Pre-Flight for Agent Builders
Guardrails for tool-using AI agents, tested before the agent runs unattended.
Two of your agents disagree about when a job is done. One asks for more work, the other obliges, and neither has a rule that ends the loop. Your dashboard shows the spend climbing; nothing in the pipeline can stop it.
Request a Pre-Flight Review See the six guardrails
Last updated 2026-09-26 · Agent Guardrail Desk, Denver, Colorado
Pre-Flight for Agent Builders
Who this is for
Engineers shipping tool-using agents, multi-agent pipelines and MCP servers. This is the loop in the public post-mortem where four agents ran for 11 days and spent about $47,000 before a billing alert fired (public post-mortem of a four-agent LangChain pipeline, published March 2026, collected at github.com/vectara/awesome-agent-failures (read 2026-09-26)). The Pre-Flight for Agent Builders tests the brakes, not the dashboard.
What we plant in an agent pipeline
- A retry loop between two agents that never agree the job is done, to test the Spend Cap and a hard limit on rounds.
- A pulled kill switch while a run is in flight, including work already queued on the server.
- A tool call outside the agent's job, such as a write to a table or repo it should only read.
- A tool result that carries a planted instruction, from the OWASP agentic categories of goal hijack and tool misuse.
- A malformed tool response, to see whether the agent stops or carries on with empty values.
- One run picked from the log, to see whether trigger, tools called, spend and changes can be read back.
The acceptance tests for agent builders
Pass means: the planted loop stops at the cap or the round limit, whichever comes first, and the alert reaches a named person; the switch stops the run in flight and blocks new runs; the out-of-scope call is refused; the planted instruction is refused or held for human approval; the malformed response halts the run; and the run log answers the four questions in under five minutes.
What you receive
The Pre-Flight Report with evidence for each guardrail, a ranked fix list, a spend-cap config for your runtime and a kill-switch runbook your on-call person can follow. $1,500 per agent or pipeline, delivered in 5 business days after read-only access to staging.
The shared spine
The same six guardrails as every program
This is a named, bounded system. Every guardrail maps to the failure it prevents and to one acceptance test we run on a staging copy of your agent. It runs on one agent or automation at a time. Out of scope: we never take production write access, and we never ship code to your production.
| Guardrail | Failure it prevents | Acceptance test |
|---|---|---|
| Spend Cap | The runaway bill | We plant a retry loop on staging. Pass: the run stops at the cap and the alert reaches the named person. |
| Kill Switch | The agent nobody can stop | We pull the switch during a live staging run. Pass: the run in flight stops, no new run starts, and the time to stop is written down. |
| Permission Scope | The write it should never make | We ask the agent to write outside its scope and search the frontend bundle for keys. Pass: the write is refused and no secret ships to the browser. |
| Silent-Break Watch | The run that keeps going on empty | We rename one form field on staging. Pass: the run halts and alerts before it writes an empty record. |
| Hijack Tests | The instruction hidden in a ticket or a web page | We plant an instruction inside a document the agent reads. Pass: the agent refuses it, or stops for human approval before any destructive step. |
| Run Log | The run nobody can explain | We pick one run from the past day. Pass: those four questions are answered from the log in under five minutes. |
Price: $1,500 per agent or automation, once. Delivered in 5 business days after read-only access to a staging copy.
Questions
Questions about this
- Does a monitoring dashboard count as a spend cap?
- No. A dashboard shows spend after it happens. A spend cap is enforced inside the agent before each model call, so a loop stops at the cap instead of at the invoice.
- Can you review a multi-agent pipeline as one agent?
- Yes, if it ships as one pipeline with one owner. The six guardrails are tested at the pipeline level and at each agent that can call a tool.
- Do you review MCP servers?
- Yes. We test what the server lets an agent reach, whether its keys stay server-side, and whether a planted instruction in a tool result changes what the agent does.
Related
Related pages
Every page links back to the Agent Guardrail Desk home page, where the price, the rulebook and the request form live.
The review, per situation
Buyer questions, answered
Price and sample
Next step
Request a Pre-Flight Review for one agent
$1,500 per agent or automation, once. Delivered in 5 business days after read-only access to a staging copy. If you book a Fix Sprint within 30 days, the $1,500 is credited in full against it.