The approval layer for agent operations

Agents prepare. Your people decide.

Recerno sits between your AI agents and the systems they can change. Consequential actions route to a named human with the context to decide in minutes — and the audit record writes itself as they do it.

Built for the person who has to signConsequential actions wait for a decisionEvidence written as a by-product of workOnly consequential actions need approval
Recerno approval queue

The gap between deploying agents and being able to defend them

Agents are easy to launch. They are hard to answer for.

Most organisations now have agents in production and no way to say who permitted what. The alternatives are a governance portal nobody opens, or approval buttons an engineer built in an afternoon and nobody logs. Recerno is the third option: oversight that fits inside the working day.

Risk-Ranked QueueHuman Approval GatesSelf-Writing EvidenceAction BoundariesSpend CeilingsKill Switch

Built around the person who signs

Six capabilities that exist because something specific goes wrong without them — each one aimed at the reviewer, the risk owner, or both.

A queue built for the reviewer

Every consequential agent action arrives with its risk, its deadline, and its consequences already written. Decide in seconds, not in a two-week ticket.

Evidence that writes itself

The record is created by the act of approving. No separate form, no retrofitting a spreadsheet before an audit, no asking an engineer what happened.

Boundaries the business can set

Per-tool, per-data-class and per-amount limits that an operations lead can configure without a deployment. Above the line, a human decides.

Exception monitoring and stop

When an agent behaves outside its declared scope, the workflow pauses and the right person is paged. The timeline is plain language.

Spend ceilings before finance asks

Cost attributed to the team and workflow that caused it, with daily ceilings that pause rather than surprise. No more overnight token surprises.

Access boundaries that hold

Agents hold scoped credentials with a named accountable owner. Revoking an agent is one action, and the record shows who authorised it.

Product

See the decision, not the dashboard

An interface built for the reviewer: risk, deadline, and consequences up front, in plain language a non-engineer can act on.

Rules a non-engineer can own

Policy Boundaries

Rules a non-engineer can own

Route by amount, data class or tool, set the deadline, name the escalation path. The compliance lead changes policy without opening a deployment window.

The record an auditor accepts

Audit Evidence

The record an auditor accepts

An append-only hash chain from request to decision to execution, where each entry carries the hash of the one before it. Export it with the identities and reasoning already attached.

Ceilings before finance asks

Spend Controls

Ceilings before finance asks

Cost attributed to the team and workflow that caused it, with daily ceilings that pause the agent rather than surprise the CFO.

The state of the fleet in one view

Operations Overview

The state of the fleet in one view

What is waiting, what was decided, what resolved itself, and what it is costing — the page a risk leader opens before a board meeting.

From unsupervised to answerable

Four steps from agents running unsupervised to agents operating under a record you can hand over.

01

Connect the agents you already run

Point your existing agents at the approval layer through a gateway or an SDK. No rewrite, and no requirement to change which model or framework you use.

02

Draw the lines that matter

Set the thresholds where automation stops and a person starts: payment amounts, data classes, recipient counts, destructive operations.

03

Your people decide

Consequential actions route to a named reviewer with a deadline. Everything else runs without interruption, which is what keeps the queue credible.

04

The record keeps itself

Every decision lands in an append-only chain with its reasoning. Your audit evidence is a by-product of ordinary work, not a quarterly scramble.

Industries

For teams where one unapproved action is a reportable event

Built for organisations carrying regulatory obligations, contractual scrutiny, or high-trust client relationships — where the question is never whether automation is useful, but who answers for it.

Financial Services & Insurance

Payments, refunds, policy amendments and claims handling where a single unapproved action is a reportable event.

Health & Care

Records, scheduling and correspondence touching health data, where oversight and data minimisation are both mandatory.

Professional & Regulated Services

Advisory and client-service work that benefits from automation while remaining accountable to a regulated principal.

Trust Center

Oversight is a record, not a policy

A governance framework that lives in a document tells you what should have happened. Recerno keeps the record of what did — who approved it, on what reasoning, and what the agent then executed.

Security & Access

Responsible AI

  • Every approval carries a named human identity and an immutable timestamp
  • Append-only evidence chain with export in the formats auditors already accept
  • Scoped, revocable credentials per agent with an accountable owner of record
  • Role-based routing so the wrong team never sees the wrong data class
  • Regional data residency, including EU-only processing
  • Kill switch that halts an agent mid-workflow and records who pulled it

Solutions

Everyone gets something real

Four different people have to be satisfied before an agent programme survives its first audit. They want different things, and all of them are reasonable.

For the Reviewer

The daily user is the one who signs

Most governance tooling is bought by one team and resented by another. This is built for the person sitting in the queue, because that is the only way oversight survives contact with a busy week.

For the Risk Leader

Oversight you can demonstrate, not describe

Show a regulator or an internal auditor exactly which human approved which action, when, and on what reasoning — without commissioning a reconstruction.

For Engineering

Friction low enough that nobody routes around it

Decisions resolve in minutes with a clear owner. Governance that developers strip out after a fortnight is worse than none, because it looks like control.

For the Board

One honest answer about exposure

How many agents are running, what they are permitted to touch, what they have spent, and which exceptions are open right now.

Objections

The questions you are about to ask

The four objections that come up in every first conversation, answered without hedging.

We already have a policy document

A policy says what should happen. This records what did. The difference is the only thing an auditor is actually testing.

Our engineers built approval buttons already

Most teams have a Slack bot and a Retool page doing a fraction of this, maintained by whoever wrote it. This is that, with the audit trail and the SLA nobody has time to build.

Approval gates will slow us down

Only consequential actions route. Everything else runs untouched, and each review arrives with the context attached, so the reviewer gets the decision rather than the raw data.

Won't the model providers just add this?

They are adding their own guardrails, which is why this stays provider-neutral and sits across all of them. Your evidence should not live in one vendor's console.

Put a human in front of the actions that matter

Tell us which agents you run and what they are allowed to touch. We will show you the queue your reviewers would actually see, and the record it would leave behind.