Thanks to visit codestin.com
Credit goes to permissionprotocol.com

Skip to content
PERMISSION/PROTOCOL
The authority layer for AI agents

Your agents take action. You decide what’s allowed.

Set the rules. Require approval when it matters. Get proof of what was authorized.

For MCP tool calls and GitHub deployments.

Explore integrations
135 documented incidents of agents acting without authorization, 25 of them critical
Want to make the decision yourself?Try the interactive demo

Where PP fits

One place to authorize agent actions.

A shared authorization layer across the workflows you connect.

Before

Separate paths. Scattered controls.

Each connection has its own permissions and approval logic.

Agent 1
Agent 2
Agent 3
MCP tools
GitHub

With Permission Protocol

Clear rules. Accountable actions.

Check policy, get approval when required, and keep proof.

Agent 1
Agent 2
Agent 3

PERMISSION PROTOCOL

Policy

Approval when required

Authorization receipt

MCP tools
GitHub

Illustrative architecture for configured MCP tool calls and GitHub deployment gates. Agents must use the enforced path for authorization to apply.

A protected GitHub change

Follow one action from request to receipt.

An agent proposes a change to a production path your team has chosen to protect.

  1. 01

    The agent requests a change

    The connected workflow checks the proposed commit against your configured policy.

    Request
  2. 02

    Your rules determine approval

    For a change that requires signoff, a named approver reviews the exact action before the protected workflow can proceed.

    Approval required
  3. 03

    Keep the authorization record

    A signed receipt binds the authorization to the approved change, ready for later review and verification.

    Authorization recorded

Example flow for a configured approval gate. Required checks and deployment rules enforce the protected path.

The evidence

Proof of what was authorized.

A receipt connects the approved action to the agent, the signer, and the policy that applied.

  • The exact action or commit covered by the approval.
  • The named signer and the authorization time.
  • A signature you can independently verify.
See a real signed receipt

ACTION AUTHORIZED

github-actionsproduction

Deploy gate authorization approved

Agent
github-actions
Signer of record
rodchalski
Policy
deploy-gate-v1
Timestamp
2026-08-21T22:26:38.587Z
SignatureVerified ✓

Ed25519 signature verified at build time over the canonical payload digest against the issuer public key published at /api/v1/keys/current

Issuerpermissionprotocol.com

app.permissionprotocol.com/r/rcpt_dg_cmt3gkieg0003v5cwonna8pk5

How to read the receipt and its signature

Start with the workflow you need to control.

Agent tool calls

MCP Guard

Apply allow, block, and approval rules to tool calls routed through the open-source MCP proxy. Use observe mode to review decisions before turning enforcement on.

Explore MCP Guard

Code changes and deployments

Deploy Gate

Add an approval and receipt check to a GitHub workflow. Configure required checks and deployment rules for the changes your team chooses to protect.

Explore Deploy Gate

For engineering and review teams

Keep your approvals. Make them evidence.

When someone asks who authorized a change, hand them a record tied to that action. Keep your existing review process and use the receipt as supporting evidence. Your reviewers determine whether it meets their requirements.

Start free, or evaluate one workflow.

For developers

$0 Free plan

Try the GitHub approval and receipt flow yourself. MCP Guard is also available as open source.

  • 1 named signer
  • 1 connected repository
Start free

For teams evaluating one workflow

$10,000 Paid evaluation

Two weeks, one GitHub approval workflow. Founder-led setup, agreed tests, and a verifiable evidence pack.

  • One GitHub repository
  • One approval workflow and agreed test path
  • Named approvers and success criteria

Continue with a separately agreed rollout if the evaluation proves useful.

See evaluation details

Before you connect a workflow.

What gets blocked?

The paths you configure for enforcement. A GitHub approval gate can require a matching receipt for a protected change. MCP Guard evaluates tool calls against your rules: allow, block, or require approval. Observe mode logs decisions without blocking calls.

Can we keep our existing approvals?

Yes. Keep your code review and branch protection. Configure Permission Protocol alongside them to add an authorization record tied to the approved action. During setup, agree which approval workflow and evidence fields your team needs.

Can an agent bypass the gate?

The gate controls only the paths routed through it. An agent with direct credentials or another execution path may bypass it, and an administrator may remove a required check. Setup must address those alternate paths and who can change the controls.

What happens during an outage?

Behavior depends on the integration and its configuration. Some Deploy Gate versions allow a workflow to continue on API errors; do not assume every integration fails closed. Local MCP Guard enforcement runs in your environment. Test unavailable-service behavior before relying on a gate for production.

What does setup involve?

Choose one workflow, define the actions that need approval, and configure the integration and approvers. Test approval, denial, changed actions, alternate execution paths, and outages. Start with the product setup guide, or use a paid evaluation for founder-led setup and agreed acceptance tests.

Choose the first action you want to control.

Bring one action, its approval path, and the evidence you need. Review the fit with our founder and agree a concrete next step.

Book a workflow review Prefer to write? Send your workflow
Codestin Search App