Approvals in Slack
Held actions land in a channel with the exact statement, the target, and the blast radius. One click to approve or deny. Nobody answers, nothing runs.
Quell is a proxy between your AI agents and production. Every query and cloud call is classified, then allowed, held for one-click approval in Slack, or blocked.
April 2026. A coding agent found an API token with more access than anyone realized, and made one call.
The production database was gone. So were the backups.
It took nine seconds.
Point the agent at Quell instead of your database or cloud. Same SQL, same API calls. It never holds a real credential.
Each request is parsed and tagged read, write, or destructive, with the target environment and blast radius attached.
Your policy decides. Reads pass through. Destructive actions on prod wait for a human. Some things never run.
SELECT id, email FROM users LIMIT 50DELETE FROM orders WHERE status = 'test'DROP DATABASE acme_prodHeld actions land in a channel with the exact statement, the target, and the blast radius. One click to approve or deny. Nobody answers, nothing runs.
Agents get a short-lived Quell token. Real keys stay with Quell, which attaches them on the way out. A leaked agent token can't be used to go around the checkpoint.
When a destructive action is allowed, Quell snapshots what it touches first. If it was a mistake, one command puts the rows back.
Policy is a YAML file. Rules match top to bottom. The first match decides.
That's how many teams we can support properly while we build, not a countdown. If your agents already touch production, we'd like to hear how.