Stipul is an agent authorization and audit platform for tool-using AI agents. https://nitter.cf/t.co/33PWPIknjS | https://nitter.cf/t.co/J9ykwTrunP

Joined April 2026
1/5 Your AI agent can read your codebase, run shell commands, and call external APIs. In many setups, nothing stops it from doing something you did not authorize. And if it does, you may not be able to prove what happened. That is the problem Stipul is built for.
2
1
46
Stipul retweeted
We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks: openai.com/index/hugging-fac…
1,993
3,237
4,036
20,764
31,399,977
Writ sits between the agent and the tool. Before any call executes, Writ checks it against the Charter. Allowed? It passes. Not allowed? It is blocked. The decision happens before the action, not after the damage. That is the difference between runtime authorization and audit theater.
5
In Stipul, the Charter is not a prompt. It is not a system message. It is not advice the model interprets. The Charter defines the boundary. Writ checks every requested action against it before any tool call runs, not as a suggestion, but as enforcement. If your policy lives in the prompt, the model is grading its own homework. The Charter lives outside the reasoning loop. Writ checks. Chronicle records. Seal proves the record. That is not instruction. That is governance.
5
Most AI governance discussions start with the model. I think that's backwards. The interesting question isn't: "Why did the model think that?" It's: "What was the model allowed to do?" Agents become risky when they gain authority over tools, systems, and data. If a tool call can create a refund, modify infrastructure, access customer records, or approve a deployment, then authorization matters more than explanation. Control the action surface. Then prove what happened. Everything else is downstream.
3
Prompt injection attempts are inevitable. Unauthorized tool execution is optional. If an agent reads malicious instructions and tries to act on them, the question isn’t whether the model was fooled. The question is whether the tool call still goes through. That’s the boundary Stipul enforces.
4
Dashboards are not governance. If your security posture is a chart that updates every 15 minutes, you're watching not enforcing. Governance happens at the boundary where a request is evaluated before it executes. The dashboard comes after. Useful for visibility. Too late for control.
2
1/ We told an AI agent it could not run a shell command. It accepted the restriction. Then it offered to run the same command through a different tool. The policy worked. The agent routed around it.
1
1
19
4/ We are building Stipul to enforce policy at the tool-call boundary. This finding showed us the boundary still needs to get smarter. Most governance content shows the clean demo. We are showing the crack in the wall. Because that is where the real product has to be built.
1
4
We let the AI grade its own homework and call it governance. An LLM cannot be both the actor and the auditor of its own actions. That is not governance. That is self-grading on a curve. Real agent governance needs real controls: • Policy outside the model • Enforcement before execution • Proof after the action Prompts are not policy.
4
Today Stipul crossed a threshold. Agents can now be authorized not just at the tool level, but at the argument level. read_file("README.md") can be allowed while read_file(".env") is denied. Enforced before execution, recorded in Chronicle, verified with Seal. Not just access control. Scoped runtime authorization.
5
• Charter: Defines the boundary of permissible action. • Writ: Checks authorization at the tool-call boundary. • Chronicle: Records each decision, input, and policy result. • Seal: Cryptographic proof that the Chronicle has not been quietly altered.
1
9
“User approved it” is not a security model. Users do not understand the full execution path. Agents do not behave deterministically. Approval is not authorization. Policy boundaries should exist regardless of user intent.
2
Governance that only watches is not governance. It’s documentation. If an AI agent already accessed the data, called the API, or changed the file, your dashboard is late. Real governance acts before execution. Control before action. Proof after.
3
As a runtime authorization and audit layer, Stipul is closest aligned with 13 and 19. Shadow agents = untracked authority Local laptops = massive, messy attack surface The real problem isn’t the model. It’s the tool call. Prompts are not policy. Logs are not governance. Control before execution. Proof after.
