AgentGatev1.1 Official Release
v1.1 Official Release · GPT-6 Astra Control Lab

Control AI tool actions
before execution.

The public Lab is read-only and contains no actual tools. Please start by connecting to a test repository to interact with real environments.

MCP Tool Call ExampleEvaluation before sending to the target tool
Action Requested by AIdocument.read
AgentGateReview Configured Rules
Execute Automatically
Human Review Required
Do Not Execute
MCP + GitHubRules per toolNo execution without approvalBlocked by defaultLogging of evaluations and executions
01 / Capabilities

Determine execution behavior for each tool operation.

MCP Tool Calls and GitHub operations from AI agents are routed through AgentGate. Rules are configured for each Server, Tool, target dataset, and Agent, determining whether to "execute automatically," "execute after human approval," or "do not execute" prior to action.

Configuration examples

Execute Automatically

Reading authorized documents → Execute

An example configuration where a connected MCP Server's read tool is executed only within the scope of authorized documents. These settings can be adjusted based on the specific tool or target data.

Human approval

Operations involving changes → Execute after approval

An example configuration that pauses operations like MCP updates or GitHub PR merges, executing only the original requests approved by a human via the management console.

Do Not Execute

Unauthorized operations → Block

Tool Calls lacking defined rules or explicitly prohibited actions (such as repository deletion) are halted before being sent to the target. Unknown Servers or Tools are also rejected by default.

02 / What Is Logged

You can review the AI's intended actions later.

The activity screen records details such as the Agent, Server, Tool, and target data; rule evaluations; human approvals or rejections; and execution results. Even halted operations remain in the history, which can be filtered by Server or Tool. Sensitive information is excluded from the display.

View recorded content
Information recorded in activity logsHistory per operation
AI requests
Agent, Server, Tool, and target data
Rule evaluations
Automatic execution, pending approval, and blocking
Human verification
Approval and rejection
Execution at the connection destination
Success, failure, not executed, and unknown result
03 / Current Scope

Register MCP Servers. GitHub support is also included.

Register public HTTPS MCP Servers that support Streamable HTTP, synchronize provided Tools, and configure rules. GitHub support covers seven standard operations; control is limited to repositories selected within the GitHub app—such as creating/closing issues or merging pull requests.

Read the Quick Start guide

GitHub Appの権限を確認する

Capabilities in v1.1MCP + GitHub
MCP Server
Registration, connection verification, and stopping
Tool
List view and schema synchronization
Rules
Server, Tool, Agent, and target data
Credential
Managed via reference names instead of passing actual values
GitHub
Seven operations for selected repositories
04 / Current features and future updates

From MCP and GitHub to enterprise AI operations.

v1.1 evaluates GPT-6 Astra's multi-step plans against policy, risk, data, and approval criteria external to the model before execution.

The public Astra Lab is read-only and does not execute actual tools. Rollback in the production Control Plane applies only to supported tools; model and SSO connections require configuration.
v0.1Already available; continues in v1.1Confirm GitHub operations before executionProvides rules per operation, human approval workflows, and operation logs for GitHub.Learn more

Routes GitHub operations through AgentGate, allowing you to select automatic execution, pending approval, or blocking for each operation. Logs all requests, determinations, approvals, and execution results.

  1. AI Agent
  2. AgentGate
  3. Auto-execute / Pending Approval / Block
  4. GitHub
  • Runtime Firewall
  • Approval
  • Activity / Audit Log
v0.2Already available; continues in v1.1Supports operations for tools other than GitHubManages Tool Calls from registered MCP Servers by allowing, holding for approval, or blocking them prior to execution.Learn more

Supports everything from MCP Server registration and tool synchronization to per-tool rules, human approvals, and execution history. Prevents direct access by combining authentication and network restrictions on the destination side, without passing upstream credentials to the AI ​​agent. GitHub integration remains available.

  1. AI Agent
  2. AgentGate MCP Gateway
  3. Allow / Pending Approval / Block
  4. Registered MCP Tools / GitHub
  • MCP Gateway
  • Server / Tool Registry
  • Generic Policy / Approval / Audit
  • GitHub integration maintained
v0.3Already available; continues in v1.1Manage permissions and delegation for each AIManages AI ownership, assigned permissions, and data visibility.Learn more

Manages AI agent ownership, organizational affiliation, granted permissions, delegator identity, and accessible data. Applies dynamic masking to return only permissible data segments as needed.

