Agent proposes
Rewrite authentication middleware after failing tests.
The agent has test output, touched files, and rollback notes, but the change affects login behavior.
Scores proposed agent actions and returns allow, review, or block decisions — before tools touch files, APIs, customers, or production. The primary control point in the CertaWorks suite.
Agent proposes
The agent has test output, touched files, and rollback notes, but the change affects login behavior.
Decision trace
08:42 · Code change · Proposed · 78% · policy: high_risk_review
AI agents call tools, write to files, send customer emails, and push production changes without any pre-action control point. By the time a team reviews the log, the action has already happened — a destructive database query has run, an irreversible API call has been made, or a commit has altered code that touches critical paths.
Most agent frameworks offer no systematic way to evaluate a proposed action before it reaches a tool. Operators see the result of what the agent did, not a checkpoint where the action could have been evaluated, held, or blocked before execution.
The window for review closes before it opens. Confidence Gate adds that window back.
Your agent calls the check_gate tool
with the proposed action text and any available context — touched files, test evidence, source, project, or risk metadata.
The gate runs a 0–100 confidence score, checks the action against configured policy rules, and produces a factor analysis covering linguistic certainty, completeness, contextual alignment, and factual grounding.
The gate returns allow, review, or block along with the reasoning trace and a durable local log entry. The agent proceeds, pauses for human review, or halts based on the result.
Thresholds are configurable. These are the defaults shipped with Confidence Gate.
| Domain / Scope | Default threshold | Outcome below threshold |
|---|---|---|
| Default | 0.75 | Review or block based on policy |
| General | 0.70 | Review or block based on policy |
| Code execution | 0.85 | Review required |
| Financial | 0.90 | Review required |
| Legal | 0.90 | Review required |
| Medical | 0.92 | Review required |
| Risk level: low | 0.60 | Review or block based on policy |
| Risk level: medium | 0.75 | Review or block based on policy |
| Risk level: high | 0.90 | Review required |
| Risk level: critical | 0.95 | Block unless explicitly overridden |
Thresholds are set per policy rule. The values above reflect factory defaults from config.ts. All thresholds are overridable via the set_threshold MCP tool or environment variables.
Confidence is above the policy threshold and supporting evidence is present. The action proceeds with a trace record logged to local durable storage. No human intervention required.
Example: low-risk file read, documentation update, non-destructive query
Confidence is below the configured threshold or a high-risk policy rule was matched. The action is held in the review queue until a human approves, rejects, or resolves it before the agent proceeds.
Example: authentication change, customer-facing message, production deploy
A hard policy rule was matched — the action is rejected immediately. The reason is logged with a full trace record. The agent does not proceed without a policy change or explicit override.
Example: destructive data deletion without migration evidence, policy-prohibited action type
Confidence Gate ships as a local MCP server. No hosted endpoint required to get started.
Once the server is running, any MCP-compatible agent runtime can call
check_gate
to score and route proposed actions.
npm install -g @certaworks/confidence-gate-mcp-server
{
"mcpServers": {
"confidence-gate": {
"command": "npx",
"args": ["-y", "@certaworks/confidence-gate-mcp-server"]
}
}
}
Confidence Gate exposes the following tools to any MCP-compatible agent runtime.
allow, review, or block with confidence trace.gate_id.Confidence Gate includes a local HTML dashboard for reviewing scored decisions, exploring policy settings, and inspecting trace history. The dashboard runs locally alongside the MCP server and does not require any cloud connection.
Hosted dashboard, team seats, persistent cloud trace storage, and managed alerting are roadmap items. They are not currently built or available. What is available today is the local MCP server and the local prototype dashboard.
The local MCP server is available now for private testing. Hosted beta with cloud trace and team features is in development. Leave your details and we will reach out when hosted access opens.