Reading authorized documents → Execute
An example configuration where a connected MCP Server's read tool is executed only within the scope of authorized documents. These settings can be adjusted based on the specific tool or target data.
The public Lab is read-only and contains no actual tools. Please start by connecting to a test repository to interact with real environments.
MCP Tool Calls and GitHub operations from AI agents are routed through AgentGate. Rules are configured for each Server, Tool, target dataset, and Agent, determining whether to "execute automatically," "execute after human approval," or "do not execute" prior to action.
An example configuration where a connected MCP Server's read tool is executed only within the scope of authorized documents. These settings can be adjusted based on the specific tool or target data.
An example configuration that pauses operations like MCP updates or GitHub PR merges, executing only the original requests approved by a human via the management console.
Tool Calls lacking defined rules or explicitly prohibited actions (such as repository deletion) are halted before being sent to the target. Unknown Servers or Tools are also rejected by default.
The activity screen records details such as the Agent, Server, Tool, and target data; rule evaluations; human approvals or rejections; and execution results. Even halted operations remain in the history, which can be filtered by Server or Tool. Sensitive information is excluded from the display.
View recorded contentRegister public HTTPS MCP Servers that support Streamable HTTP, synchronize provided Tools, and configure rules. GitHub support covers seven standard operations; control is limited to repositories selected within the GitHub app—such as creating/closing issues or merging pull requests.
Read the Quick Start guidev1.1 evaluates GPT-6 Astra's multi-step plans against policy, risk, data, and approval criteria external to the model before execution.
Routes GitHub operations through AgentGate, allowing you to select automatic execution, pending approval, or blocking for each operation. Logs all requests, determinations, approvals, and execution results.
Supports everything from MCP Server registration and tool synchronization to per-tool rules, human approvals, and execution history. Prevents direct access by combining authentication and network restrictions on the destination side, without passing upstream credentials to the AI agent. GitHub integration remains available.
Manages AI agent ownership, organizational affiliation, granted permissions, delegator identity, and accessible data. Applies dynamic masking to return only permissible data segments as needed.
Evaluates agents, timing, data, operations, past actions, and objectives, then selects automatic execution, pending approval, or blocking based on risk scores. LLM-based intent analysis can be enabled on an organizational basis. Natural language policies are published after review and simulation.
Reproduces past decisions in read-only mode via a "Black Box." Remediation tools verify state and require human approval for high-impact operations. Integrates inter-agent communication, lifecycle management, shadow modes, model/budget controls, compliance rules, and RBAC into pre-execution controls. Also supports Stripe contract synchronization.
Acts as an Enterprise AI Control Plane, integrating permissions, data, risk, approvals, and auditing into a unified execution path. Supports organizational emergency halts, decision ID tracking, session revocation, and queue retry/quarantine. Configures destination authentication and network restrictions to prevent direct access from agents.
With Astra Control Lab—which requires no account—you can generate tool-calling plans from goals, and AgentGate will classify each step as ALLOW, REQUIRE_APPROVAL, or BLOCK. The public Lab generates plans only and does not execute actual tools; we recommend GPT-6 Astra for production-grade intent analysis.
ALLOW, BLOCK, REQUIRE_APPROVAL, and basic policies are permanently available on Free. Paid plans are billed monthly in Japanese yen with no setup fee.
¥0 (tax incl.) / month
¥4,980 (tax incl.) / month
¥14,800 (tax incl.) / month
¥39,800 (tax incl.) / month
Custom quote
Limits, retention, and onboarding terms are defined in your contract.
Contact us for EnterpriseFree requires no card. Upgrade from the management console. Monthly actions use UTC calendar months, and retries with the same request are not counted twice. Legal notice for online sales
You can start using the Free tier without registering a credit card. You can upgrade from the permanently free basic features to a paid plan as your usage scales.