Pilot stage · limited 2026 design-partner cohortCrelis is in pilot stage and onboarding design partners for runtime authorization of consequential AI-agent actions.
Apply for Pilot Access →Runtime Authorization for AI Agents
AI Acts. Crelis Decides.
Runtime authorization for AI agents. Before an AI agent takes a consequential action, Crelis decides — allow, require human approval, escalate, or block — deterministically, in real time, with tamper-evident proof.
Built to let regulated teams put AI agents into production safely, approve agent workflows faster, and spend less effort on manual review and audit — proven first with design partners.
- Patent-pending
- runtime authorization — filed 2026
- Zero standing credentials
- Crelis never holds your keys
- Reproducible decisions
- every decision reproducible from its recorded context
Every authorized action receives an execution visa
Model- and vendor-neutral · runtime authorization for agents built on
All product names, logos, and brands are property of their respective owners and are used for identification purposes only. No endorsement or partnership is implied.
GREENLIGHT console
Illustrative dataDecision laneIllustrative data
allow require human approval escalate block
- 14:02:11ZSupport AgentRefund $42 · customer 88213CRL-1148 Allow
- 14:02:12ZFinance AgentWire $250,000 → ACME-7741WIRE-HIGH91 Require human approval
- 14:02:13ZResearch AgentSummarize Q3 earnings callREAD-ONLY4 Allow
- 14:02:14ZOps AgentBulk-delete 12K user recordsDELETE-SCALE99 Block
- 14:02:15ZClinical AgentUpdate dosage record · pt 4471PHI-GUARD97 Require human approval
48,212
actions today · illustrative
94.6%
allowed · illustrative
2,431
human approval · illustrative
Governance · todayIllustrative data
all policies active
48,212
AI actions today
94.6%
Allowed
2,431
Human approval required
17
Blocked
Open exceptions
- Ops Agent · bulk delete · blocked
- Finance Agent · wire · human approval required
- Compliance Agent · KYC override · escalated
Audit event stream · illustrative
Illustrative datasealed
14:02:11Z · Finance Agent
Proposed wire transfer $250,000 → ACME-7741
14:02:11Z · Crelis
Inputs evaluated · policy WIRE-HIGH fired · REQUIRE HUMAN APPROVAL · risk context 91
14:02:12Z · Crelis
Routed to treasury reviewer pool (2 eligible) · visa withheld
14:06:48Z · Treasury reviewer
Checked counterparty, approved with note
14:06:49Z · Crelis
Execution visa issued · Ed25519-signed, single-use
14:06:49Z · Banking endpoint
Visa verified · wire released — ref TXN-88231
14:06:49Z · Crelis
Evidence recorded · hash 0x91f3…aa07
The launch film
Who, actually, authorized the AI?
Three minutes on the question enterprises putting AI agents to work will have to answer — and the independent authority that answers it.
The launch film. AI acts. Crelis decides.
Inside the decision
Every consequential action must earn an execution visa
Each consequential action moves through seven steps — request received, inputs evaluated, policy applied, decision (allow, require human approval, escalate, or block), execution visa issued or withheld, visa verified by your endpoint, evidence recorded. Deterministic policy evaluation decides; no AI model makes the final call.
Decision pipeline
Illustrative datastep 7/7
Request received
action: payment.wireInputs evaluated
amount · channel · tierPolicy applied
WIRE-HIGH v12Decision
ALLOW · REQUIRE HUMAN APPROVAL · ESCALATE · BLOCK
REQUIRE HUMAN APPROVALExecution visa issued or withheld
issued after sign-offEndpoint verifies visa
signature validEvidence recorded
sealed · 0x91f3…aa07
The problem
AI agents are powerful. Ungoverned, they're a liability.
Agentic AI is crossing from suggesting to executing. Many agent stacks have no layer between an agent's decision and the real world — and no way to prove what happened after the fact.
Regulated in Singapore? Read our breakdown of MAS SAFR, the agentic AI white paper, and the records it implies.
