Heed installs inside your agent harness — intercepting every tool call before execution. The agent can't bypass it. Zero API calls on the hot path. Full audit trail.
Plugins for Hermes, OpenClaw, Claude Code, Cursor.
If it has a hook system, Heed enforces it.
Your agent followed the rules exactly. The rules were wrong for this case. Nobody reviewed it before the money left the account.
The agent was configured to send emails. Nobody specified that "send" meant "send to everyone, right now, with the draft copy."
Your agent fixed the bug and pushed. Nobody told it that main is production, Friday is sacred, and this particular fix had a side effect.
These aren't hypotheticals. They're the support tickets developers are filing right now.
The problem isn't that your agents are bad. It's that consequential actions need a human in the loop — and cooperative gates don't work. We proved it: agents skip them.
Before any tool executes, the Heed plugin fires. It classifies the action, checks policies, and gates it — all inside the execution pipeline. The agent can't bypass because it doesn't control this step.
When a policy match hits, the tool call is blocked and the right human gets notified — Slack, email, or native harness prompt. One click to approve or reject. Works on mobile.
If approved, the harness executes the tool call. If denied, the agent gets a block message. Everything is logged with full context. You have a complete audit trail.
MCP servers, decorators, and system prompts are suggestions. Heed is a gate the agent can't walk around.
MCP servers, decorators, and system prompts ask the agent to check in before acting. Our dogfooding proved: 0% compliance. Agents optimize for task completion, not governance.
No. The plugin lives inside the harness execution pipeline. The agent outputs a tool call — the harness fires our hook before executing. The agent can't skip step 2.
Rule-based classifier matches tool calls in <1ms. Three tiers: pass-through (no match → execute instantly), grace period (low-risk → execute + notify), HITL gate (high-risk → block until human decides). Natural language policies coming soon.
Email and Slack cards with approve/reject buttons. No login required. Works on mobile. The decision takes 10 seconds, not 10 minutes.
Every request, decision, and webhook delivery is logged append-only. SOC 2 and EU AI Act Article 14 ready. Know exactly what happened and when.
Install the plugin, set mode: shadow. Every tool call is classified and logged — nothing is blocked. Review the audit data, tune policies, then flip to enforce. Zero-risk onboarding.
Classification happens on your machine. 99%+ of tool calls never leave your infrastructure. Only denied and high-risk calls feed the shared classifier. Enterprise: full on-prem, zero data egress.
Plugins for Hermes (Grade A), OpenClaw (Grade A), Claude Code (Grade B), and Cursor (Grade B). Same classifier, same policies, same audit trail across every harness your team uses.
"High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which the AI system is in use."
— EU AI Act, Article 14 (Human Oversight)If your agents touch healthcare, finance, legal, government, HR, or critical infrastructure, Article 14 applies. Heed gives you the human control layer and the audit trail to prove it.
No credit card required. Upgrade or downgrade anytime.
Free to start. Plugin installs in 5 minutes. Works with every major agent harness.