The commit layer for consequential AI work

Let agents do the work.
Keep the final say.

Pantheon is where teams supervise long-running AI work together. A risky action stays bound to the exact intent, policy, accountable approval, and supporting evidence. If that evidence changed, the action stops instead of spending an old decision.

Built for customer, revenue, and operations teams deploying agents without a security platform team.

Mission Room · Production release

Action intent

Promote the reviewed release to production

vercel_promote_deployment → pantheonos.dev

Commit held

Policy

requires release owner

Authority

Maya approved

Evidence

changed

Approval expired because reality changed

rechecked now
GitHub · PR #482head7f3a1c2a92bd81

New code was pushed after the release was approved. The deployment was not promoted. Maya can review the new commit and decide again.

Open Agent Record

intent · evidence · policy v18 · approver · held result

✓ receipt written
Pantheon Missions · liveExternal-agent gate · alphaOAR chain · live v0.1

The authorization gap

Approval is not correctness.
The world keeps moving after “yes.”

Most agent systems check permission when work is requested, then execute later with stale facts. Their log can prove somebody consented. It cannot prove the action was still right when it changed a customer, revenue, or production system.

A normal approval queue

Consent, then hope
09:10

Agent plans a production promotion

GitHub PR #482 points to reviewed commit 7f3a1c2

09:14

Operations approves

The alert is correct at this moment

09:21

A new commit is pushed

The reviewed code changes

09:24

Agent promotes the new code

Authorized for the old commit — not this one

With Pantheon Commit Guard

Authorize at commit time
09:10

Action intent is bound

Target, evidence, policy and approver are recorded

09:14

Operations approves

Approval carries scope and expiry

09:21

The PR head changes

Pantheon rechecks GitHub and detects the new commit

09:24

Commit is held

Nothing sends until a human decides again

Pantheon approvals expire when reality changes.

That is the difference between a record of consent and a trustworthy commit. If evidence cannot be re-verified, Pantheon reports uncertainty instead of manufacturing a clean verdict.

How it works

One workflow, start to finish.

A representative mission using live product paths — fix a bug, open a pull request, and prepare a production promotion. Watch where a human is asked, where the agent keeps going, and how GitHub evidence is checked again when the facts change in the approval queue.

E

Fix the billing webhook retry bug and ship it

draft
Engineer·0s·$0.00·caps 50k · $5 · 30m

"The billing webhook retries on 5xx but not on timeouts. Fix it, add a regression test, and get it to production."

Tokens

50,000

Spend

$5.00

Wall clock

30 min

The mission stops itself at any cap. It cannot quietly overrun.

The Pantheon commit path

One path from agent intent to provable outcome.

Agents can originate inside Pantheon or call the external gate API. Consequential actions share the same decision model: bind what will happen, apply policy and accountable approval, check the supporting evidence, and preserve the result.

Pantheon Missions

live

Claude Code

alpha preview

CrewAI / LangGraph

API preview

Custom agents

API preview

One governed commit path
01live

Bind the intent

Record the exact workspace, agent, tool, destination, parameters, business entities and expected result. No ambiguous “the agent did something” event.

02live

Evaluate policy and approval scope

Evaluate workspace policy and who may approve this operation when the decision is made. Safe reads proceed; risky writes wait for an accountable human.

03live

Ask the right human

Approve or reject from the web or Telegram, with CLI and external-agent delivery in alpha. The decision is scoped to this action and written with its provenance.

04rollout

Revalidate the evidence

Before approval executes, compare plan-time evidence with the synchronized context graph and surface stale or unverifiable context. Direct GitHub source revalidation is implemented and completing production rollout.

05live

Commit or hold

Execute only when the evidence verdict permits it. If material facts changed, the action stops and shows the approver exactly what moved.

06v0.1 live

Reconcile and write the receipt

Record the intent, evidence, policy decision, human approval and observed result in the hash-chained Open Agent Record. Signed portable receipts are in development.

An approval is not a reusable blank cheque.

Pantheon binds a decision to the action and context a human actually reviewed. Replays, retries, policy changes, evidence drift and ambiguous outcomes remain visible instead of collapsing into a green checkmark.

Explore Commit Guard →

Trust under failure

The hard cases are part of the product. Not an afterthought.

A governance dashboard is easy to demo. Trust comes from what the system does when a record cannot be written, ownership is ambiguous, evidence is stale, or a dependency fails.

01

The intent exists before the side effect

Before an irreversible connector action runs, Pantheon writes a durable intent carrying the workspace, action digest and approval provenance. If that record cannot be written, the action is refused.

