Action firewall for autonomous agents

Your AI can act.
You keep the keys.

Ummi connects cloud agents to private tools without inbound ports. Safe actions run. Risky actions pause and text you for approval. Every outcome is auditable.

Outbound-only tunnel Human approval gates Tamper-evident trail
ummi://control tunnel secure
LIVE REQUEST#8F2A
A
Atlasrequests prod_db.delete_records
targetproduction / sessionsimpact2,481 rowspolicyowner_approval
!Execution pausedWaiting for owner · SMS sent
LOCAL TOOLSOUTBOUND TUNNELUMMI POLICYYOUR AGENT
01 / SEE IT WORK

From risky request to
verified action in 90 seconds.

This is the whole loop—not a mock dashboard. Play it straight through, or jump to the text and make the decision yourself.

00:00/01:30
Ummi control plane

Agent requests a risky action

Live
A
AtlasOperations agent
High risk · 94
tool prod_db.delete_records
scope expired_sessions
count 2,481 rows
!
Production writes require approvalAction frozen before reaching the local tool.
Request received
Policy matched · action paused
Approval sent by SMS
One-time approval granted
Local tool returned success
Success audit sealed
9:415G  ▰
UUmmiverified
Today 9:41 AM
Atlas is requesting a high-risk action.Delete 2,481 expired sessions from production?One action · expires in 5 min
APPROVE 7K2
Approved once. I’ll text you when it’s done.
Protected by UmmiRisky actions will appear here.

No app to install. Approve from the lock screen, or deny and keep the tool offline.

02 / THE CONTROL LOOP

Autonomy, with a brake pedal.

01

Connect

A local bridge makes one outbound connection. Your database, files, and internal MCP tools stay behind your firewall.

No inbound ports
02

Decide

Policies allow routine work, block forbidden actions, and route high-impact requests to the right human.

Allow · deny · ask
03

Prove

Every terminal outcome gets a bounded, redacted audit record—from the original request to the local result.

One action, one record
03 / POLICY, NOT PROMPTS

Give agents room to work.
Draw the line in code.

The model can propose an action. Ummi owns whether it reaches the tool. Approval is scoped to the exact request—not a blank check for the next one.

ACTIONPOLICYOUTCOME
Read analyticsrisk < 30AUTO-RUN
Send refundamount > $100TEXT OWNER
Write productionprotected targetTEXT OWNER
Export credentialssecret-bearing dataALWAYS DENY
04 / BUILT FOR THE FIRST REAL USERS

Your agent left the chat box.
Its controls should too.

Ummi is for teams moving from impressive demos to agents that touch money, customer data, and production systems.

FOUNDER MODE

Ship the operator
without becoming it.

Let the agent handle routine operations and escalate the rare judgment calls to your phone.

AGENT TEAMS

One control layer
across every tool.

Separate cloud intelligence from private execution with consistent policy and audit boundaries.

PRIVATE INFRA

Reach local systems.
Keep them local.

Use outbound connectivity to reach MCP tools without publicly exposing the machine that runs them.

05 / PRICING

Start free.
Upgrade when you're ready.

No demos, no sales calls, no waiting. Sign up and connect an agent in minutes.

FREE$0

Try it out.

  • 1 seat
  • 1 agent connection
  • 100 actions / month
  • 7-day audit history
  • In-browser approval

EnterpriseContact us.

06 / STRAIGHT ANSWERS

How it works.

How do I connect my agent?+

Install the Ummi CLI on the machine where your agent or tools run. It creates an outbound-only tunnel — no inbound ports, no firewall changes. Your agent routes consequential actions through Ummi for approval.

Does Ummi expose my infrastructure?+

No. The connection is outbound-only. Ummi never opens an inbound port or listens on your network. Your credentials and data stay inside your environment.

Which actions require my approval?+

You decide. Configure policies per agent: auto-run safe reads, request approval for writes and refunds, auto-deny secret access. Approval is scoped to the exact action, not a blank check.

How does the free tier work?+

Create a free workspace and get 100 actions over 7 days — enough to connect an agent, set up policies, and run an end-to-end approval flow. No credit card required.

Can my team use it?+

Yes. The Developer plan supports up to 10 seats so your team can receive and respond to approval requests. Each member gets their own sign-in.

What happens when I don't respond to an approval?+

The action expires without executing. Every timeout is recorded in your audit trail — nothing happens by default.