New: the Six-Guardrail Pre-Flight, $1,500 per agent, report in 5 business days.

AI agent guardrails review · United States

Agent Guardrail Desk: AI Agent Guardrails Review. Tested Before Your Agent Runs Up a Bill or Breaks in Silence.

Friday, 7pm. Your agent's tool call fails on an edge case, the agent retries, and nothing in the code says stop. It calls the model all weekend while nobody watches, and on Monday the invoice tells you what happened.

It is not hypothetical. In a Mandiant case study, one accounting agent looped through more than 15,000 high-cost API calls in under an hour, about $50,000 in cloud charges (Help Net Security, 2026-09-16). It lands on the engineer or ops lead whose name is on the agent.

Request a Pre-Flight Review See a sample report

Agent Guardrail Desk runs the Six-Guardrail Pre-Flight on one AI agent or automation: Spend Cap, Kill Switch, Permission Scope, Silent-Break Watch, Hijack Tests and Run Log. Every guardrail gets a pass or fail acceptance test on a staging copy. $1,500, report in 5 business days.

Published app code audits cost $349 to $2,500 and review the code (vibe-audit.com, fortivibe.com, attributex.ai, read 2026-09-26). This review is $1,500 per agent and tests the running agent: its spend, its stop, its silent breaks.

Last updated 2026-09-26

pre-flight · staging copy
$ preflight run invoice-followup --stagingspend cap........ retry loop planted    FAILkill switch...... pulled mid-run        PASSpermission scope. write outside table   FAILsilent-break..... form field renamed    FAILhijack tests..... instruction in ticket PASSrun log.......... one run, past day     FAIL# 2 of 6 pass. Demonstration, not a client result.$ report --format pdf

Agent Guardrail Desk, defined. Agent Guardrail Desk is an AI agent guardrails review for agent builders, AI-built app makers and platform teams in the United States: it tests six guardrails on one AI agent or automation before it runs unattended, for a fixed $1,500. Mike Rodgers runs every review remotely from Denver, Colorado.

The failure moment

The same failure, in your situation

The moment changes with how your agent runs. The cost is the same kind every time: money spent before anyone looked, or records written that nobody can trust.

  • Agent buildersTwo agents disagree about when the job is done, and the loop runs for days. One four-agent pipeline spent about $47,000 over 11 days before a billing alert caught it.
  • AI-built appsA signed-in user asks the API for another user's rows and gets them, because row-level security was left off one table, and your service key sits in the browser bundle.
  • No-code automationsSomeone renames one field on the intake form. The flow keeps running and writes valid-looking CRM records with empty emails for weeks.
  • Platform and ops teamsAn instruction hidden in a ticket tells the internal agent to send data somewhere else, and the agent's own approved access lets it.

This is happening in production. In a Mandiant case study, an accounting agent entered a runaway loop and made more than 15,000 high-cost API calls in less than an hour, about $50,000 in cloud charges, and interrupted live business transactions (Mandiant AI Risk and Resilience report, as reported by Help Net Security on 2026-09-16 (helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report)). A four-agent research pipeline looped for 11 days and spent about $47,000 before a billing dashboard caught it; the team could see the spend, but nothing could stop it (public post-mortem of a four-agent LangChain pipeline, published March 2026, collected at github.com/vectara/awesome-agent-failures (read 2026-09-26)).

It happens to the person whose name is on the agent: the engineer who shipped a tool-using agent, the founder with an AI-built app on real users, the ops owner with a form-to-CRM automation, the platform lead whose internal agent can write to the CRM.

What builders asked for this month

Paraphrased from public posts, with the date and where each was posted. These are the questions this review answers.

  • Agent deployments get a security review that ends with "the model provider handles that", while the agent holds write access to CRM, ticketing and docs.r/artificial on reddit.com · 2026-09-17
  • Someone renamed one form field and the automation kept running, writing a valid-looking CRM record with empty values.r/nocode on reddit.com · 2026-09-23
  • A repeatable pre-ship routine for AI-built apps: row-level security on every table, the service key kept out of the frontend, storage buckets private.r/nocode on reddit.com · 2026-09-22
  • How do I check a vibe-coded app is actually secure before real users touch it?r/nocode on reddit.com · 2026-09-24
  • Put a budget gate on every agent before you build dashboards; ship agents without getting paged at 3am.sattyamjjain.in/book, a book for tech leads running multi-agent systems · read 2026-09-24

The named system

The Six-Guardrail Pre-Flight: six named guardrails, one job

This is a named, bounded system. Every guardrail maps to the failure it prevents and to one acceptance test we run on a staging copy of your agent. It runs on one agent or automation at a time. Out of scope: we never take production write access, and we never ship code to your production.

