Let agents do the work.
Keep the final say.
Pantheon is where teams supervise long-running AI work together. A risky action stays bound to the exact intent, policy, accountable approval, and supporting evidence. If that evidence changed, the action stops instead of spending an old decision.
Built for customer, revenue, and operations teams deploying agents without a security platform team.
Action intent
Promote the reviewed release to production
vercel_promote_deployment → pantheonos.dev
Policy
requires release owner
Authority
Maya approved
Evidence
changed
Approval expired because reality changed
rechecked nowNew code was pushed after the release was approved. The deployment was not promoted. Maya can review the new commit and decide again.
Open Agent Record
intent · evidence · policy v18 · approver · held result
The authorization gap
Approval is not correctness.
The world keeps moving after “yes.”
Most agent systems check permission when work is requested, then execute later with stale facts. Their log can prove somebody consented. It cannot prove the action was still right when it changed a customer, revenue, or production system.
A normal approval queue
Agent plans a production promotion
GitHub PR #482 points to reviewed commit 7f3a1c2
Operations approves
The alert is correct at this moment
A new commit is pushed
The reviewed code changes
Agent promotes the new code
Authorized for the old commit — not this one
With Pantheon Commit Guard
Action intent is bound
Target, evidence, policy and approver are recorded
Operations approves
Approval carries scope and expiry
The PR head changes
Pantheon rechecks GitHub and detects the new commit
Commit is held
Nothing sends until a human decides again
Pantheon approvals expire when reality changes.
That is the difference between a record of consent and a trustworthy commit. If evidence cannot be re-verified, Pantheon reports uncertainty instead of manufacturing a clean verdict.
How it works
One workflow, start to finish.
A representative mission using live product paths — fix a bug, open a pull request, and prepare a production promotion. Watch where a human is asked, where the agent keeps going, and how GitHub evidence is checked again when the facts change in the approval queue.
Fix the billing webhook retry bug and ship it
draft"The billing webhook retries on 5xx but not on timeouts. Fix it, add a regression test, and get it to production."
Tokens
50,000
Spend
$5.00
Wall clock
30 min
The mission stops itself at any cap. It cannot quietly overrun.
The Pantheon commit path
One path from agent intent to provable outcome.
Agents can originate inside Pantheon or call the external gate API. Consequential actions share the same decision model: bind what will happen, apply policy and accountable approval, check the supporting evidence, and preserve the result.
Pantheon Missions
live
Claude Code
alpha preview
CrewAI / LangGraph
API preview
Custom agents
API preview
Bind the intent
Record the exact workspace, agent, tool, destination, parameters, business entities and expected result. No ambiguous “the agent did something” event.
Evaluate policy and approval scope
Evaluate workspace policy and who may approve this operation when the decision is made. Safe reads proceed; risky writes wait for an accountable human.
Ask the right human
Approve or reject from the web or Telegram, with CLI and external-agent delivery in alpha. The decision is scoped to this action and written with its provenance.
Revalidate the evidence
Before approval executes, compare plan-time evidence with the synchronized context graph and surface stale or unverifiable context. Direct GitHub source revalidation is implemented and completing production rollout.
Commit or hold
Execute only when the evidence verdict permits it. If material facts changed, the action stops and shows the approver exactly what moved.
Reconcile and write the receipt
Record the intent, evidence, policy decision, human approval and observed result in the hash-chained Open Agent Record. Signed portable receipts are in development.
An approval is not a reusable blank cheque.
Pantheon binds a decision to the action and context a human actually reviewed. Replays, retries, policy changes, evidence drift and ambiguous outcomes remain visible instead of collapsing into a green checkmark.
Trust under failure
The hard cases are part of the product. Not an afterthought.
A governance dashboard is easy to demo. Trust comes from what the system does when a record cannot be written, ownership is ambiguous, evidence is stale, or a dependency fails.
The intent exists before the side effect
Before an irreversible connector action runs, Pantheon writes a durable intent carrying the workspace, action digest and approval provenance. If that record cannot be written, the action is refused.
Access follows the resource
Authorization resolves resource → workspace → membership → role. Sharing some other workspace with a person never grants access to this project, mission or approval.
Unverified is not unchanged
Evidence checks distinguish unchanged, stale, changed, unsupported and errored context. A control that could not look does not manufacture a reassuring clean verdict.
Unavailable is not zero
Operator panels fail independently. If approvals, spend or health data cannot be loaded, Pantheon says unavailable instead of showing a false zero and telling the team nothing needs attention.
Workspace isolation is exercised with two authenticated identities in CI. Live database readiness separately probes schema, RLS and grants so missing controls surface as a readiness failure—not a feature badge.
