Let agents act.
Keep control.

Independent evidence.
A circuit breaker outside the agent’s reach.

Humming Arms seals the actions your agents take and puts a local switch at the boundaries they use.

Flight recorderTRIPPED

Policy violation · dns.query → egress revoked

A recording sequence: normal actions are sealed with fingerprints. A DNS action crosses policy, and the independent breaker cuts egress. This is a product walkthrough.

The story isn’t
the whole record.

A trace explains a run. An independent record shows the actions that crossed the boundary.

What the trace saysTHE STORY

“Fetched the docs.
Finished the task.”

  1. Opened reference material
  2. Prepared the answer
  3. Run completed

A useful story.
But who holds the original?

What actually happenedACTION RECORD
  1. file.readSEALED
  2. Absent from the narrative

    dns.querySEALEDMISSING FROM THE STORY
  3. tool.resultSEALED

Sealed actions. Independent custody.
A switch that can act on them.

One action.
An unbroken path.

Record. Detect. Contain.
Then reconstruct.

1

Act

Tools, files, network

Bind the action to an identity.

2

Seal

Receipts linked

Link receipts. Sign their source.

3

Decide

Boundary policy

Apply local rules. No remote call.

4

Contain

Apply the control

Stop access. Check the outcome.

5

Reconstruct

Actions to answers

Check integrity. Connect the timeline.

Close to the action.
Outside its authority.

The agent does the work. It does not own the recorder or the breaker.

Tap a part

Sensor architecture
Host machine
Agent sandbox
Agent
Independent controlKeys & controls stay outside the sandbox.

SDK sensor

Python and TypeScript connect tool calls and results to identities and sessions. Signing keys stay outside the sandbox.

Explore the security boundaries

An alert tells you.
A breaker stops it.

Pause the run. Remove the process. Revoke the key. Cut the way out.

Control explorerLOCAL CONTROL
Explore breaker controls
  • PROCESS RUNNING
  • CREDENTIAL ACTIVE
  • EGRESS CONNECTED

Process running · credential active · egress connected

Keep the record.
Check it yourself.

Linked receipts, signed checkpoints and external anchors. An open verifier that does not depend on the console’s verdict.

Humming Arms

Evidence

Verify an export

OPEN VERIFIERverify agent.evidence
  1. Hash linksWAITING
  2. Sensor signaturesWAITING
  3. Signed checkpointWAITING
  4. External anchorWAITING

Export walkthrough ready.

Keep your traces.
Add evidence and control.

Different questions. Complementary tools.

Traces

How did the run unfold?

Follow execution. Debug a tool call. Find the slow step.

Execution & performance

Evaluations

Was the result good?

Assess output quality and behavior against your criteria.

Quality & behavior

Humming Arms

What acted? What can stop it?

Check action evidence. Control access at instrumented boundaries.

Evidence & control

Know your
boundaries.

Clear answers for the paths you need to protect.

Does this replace tracing or evaluations?

No. Keep tracing for debugging, evaluations for quality, and observability for cost and performance. Humming Arms adds independent action evidence and controls at instrumented boundaries.

Do you need the agent’s chain of thought?

No. Monitoring and enforcement use actions and identities. Model reasoning can add context, but it is not a dependency for a policy decision or a stop.

Can a kill switch stop every action?

A stop reaches only the boundaries it controls. Killing a process cannot undo a completed request. Credential revocation and egress controls need the right authority. Map those boundaries and test the stop outcome for your deployment. A requested stop is not proof of containment; failed stops escalate for human response.

What happens when policy is missing or stale?

Missing, invalid or stale policy must not silently permit protected actions. High-risk network and credential boundaries default to denial. Stop failures require escalation, never a success label.

Does a valid record prove nothing was missed?

No. Hash chains and signatures establish integrity within the recorded sequence, not complete capture. Uninstrumented actions can be absent from a valid record. External anchors expose rewriting relative to a checkpoint; trusted signing keys and sensor coverage still matter.

How do we scope a deployment?

Start with the agents, tools, network paths and credentials you need to control. Agree on evidence capture, privacy and retention, then exercise allowed and denied actions. Use a demo to work through those boundaries and pricing.

Let them work.
Hold the switch.

Bring your agents, tools and credentials.
Map the record and the controls with Humming Arms.