I build the decision gate in front of expensive or irreversible AI actions. Bounded evidence in, a proposal out, a human commits.
The same primitive across different domains:
| Project | The gate |
|---|---|
| VibeGate | Blocks unsafe agent tool calls before execution — host-owned allowlist, not model refusal |
| Shared Room MCP | AI prepares evidence-backed drafts before commitment — nothing auto-executes |
| FitStyle Map | Decides which pairings are worth generating before VTO spend — PASS / REVIEW / HOLD with named reasons |
| Codex Dream Skin | Applies changes behind a reversible gate — verified interactions, clean restore |
How I work
- Controls are reported with their limits, not without them
- An unobserved attempt is not counted as a block
- The core path runs without a paid API key
- Evidence comes from the target side, not from my own gate
Taiwan · data pipelines, release governance, agent security
Why this shape
A security boundary has to be enforced outside the model. The model is the component under attack, so it cannot also be the component enforcing the defense. Work on tool-using agents converged on that between 2024 and 2026: enforce with a deterministic policy that mediates the agent's actions, rather than training the model to refuse. Asking a second model to adjudicate reintroduces the same vulnerability one layer down.
Regulation is moving the same way. FINRA now treats AI agents as a distinct supervisory risk category, and the AI AGENT Act of 2026 requires human approval for sensitive transactions. Around 5% of organizations grant high autonomy for critical actions.
About 74% of organizations plan to adopt agents within two years. About 21% can govern them. That gap is what these projects are built for.