What compounds
Every decision makes the next delegation more informed.
Missions generate actions. Actions generate decisions and outcomes. The record makes those decisions reusable as organizational knowledge — first for your own workspace, and only later, with explicit consent, as broader intelligence.
Governed Missions
Approve the plan, not forty tool calls.
Hand an agent a goal, approve its plan with budget and time caps, then watch checkpointed work progress. Share links let workspace teammates inspect a run and decide its gates.
Agents built anywhere
One gate and record beyond Pantheon.
External agents can submit an action intent, receive a policy decision and report the observed result through the ingestion and gate API. End-to-end framework and production decision-delivery validation is still in progress.
Open Agent Record
A decision-to-outcome record you can inspect.
Actions, policy decisions, approvals and evidence checks land in a tenant-scoped hash chain. The chain and export API are live; independent signatures and full portable verification remain in development.
Graduated Autonomy
Delegation widens only when humans allow it.
Approval history will propose scoped rules with caps, expiry and one-tap revocation. Nothing self-activates, and a rejected action demotes the rule back to human review.
Full roadmap · Building with a small group of design partners. Join them →
Where Pantheon starts
Consequential work where “probably right” is not enough.
Our initial focus is 20–200-person AI-native B2B teams letting agents take customer-facing or revenue-impacting actions. We go deep on the semantics of those actions instead of collecting shallow integrations.
Customer operations
Draft and send customer communications, close escalations, and update commitments only while the supporting ticket, account, and policy state still hold.
Revenue operations
Let agents prepare CRM and pipeline actions while humans retain authority over customer-facing changes, sensitive data, and commercial exceptions.
Engineering operations
Govern pull requests, repository changes and deployment decisions with current GitHub evidence, scoped approvals and a replayable action receipt.
Already built your own agents?
AlphaThe external gate API lets CrewAI, LangGraph and custom runtimes submit action intents into Pantheon's policy, approval and record flow. It is an alpha preview; framework adapters and end-to-end production validation are still in progress.
The connector layer
We don't replace your stack. Your agents work in it — governed.
Pantheon connects to the tools your team already uses and gives supported actions explicit policy, approval, evidence and record semantics. The depth of each governed operation matters more than a large logo wall.
Read
Agents read data from your tools
Write
Agents take actions, gated by approval
Watch
Agents react to events in your tools
Approve
Humans decide from web, CLI, or Telegram
Communication & email
read, send (gated), watch threads
read, post (gated), watch mentions
bidirectional approvals, voice
read channels, post (gated)
read, send (gated)
Code & engineering
read repos/PRs, create PRs (gated), code review
read/create/update issues (gated), analytics
deployments, promote to production (gated)
read, create PRs (gated)
read, create/update issues
Data & analytics
revenue queries, anomaly detection, churn
product analytics, funnels, trends
read-only queries, policy enforcement
read-only queries
analytics queries
Productivity
read, create (gated), watch changes
read pages/databases, create (gated)
web research with citation tracking
read contacts, update CRM
8 connectors live today, 3 in beta. New write operations ship only after their approval, idempotency, and failure semantics are defined.
How we compare
Your real alternatives.
For a team running consequential agent workflows without a security platform group, there are three realistic options: build the controls yourself, deploy an enterprise control plane, or use Pantheon. The enterprise products win on certification and breadth today; Pantheon wins on operator UX and commit-time business context.
| DIY Slack threads + shared keys | Enterprise platforms agent-governance suites | Pantheon | |
|---|---|---|---|
| Built for | Whoever has spare time | CISOs at 1,000+ person orgs | Teams without a CISO |
| Agents that do the work | You are the agent | ✗ — governs agents you build elsewhere | ✓ governed missions included |
| Agents built elsewhere | Custom glue per runtime | ✓ core product | Gate + ingestion API in alpha preview |
| Approval before a risky action | A Slack thread, usually after | ✓ via enterprise deployment | ✓ one tap — web, CLI, Telegram |
| Sharing a live agent run | Paste a read-only transcript | ✗ — dashboards for the security team | ✓ live link — teammates approve from it |
| Audit trail | Scattered chat logs | ✓ reconstructed from integrations | ✓ native, tenant-scoped hash chain |
| Decision context replay | Gone the moment the chat scrolls | ✗ observes actions, not reasoning inputs | ✓ every approval stores what the agent knew |
| Evidence checked again before execution | Manual, if someone remembers | Varies by integration | ✓ material drift holds the action |
| Compliance evidence | Screenshots and prayer | ✓ framework-mapped | Generated from the record (packs in dev) |
| Vendor's own SOC 2 | n/a | ✓ certified | On the roadmap — we're honest about it |
| Setup | Free until it breaks | Months — sales cycle + integration project | Self-serve, no procurement |
| Price | “Free” (paid in incidents) | $50K+/year | $0 → $49/operator → $199/workspace |
| Contract | None | Annual, through procurement | Monthly, no card to start |
Use Pantheon's agents — or keep the agents you already built.
