Complete capability list

Everything AI Agent Sync does.

One system, twelve capability areas, 94 capabilities. Six of the governance controls are the subject of pending patent applications. Everything listed here exists in running code with tests, not on a roadmap.

01

Governance and control

Deterministic controls that decide what an agent may do and stop it when it goes wrong. The AI proposes; policy decides; an independent verifier proves.

Live intervention · patent pending

Acts on a running session — interrupt, reground or halt — rather than reporting a failure after the fact.

Continuity through context loss · patent pending

Detects compaction and truncation mid-task and restores the objective, so a long task does not silently become a different one.

Verify-or-Block · patent pending

No state-changing action executes until the evidence gate passes. The gate runs before the action.

Ground-or-Abstain · patent pending

An agent asserting an outcome it cannot evidence is blocked, not believed.

Capability confinement · patent pending

Narrow explicit permissions per agent. Neither the agent nor injected page text can widen them.

Outcome oversight · patent pending

The agent that acted never confirms its own success. A separate read-only verifier decides.

Approval gates

Checkout, payment, identity, credential and DNS changes require a human decision.

Cost, retry and time budgets

Hard ceilings that stop runaway loops before they spend money.

Objective envelope

The task objective is held outside mutable model context so it cannot drift.

Resource conflict locks

Two agents cannot act on the same resource at once.

Operator kill switch

Halts all autonomous action instantly, across every agent, with no deploy.

Checkpoints and rollback

Recovery points so an action can be reversed where technically possible.

02

Detection

Six deterministic detectors run continuously against the live session. No model judgement, no false confidence.

Runaway loop detection

Identifies repeated tool signatures and circular reasoning, with an automatic circuit breaker.

Stall and no-progress supervision

Catches an agent that is running but no longer advancing.

Prompt injection screening

Screens untrusted page content and inter-agent messages for instruction injection and credential exfiltration.

Overconfidence detection

Flags confident success language unsupported by grounding turns.

Unrecognized agent detection

Notices when a new or unidentified agent enters the session.

Context compaction detection

Detects the moment context is lost — the failure that usually goes unnoticed.

03

Live agent observability

Real-time visibility into machine visitors, with observed fact, inferred intent and verified outcome kept as separate evidence classes.

Agents active now

Who is on the site, their operator, family, version and verification status.

Journey stage and inferred intent

Where the agent is in the journey and what it appears to be trying to do.

Movement timeline

Page-by-page and endpoint-by-endpoint path through the session.

Friction and blocker events

The exact point an agent got stuck, with evidence.

Intervention ledger

Every concierge action taken, the policy decision behind it, and the outcome.

Observed · Inferred · Verified

Three distinct evidence classes, never blended into one misleading number.

10

Analytics and monitoring

Evidence-backed measurement. Nothing is substituted when data is absent.

Journey completion and friction rate

By agent, journey and stage.

Intervention success rate

Did the concierge actually resolve it?

Conversion and recovery

Journeys saved that would otherwise have failed.

Offer performance and margin impact

What promotions cost and returned.

Fix durability

Whether a repair held, or regressed.

Continuous monitoring

Scheduled re-checks with configurable intervals.

Proactive compatibility alerts

Warning before a known change breaks you.

Drift detection

Notices when the live environment moves away from the verified state.

11

Enterprise, deployment and privacy

Built to run inside your boundary, on your terms, with evidence that survives outside scrutiny.

Local-first runtime

Operational data stays in your environment by default.

No mandatory AI vendor

Local model, bring your own key, bring your own model, or your own gateway.

Air-gapped mode

Full operation with no outbound dependency.

Encrypted local secrets

Keychain-backed credential storage.

SSO, SAML and SCIM

Enterprise identity and provisioning.

Role-based access control

Workspace roles and least-privilege membership.

API keys and service accounts

Programmatic access with scoped permissions.

Hash-chained audit export

Verifiable evidence export, including CEF for SIEM.

Tamper-evident by design

The guard fingerprints its own code. An unapproved edit to a detector is reported, not silently accepted.

Deployment packaging

Bundles for deploying into your own infrastructure.

Retention controls

You decide what is kept and for how long.

Licensing and entitlements

Offline and air-gapped license verification supported.

12

Where it runs

Released software with notarized builds, not a prototype. 229 deterministic self-tests pass on every build of the detection engine.

Agent platforms

ChatGPT, Claude, Claude Code, Cursor, Grok and Xcode, with a host registry that extends.

macOS

Notarized desktop application.

iOS

Native app with widget and Apple Watch companion.

Android

Native application.

Browser extensions

Chrome and Safari.

Self-hosted service

Container-deployable service for your own infrastructure.