Everything AI Agent Sync does.
One system, twelve capability areas, 94 capabilities. Six of the governance controls are the subject of pending patent applications. Everything listed here exists in running code with tests, not on a roadmap.
Governance and control
Deterministic controls that decide what an agent may do and stop it when it goes wrong. The AI proposes; policy decides; an independent verifier proves.
Live intervention · patent pending
Acts on a running session — interrupt, reground or halt — rather than reporting a failure after the fact.
Continuity through context loss · patent pending
Detects compaction and truncation mid-task and restores the objective, so a long task does not silently become a different one.
Verify-or-Block · patent pending
No state-changing action executes until the evidence gate passes. The gate runs before the action.
Ground-or-Abstain · patent pending
An agent asserting an outcome it cannot evidence is blocked, not believed.
Capability confinement · patent pending
Narrow explicit permissions per agent. Neither the agent nor injected page text can widen them.
Outcome oversight · patent pending
The agent that acted never confirms its own success. A separate read-only verifier decides.
Approval gates
Checkout, payment, identity, credential and DNS changes require a human decision.
Cost, retry and time budgets
Hard ceilings that stop runaway loops before they spend money.
Objective envelope
The task objective is held outside mutable model context so it cannot drift.
Resource conflict locks
Two agents cannot act on the same resource at once.
Operator kill switch
Halts all autonomous action instantly, across every agent, with no deploy.
Checkpoints and rollback
Recovery points so an action can be reversed where technically possible.
Detection
Six deterministic detectors run continuously against the live session. No model judgement, no false confidence.
Runaway loop detection
Identifies repeated tool signatures and circular reasoning, with an automatic circuit breaker.
Stall and no-progress supervision
Catches an agent that is running but no longer advancing.
Prompt injection screening
Screens untrusted page content and inter-agent messages for instruction injection and credential exfiltration.
Overconfidence detection
Flags confident success language unsupported by grounding turns.
Unrecognized agent detection
Notices when a new or unidentified agent enters the session.
Context compaction detection
Detects the moment context is lost — the failure that usually goes unnoticed.
Live agent observability
Real-time visibility into machine visitors, with observed fact, inferred intent and verified outcome kept as separate evidence classes.
Agents active now
Who is on the site, their operator, family, version and verification status.
Journey stage and inferred intent
Where the agent is in the journey and what it appears to be trying to do.
Movement timeline
Page-by-page and endpoint-by-endpoint path through the session.
Friction and blocker events
The exact point an agent got stuck, with evidence.
Intervention ledger
Every concierge action taken, the policy decision behind it, and the outcome.
Observed · Inferred · Verified
Three distinct evidence classes, never blended into one misleading number.
Agent readiness audit
The free public assessment. Compares what a browser receives with what an honestly identified agent receives, then reports the gaps. Read-only.
Discovery probe
Can an agent find the business and its capabilities at all?
Access probe
Is the agent blocked by policy, rendering or bot controls?
Capability probe
Can the agent determine what actions are available?
Commerce probe
Is machine-readable product, price and availability data present?
Identity probe
Can the agent establish who it is dealing with?
Agent-to-agent probe
Delegated intent, trust, handoff and human-protection readiness.
Uncertainty reporting
Explicitly marks what cannot be determined rather than guessing.
Applicability-weighted score
Findings weighted by whether they actually apply to this site.
Machine-readable output generation
Generates the artifacts agents need in order to read and act on a site correctly.
Agent card
Publishable capability descriptor for visiting agents.
AI catalog
Structured product and service catalog at a well-known location.
llms.txt
Machine-facing summary of the site for language models.
Robots and access policy
Explicit crawler and agent access rules.
Schema JSON-LD
Structured data an agent can parse reliably.
UCP manifest
Universal Commerce Protocol capability manifest.
Protocols and gateway
The interface visiting agents talk to, with merchant policy applied before any disclosure or action.
A2A endpoint
Agent-to-agent messaging with context and task identifiers.
UCP support
Universal Commerce Protocol surface where applicable.
MCP exposure
Model Context Protocol surface where appropriate.
Generic HTTP/JSON
A plain support gateway for agents on no standard protocol.
Capability negotiation
Discovery and negotiation of what the agent may do.
