PERMISSION/PROTOCOL

Pricing

Pricing for controlled autonomy

Two ways in: install the open-source wedge free, or run a paid rollout with our team.

Pricing is per named signer of record. We never meter the actions you gate or the receipts they mint: coverage is the point, accountability is the unit.

Pricing ladder

Free

Developer proof

$0

Team

MCP Guard for teams

$100 / signer / mo

Design Partner Pilot

One high-consequence workflow

$50K / 8 wks

Enterprise

Org-wide enforcement

from $150K/yr

Motion 1

Developers

Install the open-source wedge, prove the receipt on one repo, and bring your team when ready.

Developers

Free

Developer proof

$0

Ongoing

MCP Guard is open source. One signer, one connected repo or MCP client, and real signed receipts.

See PP block and authorize an agent-written PR before involving procurement.

Scope

  • 1 signer of record
  • 1 connected repo or MCP client
  • GitHub Deploy Gate
  • Cryptographic approval receipts
  • Basic audit trail

Features

  • Block agent-written PRs before merge
  • Require human authorization
  • Generate signed receipts
  • Verify approval state in GitHub

Success & privacy

  • Self-serve docs
  • Example repo
  • Community support
  • No training on your code
  • No source-code retention by default
  • Receipt-based audit trail
Start free

Developers

Team

MCP Guard for teams

$100 per signer / month

Billed annually ($125 monthly), 3 signer minimum, up to 10 signers

Shared policy plane, central receipt vault, and drift visibility for teams running agents in production.

Pricing follows accountability: you pay for the humans who can sign, never for the actions you gate.

Scope

  • 3 to 10 signers of record
  • Shared policy plane
  • Central receipt vault
  • Drift visibility

Features

  • Everything in Free
  • One policy for every seat
  • Team-wide receipt trail
  • Unmetered gated actions and receipts

Success & privacy

  • Self-serve setup
  • Docs and examples
  • Standard support
  • No training on your code
  • No source-code retention by default
  • Receipt-based audit trail
Start with your team

Motion 2

Regulated and Enterprise

Prove one high-consequence workflow in an eight-week pilot, then expand until every consequential agent action carries a receipt.

Regulated and Enterprise

Design Partner Pilot

Prove one high-consequence workflow

$50K

8 weeks

One high-consequence workflow gated end to end, receipts in your vault, and an executive readout your auditors can hold.

Three slots per quarter. 100% of the pilot fee credits toward your first annual contract signed within 30 days of pilot end.

Scope

  • One high-consequence workflow, gated end to end
  • GitHub + Slack integration
  • One production environment
  • One approval policy path
  • Receipts in your vault

Features

  • Agent-written PR enforcement
  • Signer-of-record approval flow
  • Approval invalidation when code changes
  • Cryptographic deployment receipts
  • Audit export

Success & privacy

  • Guided pilot delivery
  • Workflow mapping session
  • Security review support
  • Success criteria definition
  • Final executive readout
  • No training on your code
  • Signed receipts
  • Audit logs
  • Least-privilege GitHub App permissions
Contact sales

Regulated and Enterprise

Enterprise

Org-wide enforcement

from $150K / year

Annual contract

SSO with Entra ID, GitLab and single-tenant or on-prem deployment, long-horizon receipt retention, audit narrative exports, and a named engineer.

The authority layer for autonomous engineering work.

Scope

  • Org-wide protected workflow coverage
  • Multiple engineering teams
  • Multiple GitHub orgs / repos
  • Production, staging, and infrastructure environments

Features

  • Signer-of-record infrastructure
  • Approval graph engine
  • GitHub, CI/CD, cloud, and infra integrations
  • Deploy authorization
  • Infrastructure change authorization
  • Database operation authorization
  • Policy-based routing
  • Approval invalidation
  • Emergency kill switch
  • Receipt verification API
  • Immutable audit trail

Success & privacy

  • Named engineer
  • Priority support
  • Rollout governance
  • Security architecture reviews
  • Quarterly authority review
  • SSO with Entra ID
  • GitLab support
  • Single-tenant or on-prem deployment
  • Long-horizon receipt retention
  • Audit narrative exports
  • No training on customer data
Contact sales

Pricing principle

Signers, not actions.

You pay for named signers of record: the humans accountable when an agent acts. We never meter gated actions or receipts, so covering more surfaces never costs more. Gate all of the paths below; none of them is metered.

Coverage is the point. Accountability is the unit.

Agent-written PR merges
Production deploys
Infrastructure changes
Database writes or migrations
Customer data access
Financial actions
Privileged internal tools
Autonomous agent tool calls

Compare

Boring, concrete plan differences

DevelopersRegulated and Enterprise
CapabilityFreeTeamDesign Partner PilotEnterprise
Price$0$100 per signer / month$50Kfrom $150K / year
TermOngoingMonthly or annual8 weeksAnnual contract
Signers of record13 to 10Scoped for the pilotContract-scoped
Gated actions and receiptsUnmeteredUnmeteredUnmeteredUnmetered
MCP Guard (open source)IncludedIncludedIncludedIncluded
GitHub Deploy GateIncludedIncludedIncludedIncluded
Shared policy planeNot includedIncludedIncludedIncluded
Central receipt vaultNot includedIncludedIncludedIncluded
Drift visibilityNot includedIncludedIncludedIncluded
Guided delivery and executive readoutNot includedNot includedIncludedAvailable
SSO with Entra IDNot includedNot includedNot includedIncluded
GitLab supportNot includedNot includedNot includedIncluded
Single-tenant or on-premNot includedNot includedNot includedIncluded
Long-horizon receipt retentionNot includedNot includedNot includedIncluded
Audit narrative exportsNot includedNot includedExecutive readoutIncluded
Named engineerNot includedNot includedDuring the pilotIncluded
Support levelCommunityStandardGuidedPriority

Built for authority-grade evidence

PP records signed authorization evidence for consequential actions without training on customer code or retaining source by default.

No training on customer code
No source-code retention by default
Least-privilege GitHub permissions
Signed, tamper-evident receipts
Exportable audit trail
SAML/SSO on advanced plans
Dedicated instance / VPC / on-prem options for enterprise deployments

FAQ

Pricing questions for authority infrastructure

Why per signer?

We price the humans accountable for production, never the volume of actions gated. Covering more repos, pipelines, and tools never costs more. Accountability is the unit; coverage is the point.

What happens to the pilot fee?

100% of the pilot fee credits toward your first annual contract signed within 30 days of pilot end.

What if we need more than Enterprise?

Multi-company and portfolio deployments are scoped directly. Talk to us

Put authority in the path before autonomous work reaches production.

Start with one protected workflow. Expand into the authority layer for agent-driven operations.