The solution
Crelis sits between AI and execution
An independent authority layer that decides — per action, in real time — whether AI proceeds, a human approves, or execution stops.
Evaluate
Each consequential action you route through Crelis is evaluated on its inputs — task type, proposed action, amount, industry and channel, customer tier, verifications, message signals.
Decide
Deterministic policy evaluation returns one of four outcomes: allow, require human approval, escalate, or block. The final decision is never made by an AI model.
Require human approval
When policy calls for it, the action waits for an authorized reviewer, whose sign-off becomes part of the record.
Prove
Allowed actions receive a short-lived, cryptographically signed runtime execution visa, and each decision is sealed in a tamper-evident record.
Decision engine · deterministic policy evaluation
Illustrative datainteractive
Incoming agent action — select one
Inputs evaluated
- Action
- payment.wire
- Amount
- $250,000
- Industry
- Financial services
- Channel
- Treasury API
- Customer tier
- Corporate
- Verifications
- Counterparty not yet verified
Require human approval
Visa withheld until an authorized reviewer signs off.
Policy WIRE-HIGH fired: amount above the wire threshold and counterparty unverified. Human approval required from a treasury reviewer; visa withheld until sign-off.
Recorded risk context91· context only, not the decider
Internal validation results
This is what ungoverned looks like
We pointed our coverage instrument at our own engine, driven by agents written by someone who had never seen our policies. 77% of what they did was allowed because nothing objected — which is not the same as something approving. Results from the Crelis test environment; not customer-production data.
Allowed, no policy applied
77%
79 of 103 agent actions · Crelis test environment
Tool names reaching no rule
45
of 52 real CPQ/CRM names probed · 2 Aug 2026
Agent actions measured
103
independently-authored agents · 3 models
Tests passing
830
trust-engine · every commit
The platform
Four surfaces. One authority layer.
Built so governance, risk, and engineering teams can put AI agents into production safely, approve agent workflows faster, and spend less effort on manual review and audit — four surfaces on one decision spine.
Decision Studio
Illustrative datatraceinputs evaluated
- action
- payment.wire
- amount
- $250,000
- industry · channel
- Financial services · Treasury API
- customer tier
- Corporate
- verifications
- Counterparty unverified
WIRE-HIGH v12policy firedrisk context 91
Require human approval · treasury reviewerTrace a decision end-to-end — the request, the inputs evaluated, the policy that fired, the recorded risk context, and the outcome it received.
Policy Library
Illustrative datagovern- WIRE-HIGHv12active
- PHI-GUARDv8active
- DELETE-SCALEv4active
- VENDOR-PAYv2draft
Versioned, testable policies your risk team can actually read — applied deterministically to each consequential action you route through Crelis.
QA Center
Illustrative dataverifyReplay recorded decisions against goldens to catch drift and false allows before they reach customers. Every decision is reproducible from its recorded context.
Audit Center
Illustrative dataprove- 14:06:49Z0x91f3…aa07 sealed
- 14:06:12Z0x8c21…4be9 sealed
- 14:05:58Z0x77d0…c3f2 sealed
A tamper-evident chain of each decision — who allowed what, when, under which policy, with which visa — exportable for auditors and regulators.
Enterprise use cases
Wherever AI touches something that matters
Proven first in financial services; the same authorization loop applies wherever an agent's action has consequences.
Regulated finance
Financial services
Agents initiate payments and transfers, change accounts and limits, work KYC/AML exceptions and remediation, adjudicate claims and send regulated customer communications. Crelis evaluates each consequential action against your policy before it executes and routes what needs a person to an authorized reviewer.
Regulated workflow
Customer operations
Support agents resolve tickets autonomously at volume. Refunds, account changes, and edge cases above policy limits require human approval from an operator without breaking the queue.
Regulated workflow
Healthcare operations
Clinical and admin agents touch protected data. Changes that policy marks as consequential require human approval from an authorized clinical reviewer, with each access and approval sealed in a tamper-evident record.
Put an independent authority between AI and the real world.
See how Crelis evaluates, decides, and proves each consequential action you route through it — in your browser.