Unknown-agent conservative mode
Unrecognized agents get the most restrictive treatment by default.
Structured friction intake
Visiting agents can report what blocked them, as evidence not authority.
Agent identity detection
User-agent, verified identity and operator family where available.
Concierge and resolution
Merchant-side specialist agents that help an authorized visiting agent finish the journey, inside policy.
Real-time friction classification
Identifies what kind of blocker occurred as it happens.
Dynamic specialist routing
Routes to the right concierge — discovery, comparison, cart, checkout, payment, fulfillment, support.
Graded resolution order
Knowledge answer, then runtime route, then permitted action, then persistent fix, then human escalation.
Approved alternate paths
Pre-authorized checkout, auth and fulfillment routes around a blocker.
Policy-governed offers
Discounts and rewards inside margin floors, inventory rules, exclusions and stacking limits.
Product recommendation
Bundles, substitutes, upgrades and in-stock alternatives from intent and cart.
Generated agent team
A specialist team built from your configuration, per industry.
Human escalation
A clean handoff when policy says a person must decide.
Knowledge and learning
Grounded answers from your own data, and verified outcomes that become reusable.
Local knowledge ingestion
Catalog, inventory, pricing, policies, FAQs, shipping, returns, loyalty and promotions.
Vector index
Local embeddings or a vector backend you choose.
Grounded answer engine
Answers carry source provenance — no ungrounded assertions.
Compatibility knowledge graph
Agent, intent, friction, root cause, safe resolution and verified outcome, linked.
Resolution library
Verified fixes recorded as structured, reusable cases.
Recipe promotion gate
A case becomes a reusable recipe only after sandbox replay and independent verification.
Emerging behavior detection
Notices new agent behaviour patterns as they appear.
Knowledge freshness and versioning
Tracks staleness so answers do not silently rot.
Journeys and regression protection
Synthetic journeys that prove a change helped, and prove it broke nothing else.
Journey authoring
Build discovery-through-fulfillment test journeys.
Agent-family profiles
Test as different agent families behave differently.
Protected human journeys
Human paths are tested alongside agent paths.
Automatic friction reproduction
Replays a live failure in a controlled environment.
Before-and-after reliability scoring
Quantifies whether the fix actually worked.
Cross-agent regression matrix
Blocks a change that fixes agent A but breaks agent B or a human.
Analytics and monitoring
Evidence-backed measurement. Nothing is substituted when data is absent.
Journey completion and friction rate
By agent, journey and stage.
Intervention success rate
Did the concierge actually resolve it?
Conversion and recovery
Journeys saved that would otherwise have failed.
Offer performance and margin impact
What promotions cost and returned.
Fix durability
Whether a repair held, or regressed.
Continuous monitoring
Scheduled re-checks with configurable intervals.
Proactive compatibility alerts
Warning before a known change breaks you.
Drift detection
Notices when the live environment moves away from the verified state.
Enterprise, deployment and privacy
Built to run inside your boundary, on your terms, with evidence that survives outside scrutiny.
Local-first runtime
Operational data stays in your environment by default.
No mandatory AI vendor
Local model, bring your own key, bring your own model, or your own gateway.
Air-gapped mode
Full operation with no outbound dependency.
Encrypted local secrets
Keychain-backed credential storage.
SSO, SAML and SCIM
Enterprise identity and provisioning.
Role-based access control
Workspace roles and least-privilege membership.
API keys and service accounts
Programmatic access with scoped permissions.
Hash-chained audit export
Verifiable evidence export, including CEF for SIEM.
Property authorization
Ownership verified by token before any private assessment.
Deployment packaging
Bundles for deploying into your own infrastructure.
Retention controls
You decide what is kept and for how long.
Licensing and entitlements
Offline and air-gapped license verification supported.
Where it runs
Released software with notarized builds, not a prototype. 229 deterministic self-tests pass on every build of the detection engine.
Agent platforms
ChatGPT, Claude, Claude Code, Cursor, Grok and Xcode, with a host registry that extends.
macOS
Notarized desktop application.
iOS
Native app with widget and Apple Watch companion.
Android
Native application.
Browser extensions
Chrome and Safari.
Self-hosted service
Container-deployable service for your own infrastructure.