your language, and the hub enforces them at runtime and syncs them into the platforms your teams already use. Change a rule once and it changes everywhere.

Your rulebookDEFINED IN TAPPASS
Refunds over €500 need financeActive
written in plain language by finance
No customer data leaves the EUActive
applies to every agent, every model
support-agent: 3 tools, no moreActive
least privilege mandate
AWS Bedrock
AWS Bedrock
synced as guardrails
Azure AI Foundry
Azure AI Foundry
synced as content policies
Claude Code
Claude Code
synced as permissions
Microsoft Purview
Microsoft Purview
synced as compliance evidence
Slack
Slack
approvals in your channel
liteLLM
liteLLM
enforced at the gateway
change a rule once, it changes everywhere no drift between platforms enforced at the gateway even where sync can't reach hosted in your EU region

Your rulebook is your data — yours to keep, yours to leave. Export it in the open, any time. Centralise your AI authority in one place without ever being locked in.

Works with the models and agent tools you already use
OpenAIOpenAI ClaudeClaude GeminiGemini MistralMistral and every agent framework
The whitepaper

Business Rules in the
AI Agentic Age

Why every agent action must pass through a decision you own, and how runtime enforcement makes agents safe to scale.

Get the free whitepaper →
Supported by
Start it @KBC
Start it @KBCBelgium's largest startup accelerator
VLAIO
VLAIOFlanders Innovation & Entrepreneurship