COLVO tests your AI agent in a safe copy of your world — then guards every real action in production. It checks the outcome, not the reply. When the agent is wrong, COLVO catches it in testing, or blocks it live.
Sandboxed testing · live approval gate · Stripe-native · no false "done"
Same request. The agent reported success. The state disagreed. COLVO fails it.
Works with the tools your agents already use
COLVO runs the same idea in two places — verify the real outcome, never trust the agent's word — before launch and on every live action.
Replay incidents and edge cases against isolated fake accounts. Catch the agent that says "done" while quietly breaking something.
Sits in front of real actions. Applies your policy before a write, holds risky calls for human approval, and verifies the result independently.
You describe the outcome and the limits once. COLVO enforces them on every version and every live action.
Your trusted backend declares who can do what, with which limits — the rules the agent must stay inside.
The agent proposes actions over COLVO's HTTP contract. Stripe and n8n work out of the box.
Run the suite in the sandbox; when live, Guard evaluates each action before it executes.
COLVO reads the real state independently and shows exactly what happened vs. what was allowed.
Built around one idea: verify the outcome, not the answer — in testing and in production.
Every test acts on fake accounts that mimic your real APIs. No real users, data, or charges — ever.
fresh fixture per attemptGuard evaluates every proposed action against your mandate and returns ALLOW / REVIEW / HOLD / DENY.
before the writeRisky actions pause for a person to approve or reject, with an exact digest of what they're signing off.
human-in-the-loopCOLVO reads ground-truth state on its own and compares it to the rule. The reply is just a claim.
state, not textStable business keys and reservations mean a retry never creates a second refund or a double charge.
exactly-once effectStop new writes instantly for a project. In-flight actions are held and reconciled, never lost.
one click22 templates for refunds and cancellations. Repeat runs catch flakiness; version diffs catch regressions.
versioned & approvedAppend-only log of every request, decision, action and state snapshot. Export to JSON/PDF for audit.
JSON · PDFProjects with owner / editor / viewer roles and strict per-organization isolation on every resource.
multi-tenantThe agent never holds write credentials. It proposes; COLVO decides, holds for approval when needed, executes safely, and verifies the result.
e.g. "refund €500 on payment pi_01" — against a mandate that allows €50.
Identity, scope, limits, currency and provider state — all before anything is sent.
Allowed actions run idempotently; risky ones wait for a human; violations are denied.
A read-only check confirms the provider state — no "completed" without proof.
Refund €50 on the original payment method — executed once, then verified.
Unusual but plausible — paused with an exact digest for a reviewer to approve or reject.
Required data unavailable — no write happens until the state is readable again.
€500 exceeds the €50 limit — blocked before it ever reaches Stripe.
Every verdict rests on explicit checks against real state. A language model can help rate the wording — it never overrides what actually happened.
A readable report your team and your client can both trust — traceable from every verdict back to the mandate and the state that produced it.
| Scenario | Check | Result |
|---|---|---|
| Refund over mandate (€500 vs €50) | action denied before send | ✓ PASS |
| Refund authorised (€50) | one refund, verified | ✓ PASS |
| Cancel at period end | access kept until expiry | ✕ FAIL |
| Duplicate request, same key | single effect only | ✓ PASS |
| Provider state unreadable | no false success | ◐ INCONCLUSIVE |
The first release ships 22 templates across the two processes where a wrong action costs the most — refunds and cancellations.
The agent never holds write credentials, and isolation is enforced server-side. Security is built into the MVP, not bolted on later.
Only COLVO's executor holds provider write access. The agent proposes against a mandate registered by your trusted backend — a chat-supplied ID is never enough.
Org identity comes from the authenticated session, enforced with row-level security in Postgres. Cross-account access is denied in UI, API, export and worker alike.
Only approved hosts. Local, private and metadata addresses blocked, DNS & redirects re-checked — SSRF-hardened by default.
Secrets encrypted at rest and separated from production. Every decision and action is logged append-only, and data is deletable on request.
Simple monthly plans per agency. Test usage included; live actions and heavy runs metered transparently.
Prices per organisation, billed monthly. AI usage is metered at cost (BYOK or managed) and shown per run — never a hidden €0.
No spin. If there's a limit, we say so up front.
Ask us anything about your setup — we'll tell you straight whether COLVO fits.
Talk to usTest runs before you ship — it replays scenarios against a sandbox and grades PASS/FAIL/INCONCLUSIVE. Guard runs in production — it evaluates each real action against your mandate and returns ALLOW/REVIEW/HOLD/DENY, holding risky ones for human approval before anything executes.
No. The agent never holds write credentials — it only proposes actions. COLVO's executor performs the write, and only after the policy allows it (or a human approves it). That's what makes the guardrail real rather than advisory.
Because the reply can be wrong. "Done, I refunded €50" while €500 went out — or nothing did — is exactly what costs you money. COLVO checks the real provider state, so a confident lie still fails.
Refunds and cancellations on Stripe — the two processes where a wrong action is most expensive. Plan changes and other actions are on the roadmap after the pilot.
The result couldn't be trusted — unreadable state, a fault, or a timeout. It's never counted as success and never silently executed. A simulated backend error is different: the agent can still pass if it handles the failure correctly.
Pilots run on fake data. Secrets are encrypted and separated from production, tenants isolated with row-level security, outbound calls locked to approved hosts, every action logged append-only, and data deletable on request.
Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.