A checkpoint between AI agents and production

Your agents can't delete prod anymore.

Quell is a proxy between your AI agents and production. Every query and cloud call is classified, then allowed, held for one-click approval in Slack, or blocked.

For teams running Cursor, Claude Code, and their own agents against real infrastructure.
#ops-approvals3 members
Nothing waiting.
01The problem

April 2026. A coding agent found an API token with more access than anyone realized, and made one call.

The production database was gone. So were the backups.

It took nine seconds.

Reported widely, e.g. OECD AI incident 2026-04-27
0.0s
prod-db
9 objects
public.users48,211
public.orders1,204,557
public.invoices311,090
public.payments298,402
public.sessions92,118
public.audit_log3,880,204
backup daily-04-26snapshot
backup daily-04-25snapshot
backup weekly-04-20snapshot
idle
With QuellThat call is classified destructive, held, and sent to a human. Elapsed: 0.0s.
02How it works

One checkpoint for every action.

  1. 01

    Agent sends an action

    Point the agent at Quell instead of your database or cloud. Same SQL, same API calls. It never holds a real credential.

  2. 02

    Quell classifies it

    Each request is parsed and tagged read, write, or destructive, with the target environment and blast radius attached.

  3. 03

    Allow, hold, or block

    Your policy decides. Reads pass through. Destructive actions on prod wait for a human. Some things never run.

AgentQuellOutcome
cursor · prodSELECT id, email FROM users LIMIT 50
claude-code · prodDELETE FROM orders WHERE status = 'test'
ops-agent · prodDROP DATABASE acme_prod
RWD
read · 50 rows
RWD
destructive · ~1.2k rows
RWD
destructive · whole db
ALLOW200 · 50 rows · 4ms
HOLD→ #ops-approvals
BLOCKnever-drop-databases
3 requests in flight · no credentials attachedstep 1 / 3
03What you get

Three things, done properly.

Approvals in Slack

Held actions land in a channel with the exact statement, the target, and the blast radius. One click to approve or deny. Nobody answers, nothing runs.

Credential vault

Agents get a short-lived Quell token. Real keys stay with Quell, which attaches them on the way out. A leaked agent token can't be used to go around the checkpoint.

Undo for destructive actions

When a destructive action is allowed, Quell snapshots what it touches first. If it was a mistake, one command puts the rows back.

04Policies

Rules you can read in a code review.

Policy is a YAML file. Rules match top to bottom. The first match decides.

  • →Reads pass through with no added steps.
  • →Destructive actions on prod are held for a named channel.
  • →No answer before the timeout means no.
quell.yaml
README.md
acme-api / .quell / quell.yaml
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
version: 1 environments: prod: { match: "env:prod" } rules: - name: reads-pass-through when: { class: read } action: allow - name: hold-destructive-in-prod when: { class: destructive, env: prod } action: hold approvers: ["#ops-approvals"] timeout: 15m # no answer = deny - name: never-drop-databases when: { statement: "DROP DATABASE *" } action: block - name: default action: allow undo: snapshot
valid4 rulesYAML · UTF-8 · Ln 21
05Design partners

We're working with 5 design partners.

That's how many teams we can support properly while we build, not a countdown. If your agents already touch production, we'd like to hear how.

You get

  • Quell running against your stack
  • A direct line to the people building it
  • Your edge cases on the roadmap

We ask for

  • A 30-minute call every two weeks
  • Blunt feedback
  • A real workload to test against
What agents do you run
Rather talk first? Book a 30-minute call.