The problem
Agents have the keys. Logs can't prove who authorized what.
Teams are handing AI agents write access: agents that merge code, change infrastructure, edit tickets, and touch customer data. When an agent does the wrong thing, what's left is scattered logs and third-party chat histories - editable, incomplete, and unable to prove that an action was authorized by an unexpired policy. Incident reconstruction is slow and unreliable.
The solution
A gateway that fails closed.
The Membrane sits directly in front of your agents. It requires a live, signed authorization for every model and tool call, records each action in a tamper-evident, hash-linked receipt chain, and blocks or severs the agent the moment the chain breaks. Approved actions are provable; unauthorized ones never hit production.
Under your control
Your systems. Your keys. Your policy.
Self-host the gate in your own environment. Hold your own keys, set the allowed models and tools, and check authorization before agents reach your systems. Keep a tamper-evident receipt chain for the actions that pass through the gate.
Why it's different
Enforce - don't just observe or filter.
It enforces, it doesn't just watch.
Observability tools explain what an agent did after the fact. Prompt filters rewrite text. The Membrane is an inline control point that refuses unauthorized actions before they reach production.
Authorization is bound to the action, not the prompt.
Every action carries a signed policy naming the exact model, tools, and scope, linked into a tamper-evident receipt chain. A silent model or tool swap breaks the chain and is blocked.
Incident reconstruction in minutes.
Because approvals and actions are hash-linked, you can trace any action to its authorizing policy and issuer - and hand auditors a signed evidence pack. No dependence on a provider's mutable logs.
Licensed content
Gate every step. Fail closed on missing provenance.
Agents that fetch, transform, or publish licensed assets pass through the Membrane first. Each operation needs a live, signed, time-bounded scope; if the asset's provenance is missing or unverifiable, no scope is issued and the call is blocked.
The demo, in six steps
Grant scope. Allow. Block. Sever. Reconstruct. Prove.
-
Grant scope
An operator issues a 15-minute authorization for a support agent: one model, tools limited to jira.comment and slack.post, bound to one task.
-
Approved action
The agent posts a ticket comment. A green, linked receipt shows policy → model → tool, all matching and chained to the prior receipt.
-
Blocked swap
The agent reaches for a different model, or for github.merge - outside the authorization. The Membrane blocks it; a red receipt shows exactly why.
-
Expiry / sever
The authorization expires, or security hits sever. The next tool call fails closed; an alert lands in the incident channel.
-
Reconstruct
Open the timeline, click any action, and see the model, context scope, policy, and issuer behind it - no log spelunking.
-
Export evidence
One click produces a signed evidence pack. Verify the hash chain offline in seconds. SIEM-ready JSON Lines or OCSF-inspired export for existing SOC tooling.
Try the isolated public sandbox, or run the same interactive walkthrough locally with one command.
Run it locally
One command. No relay, no secrets, no paid APIs.
The software includes the gate, CLI, receipt components, read-only operator dashboard and recommendation advisor. The local demo demonstrates gate checks and receipt chaining with ephemeral keys, an in-memory bus and simulated tool effects. Receipts also export as JSON Lines or OCSF-inspired JSON for an existing SIEM.
# clone the repo
git clone https://github.com/Z0rlord/the-membrane.git
cd the-membrane
# launch the local Membrane demo dashboard
cargo run -p membrane-cli -- demo
Then open http://127.0.0.1:8790/