Agent builders optimize how work is planned and orchestrated. Enterprise control planes optimize fleet-wide security and identity. Pantheon focuses on the operational commit: binding this exact action to policy and an accountable human, checking the supporting business evidence, and preserving the decision and outcome in one record.
Evaluating a specific tool? We keep honest, detailed comparisons: vs CrewAI · vs Lindy · vs governance platforms. Last updated August 2026.
Pricing
Pay for operators. Approvers stay free.
Start free. Upgrade when governed actions become a shared operating workflow.
Every plan includes the full platform — audit, approval gates, policy, context graph, every connector (8 live, 3 beta). Your subscription pays for Pantheon; hosted model usage is metered with a monthly allowance, a spending cap you set, and no surprise overage. Bring your own model keys (BYOM) on any paid plan and pay your provider directly.
Free
Try the full platform — no card.
- ✓1 project
- ✓$2 / mo of hosted model usage
- ✓All connectors — 8 live, 3 beta
- ✓Full audit log + approval gates
- ✓Context graph
- ✓All agents
- ✓Community support
Pro
For solo operators and small teams.
- ✓Unlimited projects
- ✓$10 / mo of hosted model usage included
- ✓Then provider cost + 25% — you set the cap
- ✓Everything in Free
- ✓Multi-agent pipelines
- ✓Telegram approvals
- ✓Usage dashboard
- ✓BYOM: Anthropic, OpenAI, Google, Ollama
- ✓Email support
Team
For teams that need shared governance.
- ✓Everything in Pro
- ✓5 operators included · viewers and approvers free
- ✓Need more than 5 operators? Talk to us
- ✓$50 / mo pooled model usage across the workspace
- ✓Shared spend cap + per-mission cost estimates
- ✓RBAC (owner/admin/member/viewer)
- ✓Role-based approval policies
- ✓Custom agents (unlimited)
- ✓Team audit log + CSV/JSON export
- ✓Per-connector privacy controls
- ✓Priority support
Enterprise
For regulated teams.
- ✓Everything in Team
- ✓Design-partner engagement with the founders
- ✓Negotiated model-usage terms
- ✓Self-hosted or dedicated cloud — in development
- ✓SSO / SAML / SCIM — in development
- ✓SIEM export — in development
- ✓Custom policy DSL — in development
- ✓SOC 2 / HIPAA — on the roadmap, not certified
- ✓Support terms and SLA by contract
Free is per account. Pro is per operator; Team is one workspace including 5 operators. Viewers and approvers are always free. No credit card to start.
| Capability | Free | Pro | Team | Enterprise |
|---|---|---|---|---|
| Projects | 1 | Unlimited | Unlimited | Unlimited |
| Included model usage / mo | $2 | $10 | $50 pooled | Negotiated |
| Usage past the allowance | Stops | Cost + 25% | Cost + 25% | Contract rate |
| Spending cap you control | n/a | ✓ | ✓ shared | ✓ |
| Operators included | 1 | 1 | 5 | Custom |
| Viewers / approvers | — | — | Unlimited, free | Unlimited, free |
| All connectors | ✓ | ✓ | ✓ | ✓ |
| Audit log + approval gates | ✓ | ✓ | ✓ | ✓ |
| Multi-agent pipelines | ✓ | ✓ | ✓ | ✓ |
| BYOM (your model keys) | — | ✓ | ✓ | ✓ |
| RBAC (4 roles) | — | — | ✓ | ✓ |
| Role-based approvals | — | — | ✓ | ✓ |
| Custom agents | — | — | ✓ | ✓ |
| Audit export (CSV/JSON) | — | — | ✓ | ✓ |
| Self-hosted / SSO | — | — | — | In development |
| SOC 2 / HIPAA | — | — | — | Roadmap — not certified |
| Support | Community | Priority | Dedicated + SLA |
Security
Good answers, even without a CISO.
FAQ
Common questions
Have another question? Ask us →
Give agents more work. Give old approvals less power.
Run a governed mission now, or bring us one consequential production workflow as a design partner.
No credit card. No claim that Pantheon is SOC 2 certified — because it is not yet.