Agent governance
AI agents with guardrails: scope, budgets, approval
Let agents do real work without handing them the keys. Limit an agent to chosen clients and projects, make it read-only, give it a monthly budget or an end date, decide who may ask it, and see in a log everything that was changed and by whom.
Pick the clients and projects an agent may touch. Anything else looks like it doesn't exist.
How it works
- Open Team → AI agents and choose the agent. Its settings hold everything below.
- Scope it: pick the clients and projects it may touch. Leave both empty for no limit.
- Decide who may ask it: everyone, or chosen roles and named people.
- Set limits: read-only, a monthly budget for model cost and for logged time, and an end date for temporary agents.
- Write its instructions: how your team works. Every session starts with them.
- Optionally add a webhook so a request starts the agent, and read the activity log whenever you want to know what changed.
Limits the agent can't talk its way around
Scope, read-only and access are enforced in the data layer, not in a prompt. The same rules apply to MCP and REST: out-of-scope tasks look like they don't exist, time can only be logged to projects in scope, reports only contain what the agent may see, and tasks with no project or client are outside any scope. A read-only agent is refused every tool that writes, except reporting its own time and requesting an agent.
Budgets that pause, not surprise
Give an agent a monthly limit on the model cost it reports and on the time it logs. Over budget, it is paused: it keeps its connection but gets no new work, hand-offs to it are refused with a clear message, and the owner and admins get a push. It starts again by itself in a new month or when you raise the limit.
Temporary agents and who may ask
- An end date turns an agent off like any other: its token and connections stop at that moment
- Access can be restricted to roles (for example managers) and named people
- A restricted agent can't be @mentioned, DM'd, assigned a task or steered by anyone else, and can't be reached through another agent they do have access to
- Only admins add agents. Anyone, people or agents, can request one, and an admin approves or declines it
Instructions that live in Hourtick
The agent's instructions, its harness, are written in Hourtick by its owner or an admin, never by the agent itself. They lead every context the agent receives, so Claude Code on one laptop and a script in CI follow the same rules. Every version is saved with who made it, and a click on "Use this" restores an earlier one.
Webhooks that start agents
A queued or resumed request calls the agent's webhook: a signed JSON call, or a GitHub repository_dispatch event that can start a workflow running a coding agent. Calls are HMAC-signed, use https only, go only to public addresses and never follow redirects, time out after 8 seconds and retry with backoff. The last result is shown on the agent and failures are logged. The signing secret is shown once and never passes through MCP.
A log of who did what
Every change to an agent is recorded: created, edited, turned off or on, paused or resumed and why, instructions changed, webhook set, token rotated or connection added. Agents can't change agents at all, including their own owner's other agents, so governance can't be loosened from the inside.
Connect as the agent, not as yourself
When you connect an AI app by signing in, the consent page asks whether it should work as you or as one of your agents. Choose an agent and everything it does is attributed to that agent, with its limits, and Hourtick re-checks on every request that you may still connect it.
Frequently asked questions
Is scope enforced for both the API and MCP?
Yes. The same data layer enforces scope for REST and MCP, so there is no side door.
What happens when an agent goes over budget?
It is paused, no new work is handed to it, and its owner and admins are notified. It resumes when the month rolls over or the limit is raised.
Can an agent change its own instructions or limits?
No. Instructions and governance settings can only be changed by people: the owner or an admin.
Can a read-only agent still log its time?
Yes. It can report its own time and request a new agent, but every other write is refused.
Can I use this with Claude Code, Codex, Cursor or Grok?
Yes. Any agent that speaks MCP is governed the same way. The webhook can start it through GitHub Actions or your own endpoint.
Does governance cost extra?
No. Everything is included on every plan.
Guides
What is an agent harness
The harness is everything around the model: context, tools, memory, checks and guardrails. Why it decides how well AI agents do real work.
Human review of AI work
How to review AI agent work so a person is accountable, review time is counted and clients can see a record: roles, steps, and what to keep.
More features
AI agents
Give an agent a seat on the team. It takes tasks, asks when stuck and logs billable time of its own.
AI work reports
What an agent task really cost, and a frozen client report that shows a person checked the work.
API and MCP
A documented REST API and an MCP server that Claude, ChatGPT, Codex and Cursor sign in to.
Workspaces and data
Roles, several workspaces, EU data, a choice of EU or US file storage and no surveillance.
Costs and profit
Revenue, cost, profit and margin per client, project or person, for people and AI agents.
Integrations
Link tasks to Linear, Notion, Teamwork and Asana, and the tracked time follows.
Track your first hour in a minute.
Free for your whole team, forever. $29/month when you need 5 GB.