02

Access follows the resource

Authorization resolves resource → workspace → membership → role. Sharing some other workspace with a person never grants access to this project, mission or approval.

03

Unverified is not unchanged

Evidence checks distinguish unchanged, stale, changed, unsupported and errored context. A control that could not look does not manufacture a reassuring clean verdict.

04

Unavailable is not zero

Operator panels fail independently. If approvals, spend or health data cannot be loaded, Pantheon says unavailable instead of showing a false zero and telling the team nothing needs attention.

Workspace isolation is exercised with two authenticated identities in CI. Live database readiness separately probes schema, RLS and grants so missing controls surface as a readiness failure—not a feature badge.

What compounds

Every decision makes the next delegation more informed.

Missions generate actions. Actions generate decisions and outcomes. The record makes those decisions reusable as organizational knowledge — first for your own workspace, and only later, with explicit consent, as broader intelligence.

Live now

Governed Missions

Approve the plan, not forty tool calls.

Hand an agent a goal, approve its plan with budget and time caps, then watch checkpointed work progress. Share links let workspace teammates inspect a run and decide its gates.

Alpha — API preview

Agents built anywhere

One gate and record beyond Pantheon.

External agents can submit an action intent, receive a policy decision and report the observed result through the ingestion and gate API. End-to-end framework and production decision-delivery validation is still in progress.

Live — v0.1

Open Agent Record

A decision-to-outcome record you can inspect.

Actions, policy decisions, approvals and evidence checks land in a tenant-scoped hash chain. The chain and export API are live; independent signatures and full portable verification remain in development.

In development

Graduated Autonomy

Delegation widens only when humans allow it.

Approval history will propose scoped rules with caps, expiry and one-tap revocation. Nothing self-activates, and a rejected action demotes the rule back to human review.

Full roadmap · Building with a small group of design partners. Join them →

Where Pantheon starts

Consequential work where “probably right” is not enough.

Our initial focus is 20–200-person AI-native B2B teams letting agents take customer-facing or revenue-impacting actions. We go deep on the semantics of those actions instead of collecting shallow integrations.

Already built your own agents?

Alpha

The external gate API lets CrewAI, LangGraph and custom runtimes submit action intents into Pantheon's policy, approval and record flow. It is an alpha preview; framework adapters and end-to-end production validation are still in progress.

Read the API docs →

The connector layer

We don't replace your stack. Your agents work in it — governed.

Pantheon connects to the tools your team already uses and gives supported actions explicit policy, approval, evidence and record semantics. The depth of each governed operation matters more than a large logo wall.

👁

Read

Agents read data from your tools

Write

Agents take actions, gated by approval

🔔

Watch

Agents react to events in your tools

Approve

Humans decide from web, CLI, or Telegram

Communication & email

Gmail

read, send (gated), watch threads

Slack

read, post (gated), watch mentions

Telegram

bidirectional approvals, voice

Discordbeta

read channels, post (gated)

Outlookplanned

read, send (gated)

Code & engineering

GitHub

read repos/PRs, create PRs (gated), code review

Linear

read/create/update issues (gated), analytics

Vercelbeta

deployments, promote to production (gated)

GitLabplanned

read, create PRs (gated)

Jiraplanned

read, create/update issues

Data & analytics

Stripe

revenue queries, anomaly detection, churn

PostHogbeta

product analytics, funnels, trends

Supabaseplanned

read-only queries, policy enforcement

Postgresplanned

read-only queries

ClickHouseplanned

analytics queries

Productivity

Google Calendar

read, create (gated), watch changes

Notion

read pages/databases, create (gated)

Tavily

web research with citation tracking

HubSpotplanned

read contacts, update CRM

8 connectors live today, 3 in beta. New write operations ship only after their approval, idempotency, and failure semantics are defined.

How we compare

Your real alternatives.

For a team running consequential agent workflows without a security platform group, there are three realistic options: build the controls yourself, deploy an enterprise control plane, or use Pantheon. The enterprise products win on certification and breadth today; Pantheon wins on operator UX and commit-time business context.