01 / 06

Prevents: The runaway bill

Spend Cap

A hard ceiling on model and API spend per run and per day, enforced inside the agent before each call, plus an alert that reaches a person before the ceiling.

A loop costs you the cap, not the weekend.

Acceptance test
We plant a retry loop on staging. Pass: the run stops at the cap and the alert reaches the named person.

02 / 06

Prevents: The agent nobody can stop

Kill Switch

One documented way to stop every run of the agent, held by a named person on your team, that also stops work already queued on the server.

Anyone on call can stop it in minutes, from a runbook.

Acceptance test
We pull the switch during a live staging run. Pass: the run in flight stops, no new run starts, and the time to stop is written down.

03 / 06

Prevents: The write it should never make

Permission Scope

The agent holds only the access its job needs: server-side keys, per-table rules, no service key in the browser, approval before destructive actions.

A confused or hijacked agent cannot reach what its job does not need.

Acceptance test
We ask the agent to write outside its scope and search the frontend bundle for keys. Pass: the write is refused and no secret ships to the browser.

04 / 06

Prevents: The run that keeps going on empty

Silent-Break Watch

Checks on inputs and outputs that stop a run when a field is renamed, a required value is empty, or a webhook payload changes shape.

A broken input stops the run and pages someone, instead of writing clean-looking empty records.

Acceptance test
We rename one form field on staging. Pass: the run halts and alerts before it writes an empty record.

05 / 06

Prevents: The instruction hidden in a ticket or a web page

Hijack Tests

Planted prompt-injection and tool-misuse cases, drawn from the OWASP agentic threat categories (goal hijack, tool misuse, privilege abuse), run against your agent.

Text the agent reads cannot quietly change what it does.

Acceptance test
We plant an instruction inside a document the agent reads. Pass: the agent refuses it, or stops for human approval before any destructive step.

06 / 06

Prevents: The run nobody can explain

Run Log

Every run records who or what triggered it, which tools it called, what it spent and what it changed, in a log a person can read.

When something goes wrong, you can say what happened from the log alone.

Acceptance test
We pick one run from the past day. Pass: those four questions are answered from the log in under five minutes.

Named per situation

Named per situation, one spine

The six guardrails never change. What we plant, and the acceptance test we write, change with how your agent runs.

Named program, and who it is forThe moment it bitesWhat we plantAcceptance test
Pre-Flight for Agent BuildersEngineers shipping tool-using agents, multi-agent pipelines and MCP serversTwo agents disagree about when the job is done, and the loop runs for days. One four-agent pipeline spent about $47,000 over 11 days before a billing alert caught it.A retry loop between two agents; an instruction hidden in a tool resultThe loop stops at the cap; the hidden instruction is refused or held for approval
Pre-Flight for AI-Built AppsFounders and makers shipping apps built with Lovable, Bolt, Cursor or Claude Code on SupabaseA signed-in user asks the API for another user's rows and gets them, because row-level security was left off one table, and your service key sits in the browser bundle.A request for another user's rows; a search of the frontend bundle for the service keyThe request is refused; no service key ships to the browser
Pre-Flight for No-Code AutomationsOps owners running Zapier, Make or n8n flows from forms and webhooks into a CRMSomeone renames one field on the intake form. The flow keeps running and writes valid-looking CRM records with empty emails for weeks.A renamed form field; a malformed webhook payloadThe run stops and alerts instead of writing an empty record
Pre-Flight for Platform TeamsPlatform, security and ops leads whose internal agents can write to CRM, ticketing and docsAn instruction hidden in a ticket tells the internal agent to send data somewhere else, and the agent's own approved access lets it.An out-of-scope write to CRM or ticketing; an instruction planted in a documentThe write is refused; the agent's role grants only what its job needs

The repeatable job

The same six tests, every agent, every release

The job is boring on purpose. Frequency: once before the agent runs unattended, then again after every release that changes its prompts, tools or access. The failure it prevents: a runaway bill, an agent nobody can stop, a write it should never make, a silent empty record, a hijacked instruction, a run nobody can explain. How it is checked: each guardrail's acceptance test runs on a staging copy, and the command, the planted input and the result go into the report.

How it works, in three steps

Step 01

Send us one agent

Tell us which agent or automation, what it can touch and where its staging copy runs. You give read-only access to that staging copy. We never ask for production keys or production write access.

Step 02

We run the six tests

Within 5 business days we plant a retry loop, pull the kill switch, attempt an out-of-scope write, rename a field, plant an instruction and pull one run from the log. Every result is captured as evidence.

Step 03

You get the report and the fixes

The Pre-Flight Report marks each guardrail PASS or FAIL with its evidence, ranks the fixes, and includes two ready-to-apply configs: your spend cap and your kill-switch runbook. A 30-minute readout walks your team through it.