My 30+ observations on the greatest opportunities in AI agents right now: And some ideas that are keeping me up at night. 1. The new buyer on the internet is an AI agent. Imagine billions of new customers showing up with money to spend but they only shop via MCP. That's what's happening. No MCP server means you're invisible to the fastest growing buyer on the internet. 2. Every franchise system in America (30,000+) needs an agent layer and none of them have one. One founder per franchise vertical. That's 30,000 businesses waiting. 3. Everyone said "distribution is the only moat" a year ago. Now I'd add that the only moat is distribution plus memory. The company that has your audience AND your agent's accumulated context is impossible to leave. 4. Consumer mobile is more interesting than it's been since 2012. Apps can finally DO things for you instead of showing you things. The next wave of $100M apps are being built right now. 5. The most interesting startup nobody has built is an agent marketplace where you rent access to someone else's trained agent. A recruiter spent 6 months training a sourcing agent on healthcare hiring. That agent is worth renting to every other healthcare recruiter on earth. The agent itself becomes the product. 6. A sorta strange phenomenon that's happening right now is agents are developing preferences. Give the same agent the same task 100 times and it starts developing patterns in how it approaches it. Nobody is studying this yet. But the agents that develop good patterns are worth more than the ones that don't. That's a new kind of asset. 7. Dead internet theory is about to become dead SaaS theory. Half the apps you use will quietly replace their support team, their onboarding team, and their content team with agents. You won't notice for months. Then you'll realize you haven't talked to a human at that company in a year. 8. The most valuable data in the world right now is sitting in the support tickets of small or mid tier SaaS companies. Every ticket is a customer telling you exactly what to build next. Mine this. 9. The most interesting pricing problem nobody has solved is how do you price a product when your costs change every time OpenAI or Anthropic updates their model pricing? Your margins can swing 40% overnight based on a decision made in San Francisco. The company that builds dynamic pricing infrastructure for agent-based businesses solves a problem every AI company has. 10. The best AI products feel like they're reading your mind. The worst ones feel like filling out a form with extra steps. 11. An interesting arbitrage I've noticed lately is hiring a human VA for $20/hour to supervise an AI agent that does $200/hour work. The human just checks the output. 12. The managed AI agent business is becoming the new agency model. $5k/month per client. You build it, run it, maintain it. The client gets a digital employee they never have to think about. This will be a $50 B+ category. 13. The first "shadow agent" scandals are about to drop. Employees running personal agents on company infrastructure without telling anyone. Using company API keys. Agents accessing internal docs. IT departments have little visibility into this right now. Lots of opportunity to build companies here. Definitely a painkiller not a vitamin type of business. 14. Right now there are probably millions of agents running on autopilot that their creators forgot about. Still burning tokens. Still sending emails. Still scraping websites. Still costing money. The "find and kill your zombie agents" tool is a product that writes itself. 15. Companies are starting to hire based on someone's agent portfolio instead of their resume. "Show me 3 agents you built that are running right now." It's REALLY early but it's starting. 16. Your Slack archive is a product. Every company's internal Slack has thousands of messages explaining how they actually do things. The company that lets you point an agent at your Slack history and auto-generate SOPs and agents from it will be enormous. 17. We're watching the cost of intelligence fall faster than the cost of distribution. Which means distribution is now the expensive thing. 18. The most underrated asset a human can have in 2026: the ability to sit in a room with another human, make eye contact, and have a real conversation. As AI handles more of the transactional stuff, the humans who can do the relational stuff become disproportionately valuable. The soft skills people used to dismiss as fluffy are becoming the hard skills. The hard skills people spent decades acquiring are becoming the soft ones. 19. There are MANY huge companies to be built around the fact that most people's agents are running on their personal laptops which they also use to browse the internet, check email, and download random files. The attack surface is enormous. One compromised Chrome extension and your agent's API keys, customer data, and workflows are exposed. 20. There's a new type of burnout forming that doesn't have a name. It's not from working too hard. It's from context switching between human work and agent work 50 times a day. Reviewing agent output, correcting it, approving it, reviewing again. The mental load of supervising agents is different from the mental load of doing the work yourself. Some founders are telling me they were less tired when they did everything manually because at least the cognitive pattern was consistent. 21. The cheapest form of market research: search "[your industry] spreadsheet template" on Google. Whatever people are tracking manually is your product. 22. Half the YC companies pivoted within 8 weeks of demo day. Not because they failed. Because agents let them test 5 ideas in the time it used to take to test one. The concept of "committing to an idea" is dissolving. Serial pivoting is becoming the default because 1) AI lets you move fast 2) the world is moving fast. 23. The loneliest job in tech right now is being the only person at your company who understands what the agents are doing. You can't explain it to your boss. You can't hand it off to a colleague. If you leave, everything breaks. You've become a single point of failure for an entire automated system. That person needs a title, a team, and a backup plan. Most companies haven't figured this out yet. 24. Your browser history is the most valuable training data you own and you're giving it away for free. Every site you visit, every product you research, every competitor you study, every pricing page you screenshot. That behavioral data, structured and fed to an agent, would make it understand your business better than any onboarding call. The company that lets you turn your browser history into agent context builds something nobody can replicate. 25. Everyone is building AI wrappers. Nobody is building AI unwrappers. The tool that takes an AI-generated document and tells you which parts a human wrote and which parts were generated. 26. Stripe just became the most important company in the agent economy and they barely had to do anything. Every agent that sells something needs Stripe. Every agent that buys something needs Stripe. They're the payment rail for the entire agentic internet by default. 27. The most undervalued API in the world right now is the US Postal Service address verification API. It's practically free. Every local business lead gen agent needs it. Every real estate agent needs it. Every direct mail agent needs it. Boring government infrastructure is quietly becoming the backbone of agent-native businesses. 28. The concept of "business hours" is for humans. Your agent closed a deal in Tokyo at 3am, processed the payment, sent the onboarding email, and updated the CRM before your alarm went off. 29. What happens when agents start recommending other agents? Your research agent finds that a competitor's sales agent is better and suggests you switch. Agent referral networks are forming organically. The first agent affiliate program is probably 6 months away. 30. Cal dotcom closed their source code. That's the canary. When open source companies start closing up, it means agents were cloning their product too easily. Every open source company is quietly asking the same question right now. 31. "AI for pet groomers" sounds like a joke and that's exactly why it will work. 150,000 of them in America. Zero tech. All scheduling by phone or IG DMs. The joke ideas always win. 32. The thing that will seem most obvious in hindsight: we spent 2025-2026 arguing about which model is best while the entire value was in the orchestration layer. The model is the CPU. Nobody buys a computer based on the CPU anymore. They buy it based on what they can do with it. Makes so much sense in hindsight. What else will be obvious in hindsight? I'll share more notes soon. I can't sleep with all that's going on. Maybe you too. What an incredible time to be building.
25