Agent action
Tool, arguments, identity, and session context.
Runtime authorization for agent actions
Your agent proposes an action. Salus checks the action, the policy, and the evidence behind it before your backend executes.
HAT097 + HAT251 · $299
book_flights_available:0Structural checks establish the facts. Reasoning can interpret intent and unstructured context. Salus then controls execution and records how the decision was made.
Tool, arguments, identity, and session context.
Policy, evidence, provenance, limits, and state.
Interprets intent and unstructured context when structure alone cannot settle the action.
Runs the action, returns an exact fix, or sends it to a person when judgment is required.
Decision path, evidence, timing, and provider status.
Choose a family to see what Salus evaluates before a consequential tool call reaches your systems.
Require current, trusted facts for the values the agent is about to commit. A saved value is not enough when the policy requires a live one.
missing: live_available_itineraryInventory what agents already do, write the policy, test it, control live decisions, and review configured recovery paths from one place.
Import recent runs and map the tools, writes, and providers already in use.
Define the evidence, limits, confirmation, and scope each action requires.
require: live_available_itineraryTest policy changes against prior actions and synthetic policy variants before rollout.
Run each protected route in shadow or enforcement and inspect the outcome.
For configured tools, use the receipt to review and approve a retry, rollback, or compensation path.
Every consequential action produces a receipt showing what was proposed, what Salus checked, why it decided, and whether execution occurred.
Export decisions in CSV, JSON, agent JSON, or Markdown. Retention is configurable.
Read data handling →book_reservationbook_flights_available:0Salus brings identity, policy, evidence, runtime context, and additional checks together at runtime to control what your agents can actually do.
Protect one consequential route without replacing your agent, model, framework, or backend.