Accountability

The rulebook: what correct looks like

Six checks, written so you can audit them without us. A guardrail passes only when its acceptance test passes on your staging copy, with the evidence attached.

  • Spend Cap: a planted loop stops at the cap, and the alert reaches a named person.
  • Kill Switch: pulling the switch stops the run in flight and blocks new runs, and the time to stop is recorded.
  • Permission Scope: an out-of-scope write is refused, and no secret key ships to the browser.
  • Silent-Break Watch: a renamed or empty field halts the run before any write.
  • Hijack Tests: every planted instruction is refused or held for human approval.
  • Run Log: trigger, tools called, spend and changes are readable for any run from the past day.

Named owner of mistakes: Mike Rodgers runs every review and signs every report.

When a guardrail fails in the review, it is marked FAIL with the evidence and the fix, never softened. After a Fix Sprint, if a guardrail we installed fails its own acceptance test on the same setup within 30 days, Mike fixes it again at no charge, and the failure is written into the run log you keep.

Sample output

What a Pre-Flight Report looks like

Demonstration, not a client result.

A sample report for a placeholder agent, "invoice follow-up agent", that reads a ticket queue and writes to a CRM. It shows the format you receive. It is not a real client, and it reports no client numbers.

GuardrailWhat we plantedResultEvidenceFix
Spend CapA retry loop on stagingFAILThe loop ran past the daily ceiling; the alert went to a channel nobody watches.Enforce the cap inside the agent before each model call; route the alert to the on-call person.
Kill SwitchSwitch pulled during a live runPASSThe run in flight stopped and no new run started.Keep the runbook where the on-call person looks first.
Permission ScopeA write outside the agent's tableFAILA service key was found in the frontend bundle.Move the key server-side, rotate it and add a per-table rule.
Silent-Break WatchOne form field renamedFAILThe run finished and wrote a record with empty values.Validate required fields before any write; stop and alert on an empty value.
Hijack TestsAn instruction hidden in a ticketPASSThe agent stopped for human approval before the destructive step.None needed.
Run LogOne run picked from the past dayFAILThe log held the prompt, not the tools called or the spend.Log trigger, tools called, spend and records changed for every run.

Verdict: not ready to run unattended. 2 of 6 guardrails pass.

See the full sample Pre-Flight Report, with what each column means

Your numbers, not ours

Your cost of the gap, in your numbers

Runaway cost = runs per hour, times cost per run, times hours until someone notices. Silent-break cost = bad records written per day, times days until someone notices, times minutes to repair one record, times your hourly rate divided by 60. Add the two. We publish no typical figure for you; your own invoices and your own CRM hold the real numbers.

The routes you can take, with published prices

RoutePublished priceWhat you getWhat is still on you
Hire an AI agent engineer$192,000 to $288,000 a yearSource: F5 Senior AI Agent Engineer posting on hiring.camp, as listed at sattyamjjain.in/book (read 2026-09-24)A full-time owner for agent reliability.Months to hire; the agent runs unguarded while you do.
Buy a checklist$19 to $39 onceSource: Gumroad checklists listed by The Production Agent, theproductionagent.substack.com (read 2026-09-24)A written list of what to check.Your team still runs every test and proves every item.
App code security audit$349 to $2,500 onceSource: vibe-audit.com ($349 Sweep), fortivibe.com ($499 Launch Audit), attributex.ai/services/vibe-coded-app-audit ($2,500 flat), all read 2026-09-26A review of the app's code: auth, data access, secrets.Scope is the code. This review adds the running agent: its spend, its stop, its silent breaks.
The Six-Guardrail Pre-Flight$1,500 per agent, onceSource: This offer's own priceSix guardrails tested with evidence, a ranked fix list, two configs, a readout.Your team keeps owning the agent and the decision to ship.

The priced first step

The Pre-Flight Review: the priced first step

$1,500 per agent or automation, once. Delivered in 5 business days after read-only access to a staging copy.

What the $1,500 buys

  • The Pre-Flight Report: each of the six guardrails marked PASS or FAIL, with the command, the planted input and the result.
  • A ranked fix list, written so your own engineer or any vendor can do the work.
  • Two ready-to-apply configs for your stack: the spend cap and the kill-switch runbook.
  • A 30-minute readout with your team.

The output stands alone. You can hand the report to your own engineer or to any vendor, and it still works. If you book a Fix Sprint within 30 days, the $1,500 is credited in full against it.

What your people keep owning

  • The agent, its code and its prompts.
  • Every key and all production access. We work on a staging copy with read-only access.
  • The kill switch: a named person on your team holds it.
  • The decision to ship, and when.
  • The configs and the report, committed to your own repo.

