Workflow guards
One guard per high-risk workflow
Three canonical guards anchor the public catalog. Additional guards are indexable but typically scoped through design-partner or pilot conversations.
Onchain transaction guards are documented on the onchain authority page. Compute workload authority is an AgentChain protocol story, not a Humbleaf public claim.
Canonical guards
Workflow Dispatch Guard
Govern privileged automation per action — not per standing token.
Merchant Refund Guard
Stop anomalous refunds before money leaves — with proof of who approved.
Authority Stress Matrix
Prove unsafe cases fail closed — not silently allow execution.
Catalog guards
Fleet Authority Sensors
See drift and hotspots before they become incidents.
Tool Access Escalation Guard
Bound tool access per action — not per standing grant.
Evidence Bundle View
Answer "who authorized this?" without log archaeology.
Decision History View
Prove what did not happen — and why.
Available under engagement
These guards are proven internally or in design — scoped through pilot conversations rather than broad public positioning.
Deployment & Config Change Guard
Pre-execution control over production changes — not reactive log review.
Agent Delegation Guard
Bounded, provable delegation chains instead of authority sprawl.
Payout Destination Guard
Prevent payout redirection fraud with pre-execution control.
Settlement Exception Guard
Controlled retries — no silent double-pay.
API Key & Webhook Guard
Block unauthorized integration tampering before it takes effect.
