IAM tells you who can reach something. Humbleaf tells you whether this exact action should happen now.
Operating law
Invariant decision semantics
Workflows get more complex. Decision semantics stay invariant.
Who asked
The actor — human, agent, or service — recognized at decision time.
What authority was requested
The exact action proposed, not a standing credential or broad permission.
What policy applied
The rules snapshot in force when the decision was made.
What decision happened
ALLOW, DENY, or APPROVAL_REQUIRED — recorded, not reconstructed from logs.
What evidence proves it
A replayable bundle auditors can verify without log archaeology.
One refund, checked before money moves
An automation attempts a €4,800 refund. Humbleaf checks, before anything executes:
- 01Actor identity and continuity
- 02Amount against policy threshold
- 03Merchant risk state
- 04Policy snapshot in force
- 05Whether approval is required
- 06Whether the approval is single-use and unexpired
Not every automated action needs an authority layer.
The line that matters is consequence — not whether an agent is involved.
Low consequence
Consequential
Humbleaf protects consequential actions — where mistakes are expensive, irreversible, or regulated.
What Humbleaf protectsFrom access to action authority
From
Access control
To
Action authority
From
Bearer keys
To
Per-action authorization
From
Logs after the fact
To
Control before + evidence after
From
"The agent has a key"
To
"This exact action is authorized right now"
From
Unmanaged automation
To
Controlled autonomy
What Humbleaf does
…and rehearse it safely before production.
Unsafe states become denials, not mystery logs.
Authorize before execution
Every high-risk action is checked against your policy before it runs.
Recognize the actor
Identity continuity confirms who is acting and whether behavior is consistent over time.
Assess behavioral risk
Risk signals advise when something looks abnormal — they never block on their own.
Approve the exact action
When warranted, a named human approves one specific action — single-use, expiring.
Preserve the evidence
Every decision, including denials, leaves a replayable evidence bundle.
The bottleneck is trust
Four teams are blocked by the same missing layer.
Risk & insurance
Can we underwrite this autonomous workflow?
Workflows become easier to assess when identity, authorization, approval, and evidence exist before execution — not reconstructed after an incident.
Treasury & payments
Can we prevent context-blind money movement before settlement?
Consequential money-movement actions are checked against policy and risk before they execute — anomalies escalate to a named human.
Audit & compliance
Can we prove actor continuity, policy, approval, and decision after the fact?
Every decision leaves a replayable evidence bundle — including denials — so auditors verify without log archaeology.
Security & platform
Can we let automation operate without handing it standing authority?
Agents, scripts, and workflows can request actions without receiving permanent permission to execute every future action.
How an authority decision happens
Seven steps, every consequential action, every time.
- Propose
- Recognize
- Evaluate policy
- Assess risk
- Route approval
- Execute / block
- Preserve evidence
ALLOW
Policy permits execution.
DENY
Policy blocks execution.
APPROVAL_REQUIRED
A named approver must authorize this exact action.
Risk advises. Policy decides. Evidence proves.
Existing systems prove pieces. Humbleaf binds the whole authority decision.
Each tool answers part of the question. None binds action, identity, policy, approval, and evidence into one decision.
| System | Knows | Cannot |
|---|---|---|
| Wallet / key store | Who signed | Cannot explain why the action was authorized |
| OAuth / SSO | Who logged in | Cannot prove identity continuity over time |
| Agent framework | Workflow state | Cannot establish authority for an action |
| Audit log | What happened | Cannot prove it should have happened |
Explore by domain and workflow
Industry depth and workflow-level guards — each with honest shipped and in-design status.
We don't ask you to trust us. We show you.
Three canonical decisions — allow, deny, and approval-required — each leaving a replayable evidence trail. Denials are first-class proof.
Start in shadow. Gate when ready. Govern at scale.
Begin with one workflow in observe-only mode. Turn on approval gates only after human-reviewed readiness. Then expand — one workflow at a time.
Humbleaf is a new layer — not a relabel of tools you already have
Not IAM
IAM says who you are and what you can reach. Humbleaf authorizes the exact action at execution time.
Not SIEM / logging
Logs explain the past. Humbleaf controls the action before it runs and proves it after.
Not a generic approval tool
Approvals are bound to the exact action, used once, and expire — not a thumbs-up in chat.
Not an agent framework
Frameworks run agents. Humbleaf governs what they're allowed to do.
Not crypto-only
The authority layer is chain-agnostic. Onchain is one supported workflow type.
Not a compliance checklist
Checklists assert. Humbleaf enforces and evidences at runtime.
Not after-the-fact audit only
Control happens before execution, with evidence preserved after.