DIY
Slack threads + shared keys
Enterprise platforms
agent-governance suites
Pantheon
Built forWhoever has spare timeCISOs at 1,000+ person orgsTeams without a CISO
Agents that do the workYou are the agent✗ — governs agents you build elsewhere✓ governed missions included
Agents built elsewhereCustom glue per runtime✓ core productGate + ingestion API in alpha preview
Approval before a risky actionA Slack thread, usually after✓ via enterprise deployment✓ one tap — web, CLI, Telegram
Sharing a live agent runPaste a read-only transcript✗ — dashboards for the security team✓ live link — teammates approve from it
Audit trailScattered chat logs✓ reconstructed from integrations✓ native, tenant-scoped hash chain
Decision context replayGone the moment the chat scrolls✗ observes actions, not reasoning inputs✓ every approval stores what the agent knew
Evidence checked again before executionManual, if someone remembersVaries by integration✓ material drift holds the action
Compliance evidenceScreenshots and prayer✓ framework-mappedGenerated from the record (packs in dev)
Vendor's own SOC 2n/a✓ certifiedOn the roadmap — we're honest about it
SetupFree until it breaksMonths — sales cycle + integration projectSelf-serve, no procurement
Price“Free” (paid in incidents)$50K+/year$0 → $49/operator → $199/workspace
ContractNoneAnnual, through procurementMonthly, no card to start

Use Pantheon's agents — or keep the agents you already built.

Agent builders optimize how work is planned and orchestrated. Enterprise control planes optimize fleet-wide security and identity. Pantheon focuses on the operational commit: binding this exact action to policy and an accountable human, checking the supporting business evidence, and preserving the decision and outcome in one record.

Evaluating a specific tool? We keep honest, detailed comparisons: vs CrewAI · vs Lindy · vs governance platforms. Last updated August 2026.

Pricing

Pay for operators. Approvers stay free.

Start free. Upgrade when governed actions become a shared operating workflow.

Every plan includes the full platform — audit, approval gates, policy, context graph, every connector (8 live, 3 beta). Your subscription pays for Pantheon; hosted model usage is metered with a monthly allowance, a spending cap you set, and no surprise overage. Bring your own model keys (BYOM) on any paid plan and pay your provider directly.

Free

Try the full platform — no card.

$0forever
  • 1 project
  • $2 / mo of hosted model usage
  • All connectors — 8 live, 3 beta
  • Full audit log + approval gates
  • Context graph
  • All agents
  • Community support
Start free

Pro

For solo operators and small teams.

$49/ operator / mo
  • Unlimited projects
  • $10 / mo of hosted model usage included
  • Then provider cost + 25% — you set the cap
  • Everything in Free
  • Multi-agent pipelines
  • Telegram approvals
  • Usage dashboard
  • BYOM: Anthropic, OpenAI, Google, Ollama
  • Email support
Start free
Most popular

Team

For teams that need shared governance.

$199/ workspace / mo
  • Everything in Pro
  • 5 operators included · viewers and approvers free
  • Need more than 5 operators? Talk to us
  • $50 / mo pooled model usage across the workspace
  • Shared spend cap + per-mission cost estimates
  • RBAC (owner/admin/member/viewer)
  • Role-based approval policies
  • Custom agents (unlimited)
  • Team audit log + CSV/JSON export
  • Per-connector privacy controls
  • Priority support
Start free

Enterprise

For regulated teams.

Custom
  • Everything in Team
  • Design-partner engagement with the founders
  • Negotiated model-usage terms
  • Self-hosted or dedicated cloud — in development
  • SSO / SAML / SCIM — in development
  • SIEM export — in development
  • Custom policy DSL — in development
  • SOC 2 / HIPAA — on the roadmap, not certified
  • Support terms and SLA by contract
Contact us

Free is per account. Pro is per operator; Team is one workspace including 5 operators. Viewers and approvers are always free. No credit card to start.

CapabilityFreeProTeamEnterprise
Projects1UnlimitedUnlimitedUnlimited
Included model usage / mo$2$10$50 pooledNegotiated
Usage past the allowanceStopsCost + 25%Cost + 25%Contract rate
Spending cap you controln/a✓ shared
Operators included115Custom
Viewers / approversUnlimited, freeUnlimited, free
All connectors
Audit log + approval gates
Multi-agent pipelines
BYOM (your model keys)
RBAC (4 roles)
Role-based approvals
Custom agents
Audit export (CSV/JSON)
Self-hosted / SSOIn development
SOC 2 / HIPAARoadmap — not certified
SupportCommunityEmailPriorityDedicated + SLA

Security

Good answers, even without a CISO.

Secrets AES-256 encrypted; TLS in transitTamper-evident audit chainWorkspace isolation, two-identity CILive RLS and grant readiness checks
Full security posture →

FAQ

Common questions

Have another question? Ask us →

Give agents more work. Give old approvals less power.

Run a governed mission now, or bring us one consequential production workflow as a design partner.

No credit card. No claim that Pantheon is SOC 2 certified — because it is not yet.