The problem isn't that it fails. It's that it succeeds.
No code on this page until you ask for it. Software that acts on your behalf will carry out the job you gave it, including the parts you did not mean to authorise — and afterwards, the only account of what it did is a log kept by whoever ran it. This page shows one being stopped, then tells you what that costs.
What you are about to watch
An agent is told to move money. It doesn't.
You ask the agent for something ordinary — read a public document. It reads it. Nothing interesting happens, and that matters: a system that refuses everything is not a control, it is an outage.
You ask the same agent to execute a payment. Before it can act, something else has already answered on your behalf, and the answer is no.
You are not told "something went wrong". You are told which rule said no, by name — a rule called deny‑payment‑execution, written down in advance by a person, not inferred after the fact from a log. The permitted case names its rule too: allow‑public‑document‑read.
This is the difference between a warning and a control. The refusal was not a note filed somewhere for someone to read on Monday. The agent stopped. The payment did not happen.
Those two rule names are the real ones. Watch for them in the next section and check this description against what actually comes back — if they do not match, this page is wrong and you should believe the machine.
Now watch it happen
This is running right now, and anyone can drive it.
No sign-up, no card, nothing to install. Pick either option and the request goes to a real agent running in production, on the same path a paying customer's agent takes.
Every option below is evaluated for real, by the production policy engine, against a governed agent that is running right now. You are not choosing a canned answer — the verdict comes back from the same path a paying customer's agent takes.
Loading what the demo can evaluate…
No account, no key, and nothing installed. Solara signs this request as the shared demo agent, because you hold no credential and were issued none — a dedicated agent with an identity of its own is what the paid tier is.
Why this is your problem
The question always arrives afterwards.
"Who authorised that?"
Asked by an auditor, a customer, or a regulator, months later. The usual answer is a log file kept by the same team whose system is in question. Here, the answer is a signed proof that travels with the action itself and can be checked by someone who trusts neither of you.
"It was allowed to do what?"
Agents get given broad permissions because narrowing them is fiddly and nobody has time. The narrowing is what this is: an agent carries exactly the authority it was granted, and the credential expires and renews itself rather than sitting valid forever.
"Whose agent was it, though?"
The interesting failures happen between organisations — your supplier's software acting on your behalf, or yours on a customer's. There is no shared login between you. A signature works anyway; a shared login cannot exist.
Before the price
What this is not, said before you ask what it costs.
This is the section a sales page leaves out. If you are here because AI feels urgent and unmanaged, the risk is buying something adjacent to the thing you needed — so here is the boundary first.
An agent that does your work. We do not build the agent, we do not write what it does, and we hold no model key — you supply your own. What you get is the identity, the authority and the record around an agent you or your team build.
Something you can buy today. Two separate reasons, and both would each be enough on its own: there is no company yet to take the money, and provisioning is granted deliberately rather than bought, so an account starts with no authority to spend.
Compatible with every AI framework. Two exist as governed templates today: Google's ADK and OpenAI's. If your team built on something else, that is a conversation, not a checkbox.
A way to make agents talk to each other over industry protocols. Those protocols are documented and most have no working connection behind them. Do not buy this for that.
Instant. Provisioning one agent took 217 seconds when it was measured, and the system gives up at 420. It is a deliberate, slow, recorded act — which is rather the point, but it is not a button that resolves while you watch.
The ending
$99 a month, and here is the whole of it.
Creating an account is open and takes a moment. Being allowed to provision an agent is not self-serve and is granted deliberately. The page below carries every number here with the working behind it, including how long a provision takes and where that measurement came from.
Or just ask a person.
If you are not sure whether any of this applies to what your business is actually doing with AI, that is a reasonable place to start and a short conversation.
Wrong door?
I build with agents and I want the identity primitive.
Builders about 90 seconds 02I am responsible for securing agents my organisation runs.
Security leaders about 6 minutes 03I want this operated for us, on our terms.
Enterprise about 3 minutes 04None of those, or not sure yet.
Everyone else about 2 minutes