Ducto

For in-house teams

Give your agent the account. Keep the controls.

Your growth team wants the agent moving budgets and fixing tracking. Your finance and security teams want proof it can't go wrong. Ducto is how both get a yes.

Need → mechanism

What you need, and the thing that enforces it

Finance wants a hard ceiling on spend changes

Caps from the policy row

Budget and bid ceilings live in Postgres, server-side. The model never sees them and cannot raise them — a hijacked prompt changes nothing about what executes.

Security asks what happens when the model is wrong

Preview-before-apply

Every mutation dry-runs first, and apply requires a live preview whose fingerprint matches the exact change. Wrong or mutated arguments simply don't execute.

Some changes should get human eyes

Approval on the classes you flag

Route big budget moves and structural changes to an approval inbox. Everything else executes instantly within caps — approval is a scalpel, not a toll booth.

The CMO asks “what changed last week?”

Hash-chained audit

An append-only ledger records every tool call — who, what, which policy allowed it. No role can edit it, including us. Filter, export, answer in minutes.

Rollout

The path from zero trust to real autonomy

No big-bang grant. Each stage is a policy setting, not a leap of faith.

Week 1

Read-only

Connect accounts by OAuth. The agent reports, audits, and answers questions. Zero write risk.

When ready

Writes within caps

Set budget and bid ceilings in the policy row. Routine changes execute instantly inside them.

Ongoing

Approval on what matters

Flag the tool classes that deserve human eyes. They wait in the approval inbox; the ledger records everything.

FAQ

The questions this page raises

Can we roll this out gradually?
That's the default path. Everything starts read-only — the agent reports and audits with zero write risk. Then you grant writes platform by platform, with caps, as trust builds.
What does the security review need from us?
Point them at the security architecture page — it names the enforcement path, the RLS model, the KMS-envelope token vault, and the audit chain. It's written for the veto-holder.

Start read-only. Expand when the veto-holders nod.

Free forever, read-only, every platform. Plus 14 days of the full product. No card required.