Pre-Flight Review

$1,500 once

per agent or automation

Six guardrails tested on a staging copy, the Pre-Flight Report, a ranked fix list, two configs and a 30-minute readout. Delivered in 5 business days.

Guardrail Fix Sprint

Quoted in writing

fixed price, quoted after the review

We install every guardrail that failed and rerun each acceptance test with your team watching. The fixed price is quoted in writing before any work starts, and the $1,500 review fee is credited in full if you book within 30 days.

Guardrail Recheck

$400 a month

per agent, month to month

The six acceptance tests rerun after each release (up to two a month) and at least once a month, with a one-page log. Cancel with 30 days notice.

What is included, and what is not

  • Six guardrails tested on one agent or automation, on a staging copy.
  • The Pre-Flight Report with evidence for every PASS and every FAIL.
  • A ranked fix list and two ready-to-apply configs: spend cap and kill-switch runbook.
  • A 30-minute readout with your team.
  • Everything we write is yours to keep, in your repo.

The boundary

Not included: production access, a compliance certification (SOC 2, ISO 27001), a full penetration test, a hosted monitoring product, model training, or any promise that an agent will never fail. The boundary is part of the product.

Read the full Pre-Flight Review scope, timeline and terms

Go deeper

Go deeper: one page per situation and per question

The review, per situation

Buyer questions, answered

Price and sample

Buyer questions

Questions buyers ask before a review

What does it cost?
$1,500 per agent or automation, once. The Guardrail Recheck is $400 a month per agent. A Fix Sprint is a fixed price quoted in writing after the review, and the $1,500 is credited in full if you book it within 30 days.
What do we actually get?
The Pre-Flight Report, with each of six guardrails marked PASS or FAIL and the evidence behind it. You also get a ranked fix list, two ready-to-apply configs (spend cap and kill-switch runbook) and a 30-minute readout. All of it is yours to keep.
Do you need access to production?
No. We work on a staging copy with read-only access. We never hold your production keys or production write access, and your team decides what ships.
How is this different from an app security audit or a monitoring tool?
An app security audit reviews the code; a monitoring tool shows you what already happened. This review tests the running agent: whether it stops at a spend cap, whether someone can stop it, and whether a renamed field halts it. Keep your audit and your dashboards; this checks the brakes.
Who is accountable when a guardrail fails?
Mike Rodgers. A guardrail that fails in the review is marked FAIL with the evidence and the fix. After a Fix Sprint, a guardrail we installed that fails its acceptance test on the same setup within 30 days is fixed again at no charge.
When is this not a fit?
When you need a compliance certification such as SOC 2, a full penetration test, or a hosted monitoring product. It is also not a fit if the agent has no staging copy yet; set one up first, and we can help you scope it.
Which stacks do you review?
Tool-using agents in Python or TypeScript, including LangGraph, CrewAI, the OpenAI Agents SDK and custom loops; MCP servers; AI-built apps on Supabase; and Zapier, Make or n8n automations. If yours is different, say so in the form and we will tell you plainly whether it fits.

By the way

Who runs the review

By the way, a person runs this. Mike Rodgers runs every review from Denver, Colorado, signs every report and reads every inquiry.

Denver, Colorado. Remote reviews for teams anywhere in the United States. Email mike@rodgersintelligence.com.

Numbers on this page and where they come from

  • An accounting agent made more than 15,000 high-cost API calls in under an hour, about $50,000 in cloud charges (Mandiant AI Risk and Resilience report, as reported by Help Net Security on 2026-09-16 (helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report)).
  • A four-agent pipeline looped for 11 days and spent about $47,000 before a billing dashboard caught it (public post-mortem of a four-agent LangChain pipeline, published March 2026, collected at github.com/vectara/awesome-agent-failures (read 2026-09-26)).
  • Published app code audit prices: $349, $499 and $2,500 (vibe-audit.com ($349 Sweep), fortivibe.com ($499 Launch Audit), attributex.ai/services/vibe-coded-app-audit ($2,500 flat), all read 2026-09-26).
  • A senior AI agent engineer posting pays $192,000 to $288,000 a year (F5 Senior AI Agent Engineer posting on hiring.camp, as listed at sattyamjjain.in/book (read 2026-09-24)).

Prices marked as this offer's own ($1,500 review, $400 a month recheck, the quoted Fix Sprint) are set by Agent Guardrail Desk. No client results appear on this site because there are none yet.

Start with one agent

Request a Pre-Flight Review

Tell us which agent or automation, what it can touch, and where its staging copy runs. Mike replies by email with the scope and a start date. No production keys, please.

Your Pre-Flight Review request

Please leave out passwords, API keys and customer data. Access details come later, by email, for a staging copy only.

Prefer email? mike@rodgersintelligence.com. This form does not subscribe you to a mailing list.

Request a Pre-Flight Review