Any agent.
Any model.
Your rules.

The neutral control layer for teams of people and AI agents. Every action is checked against your rules, the right person decides, and everything is recorded.

  • For Claude, OpenAI, Gemini and Grok
  • For teams who sign off on agent work
  • For a record you can show an auditor
The problem

Agents are fast.
Mistakes are faster.

It might do something I can't undo.

Delete files, push to main, deploy, change a database.

Preflight: deletes, pushes and deploys stop and ask. The agent can't push your code at all.

It might leak a secret.

Read a .env file, send keys somewhere they shouldn't go.

Preflight: secret files are unreadable where the agent runs, and your keys never reach it.

I can't tell what it actually did.

No record of what ran, why, and who allowed it.

Preflight: every plan, action, decision and result is kept, and nobody can edit the record.

How it works

Agree on the plan
before anything runs.

Fix checkout rounding · always-on agent · branch preflight/fix-482Waiting for work
Record0
  1. Nothing yet. Nothing runs before the plan is approved.

Each action the agent asks for is checked here before it runs.

An example flow. A GitHub issue about a checkout total that is off by a cent is picked up by the Bug fixer, an always-on agent. It proposes 7 steps, two of them in parallel, and two other models review the plan as advice. The tech lead adds a limit, never change src/billing/, and approves. Every action passes 7 checks in a fixed order: reading Sentry and the code is allowed, an edit to the billing code is blocked by the limit, reading .env.production is blocked as a secret file, and the tests fail once, are fixed and pass. A team rule holds the production deploy until the CTO approves, and another holds the email to 312 customers until the Support lead approves. Every event is kept in the record.

Inside the approved plan the agent works alone. Outside it, it stops and asks.

  • Canvas or text plans
  • Every version kept
  • Supervised, Balanced, Autonomous
  • Always ask before
  • Its own branch
Rules, not guesses

Your rules, checked by code.
Every time.

Team rules · Production deploys need the CTO · v3

When an agent wants to deploy
only if environment is production
in all projects then require the CTO

Try it: what the agent asks for
Result
Held for the CTO

The rule matches: the command itself says production. The flow waits, and only the CTO is told.

action
deploy
environment
production
source
the --prod flag
rule
v3 · require CTO

No AI decides whether a rule applies. Unknown values never pass.

Rules can check

  • Files and commands
  • Services and their tools
  • Amounts and currencies
  • Customers and vendors
  • Environments
  • Time windows
People and agents, one team

The right person decides.
Only they are told.

Approvals go to the job role that signs off. Silence never approves anything.

Features

  • 1 to 3 job roles per rule
  • One inbox for every flow
  • Email, Slack, Discord, ntfy
  • Reminders on team hours
  • Always-on agents
The record

Every action, who approved it, and why.
Nobody can edit it.

If an action can't be recorded, it doesn't run.

Designed so that

  • The record is append-only
  • Each team has its own key
  • Content is never used for training
  • Every rule version is kept
Built in

Safe by default.
Open where you choose.

Network off by default

The sandbox has no internet. A command a person approved opens it, only to allowed sites, and it closes after.

$ npm install @radix-ui/colors ‖ waiting network needed · asking the tech lead ✓ approved open to registry.npmjs.org for this command ✓ done network closed

Secrets stay out of reach

.env and key files are unreadable where the agent runs. Keys and tokens never reach the agent.

read_file .env ✕ blocked secret file

Works on your GitHub repos

Each flow gets its own worktree and branch. The agent can read Git but can't commit or push. People do.

preflight/add-dark-modepreflight/fix-checkout

Use the models you already pay for

API keys for Claude, OpenAI, Gemini or Grok, or your Claude Code, Codex, Gemini CLI or Grok Build plan.

ClaudeOpenAIGeminiGrok

Choose where work runs

Docker on your computer or Vercel Sandbox in the cloud, chosen per team.

DockerVercel Sandbox

Cost under control

Each flow knows what it spent. Budgets per flow, per day and per team.

A second opinion

Up to 3 models from different makers review a plan before you approve it. They advise; you decide.

See the real app

Preview, code editor and terminal on the same files the agent works on.

Neutral

Sandboxes decide where an agent runs. Preflight decides what it may do.

CapabilityAgent aloneApprovals in one AI toolA sandbox providerPreflight
Works across models and tools—One toolYesYes
Team rules with business values—Limited—Yes
Approval by job role———Yes
Permanent record—PartialLogsYes
Isolated place to run—VariesYesUses one
Questions

What people ask first.

Is Preflight an AI agent?

No. It controls agents. The agent can think with Claude, OpenAI, Gemini or Grok. Preflight decides what it may do.

Do I have to approve everything?

No. Inside the approved plan the agent works alone. You choose how much it decides by itself, and only risky or unexpected actions ask.

Does an AI decide whether my rules apply?

No. Rules are checked by plain code, the same way every time.

Can the agent push to my main branch?

No. Git is read-only for the agent. People commit, in Preflight or in their own tools.

Can it read my secrets?

Secret files like .env are unreadable where the agent runs, and your keys never reach it. Keep production keys out of project folders, since a script the agent writes could use credentials stored there.

Where does the agent's code run?

In an isolated sandbox: Docker on your computer, or Vercel Sandbox in the cloud. Your team chooses.

Which models can I use?

Your own API keys for Claude, OpenAI, Gemini or Grok, or the subscriptions you already have: Claude Code, Codex, Gemini CLI or Grok Build.

Is my code used for training?

No. Your team's content is used only to run the service, and it's encrypted with your team's own key.

Can I see what happened afterwards?

Yes. Every plan, action, decision and result is kept, and the record can't be edited.

Agents propose.
People approve.

We're opening Preflight to a small number of software teams first. Leave your work email and we'll write when there's a place for you.