For your IT
The checkpoint runs next to your AI. The AI never holds your passwords.
Suveren puts a checkpoint between the AI your company uses and your systems. Every action that changes something in email, ERP or CRM needs a signed OK from a named person first. If the checkpoint does not answer, nothing runs.
This page is for the people who would run it: what runs where, what leaves your network, what your team does, and what it can take over.
Architecture
What runs where
Calls that only read are checked against the limits too, but need no ticket. Only actions that change something need one.
Data
What leaves your network
- To the AI provider: what the AI reads and writes through its tools, for example the ERP records it looks up. That is the same as using that AI today. To keep it inside, use a model you host.
- To the Authority Server: who acted, under which permission, the kind of action, the details checked against the limits such as amount and recipient, the running totals and the time. Never a password. For a message, a fingerprint of its content, not the content itself.
- To Suveren: only during the first three weeks, while we host the Authority Server, in Frankfurt, under a data processing agreement. After that, nothing.
Access
Where the passwords are
The Gateway keeps the credentials for your systems in an encrypted vault on the computer where it runs (AES-256-GCM). The vault stays locked until a person logs in. The AI only ever sees the tools, the limits and the results, never a password or token.
Give each connector a service account with only the rights it needs. The limits decide what the AI may do. The service account decides what it could ever do.
People
Who approves, and how
People log in to the Gateway with their Suveren account. Each area, such as payments or email, has its own approvers. When an action needs a yes, the Gateway shows the request with everything needed to decide. The person approves or rejects it there, and their name goes on the ticket.
For each area, the person who gives the permission chooses one of three ways:
- Runs on its own: within the limits, every call gets its ticket and runs without asking anyone. The limits include amounts, recipients, systems, and daily and monthly totals across all calls.
- Asks first: every call becomes an approval request with the full action. Nothing runs until an approver says yes. A request that nobody answers expires after 72 hours; requests are kept seven more days, then deleted.
- Asks above a limit: below the amount you set, the call runs on its own; above it, it becomes an approval request as above. Above a fixed ceiling your team sets, nothing runs and no one can approve it.
Who may approve is set per area by your team's administrators. Being a member of the team alone does not allow anyone to grant permissions.
When something fails
If it does not answer, nothing runs
The Gateway fails closed. If the Authority Server cannot be reached, the AI's actions stop. There is no fallback and no reuse of old tickets. Your systems keep working for people as they do today, because the Gateway only sits in front of the AI. To stop one person's AI, stop their Gateway. To stop every AI action at once, stop the Authority Server: without it, no ticket is issued and nothing runs.
The ticket
What a ticket contains, exactly
- Mandate
- Maria Hofer · Customer Service Lead
- Scope
- payments.refund
- Limits
- ≤ €500 · single transaction · 20 a day
- Issued
- 2026-09-14 14:22 UTC
- Expires
- 2026-09-14 14:52 UTC
€127.40 → cust_4f81e2 · done 14:23 UTC
Gateway: allowed (within limits)
Every ticket contains:
- Who allowed it: the person's permission, and their name where their identity is verified.
- What: the kind of action and the system it runs in.
- The details checked against the limits, for example amount and recipient.
- The running totals for the day and the month, and the limits that applied.
- The approval, if someone had to say yes first.
- For a message: a fingerprint of its content, not the content itself.
- The time, and the Ed25519 signature that proves nobody changed it.
Anyone with the public key can check a ticket, without Suveren and without a network connection. The Gateway keeps its own signed copy of every ticket, and your auditor can export them.
A ticket never records how fast or how well anyone works. Who may read tickets and how long they are kept is agreed with your works council.
Connectors
How it reaches your systems
Every system connects through an MCP server, the open standard many software vendors now offer. The Gateway starts it, hands it its credentials, and refuses any tool that is not on its list. Where a system has no MCP server yet, we build one.
Ready today: Gmail, Google Calendar, Mollie payments, a CRM, a records store, LinkedIn and GitHub releases. For your ERP and CRM we check in the thirty minutes what exists for your version.
Running it
What your team runs
Updates come as numbered releases. As long as Suveren offers the service, it provides updates and security fixes free of charge for the unmodified software, and announces the end twelve months ahead. How many days your team needs in each step depends on your systems. We estimate it with you in the thirty minutes.
Run it, change it, build on it
Your IT can take it over from day one
The protocol took a year to describe. The software that follows it, AI built from scratch in a couple of months, working from written guides and a test suite. You get the same:
- The source code of both programs.
- The architecture guide the AI worked from, written for people and for AI coding assistants, so your own AI can work on the code safely.
- The full test suite, including the protocol tests, which shows whether a change broke anything.
- Both programs ready to install, and the path to every update.
With the AI coding assistant your team already uses, it can run the software, fix it and extend it from day one, with us or without us. That is the point: you should not have to pay a vendor every year for software your own people can own.
Who stands behind it
One person, and what you need to go on without him
Suveren is Andreas Schadauer with a network of partners. He described the protocol, the what and the why. AI wrote the software, the how, under his direction. Automated tests check it, including a test suite for the open protocol that runs against the real programs.
If Suveren stops, you keep running. The Gateway is open source, you hold the Authority Server's source code, and the protocol is open.
Law and compliance
GDPR, EU AI Act, NIS2
During the three hosted weeks, Suveren processes data for you under a data processing agreement. After that, both programs run under your control and your processes. Your roles under the EU AI Act and NIS2 depend on your use cases. We work them out with your counsel, your data protection officer and your IT in the three weeks.
Want the full detail?
The Human Agency Protocol specifies the ticket, the permissions and the checks in full.
The Human Agency Protocol →