Put an agent under governance in minutes: sign in, add the agent, point your client at Owyhee, grant exactly what you allow — then watch the receipts, and revoke the moment you change your mind.
console.kipplelabs.com and sign in. Your first sign-in creates your workspace — nothing to install, nothing to pay.console.kipplelabs.com/mcp/<server>. Paste it into your client's MCP settings and the agent's tool calls now travel through Owyhee. Running the deploy-path agent instead? The console shows the wiring for that too.content:comment on one site). Everything else is denied by default, with a reason, before it ever reaches the tool.Three things, and they're the whole product:
Keys and credentials live encrypted in per-organization custody inside Owyhee — never in an env var, never on the agent's box. The agent gets scoped access, not your secrets.
Per-agent grants, deny-by-default. A verified AXIS identity rides on every call, so a grant applies to exactly one agent — and revocation is one click.
A signed record of every action: who, what, under which scope, allowed or denied. Not a promise of good behavior — a receipt of actual behavior.
The console is live and free to start. If you don't have an agent yet, the deploy path stands one up in about ten minutes.