  1. Agent Identity
  2. Owner / Department
  3. Authority / Delegation
  4. Data Access / Dynamic Masking
  • Agent Identity
  • Owner / Department
  • Authority / Delegation
  • Data Access
  • Dynamic Masking
v0.4Already available; continues in v1.1Assess risk based on context and past behaviorEvaluates risk by considering not only the operation itself but also the time, data, purpose, and history.Learn more

Evaluates agents, timing, data, operations, past actions, and objectives, then selects automatic execution, pending approval, or blocking based on risk scores. LLM-based intent analysis can be enabled on an organizational basis. Natural language policies are published after review and simulation.

  1. Agent, Time, Data
  2. Operation, History, Objective
  3. Risk Score
  4. Auto-execute / Pending Approval / Block
  • Risk Engine
  • Intent Analysis
  • Behavioral Intelligence
  • Reputation
  • Adaptive Authority
  • AI SOC
v0.5ProvidedUnifying AI operations and incident responseSupports reproducing decisions and performing remediation actions, promoting or halting agents, and controlling models and budgets.Learn more

Reproduces past decisions in read-only mode via a "Black Box." Remediation tools verify state and require human approval for high-impact operations. Integrates inter-agent communication, lifecycle management, shadow modes, model/budget controls, compliance rules, and RBAC into pre-execution controls. Also supports Stripe contract synchronization.

  1. Recording & Reproduction
  2. Decision & Response
  3. Recovery & Halt
  4. Continuous Operation
  • AI Black Box
  • Decision Replay
  • Rollback
  • Agent-to-Agent Security
  • Agent Lifecycle
  • Simulation / Shadow Mode
  • Multi-model Governance
  • Model Routing
  • Cost Control
  • Compliance
v1.0ProvidedUnified management of enterprise AIManages access to AI and business systems based on human and corporate policies.Learn more

Acts as an Enterprise AI Control Plane, integrating permissions, data, risk, approvals, and auditing into a unified execution path. Supports organizational emergency halts, decision ID tracking, session revocation, and queue retry/quarantine. Configures destination authentication and network restrictions to prevent direct access from agents.

  1. People / Company
  2. Enterprise AI Control Plane
  3. AI Workforce
  4. Enterprise Systems
  • Identity
  • Authority
  • Policy
  • Data Control
  • Risk
  • Approval
  • Audit
  • Replay / Rollback
  • Agent Security
  • Lifecycle
  • Compliance
  • Cost
v1.1Current · Production VersionControl Astra's plans before they become actionsIndependently evaluates each step of the multi-step tool calls generated by GPT-6 Astra.Learn more

With Astra Control Lab—which requires no account—you can generate tool-calling plans from goals, and AgentGate will classify each step as ALLOW, REQUIRE_APPROVAL, or BLOCK. The public Lab generates plans only and does not execute actual tools; we recommend GPT-6 Astra for production-grade intent analysis.

  1. Goal
  2. GPT-6 Astra Plan
  3. AgentGate Decision
  4. Allow / Hold / Block
  • GPT-6 Astra
  • Multi-step Planning
  • Public Control Lab
  • Read-only Simulation
  • Independent Policy
  • Risk Receipt
Pricing

Start free, then scale with your usage.

ALLOW, BLOCK, REQUIRE_APPROVAL, and basic policies are permanently available on Free. Paid plans are billed monthly in Japanese yen with no setup fee.

Free

¥0 (tax incl.) / month

  • 1 agents
  • 1 MCP servers
  • 1,000 actions / month
  • 7-day audit log
  • Personal workspace
  • Basic policy, approval, and audit
Start free

Starter

¥4,980 (tax incl.) / month

  • 5 agents
  • 3 MCP servers
  • 10,000 actions / month
  • 30-day audit log
  • Personal workspace
  • Basic policy, approval, and audit
Register free and choose a plan

Team

¥14,800 (tax incl.) / month

  • 20 agents
  • 10 MCP servers
  • 100,000 actions / month
  • 90-day audit log
  • Up to 10 members
  • Advanced administration
Register free and choose a plan

Business

¥39,800 (tax incl.) / month

  • 100 agents
  • 50 MCP servers
  • 1,000,000 actions / month
  • 365-day audit log
  • Up to 100 members
  • Advanced administration and SSO
Register free and choose a plan

Free requires no card. Upgrade from the management console. Monthly actions use UTC calendar months, and retries with the same request are not counted twice. Legal notice for online sales

v1.1 Official Release

Confirm AI tool operations before execution.

You can start using the Free tier without registering a credit card. You can upgrade from the permanently free basic features to a paid plan as your usage scales.

Get Started for Free