Parmana

Authorization for AI agents

Your rules. Your control.

Parmana sits outside your business systems. It checks every request your AI makes against your rules, and gives you a signed receipt for every decision.

AI asks. Parmana checks. Only what you allowed goes through.

Request from refund agent

paytm:refund
Order
ORD-1042
Amount
₹15,000
Manager approval
signed

Allowed by your rules

customer-refund 1.2.0, approved through maker checker

  • Caller authenticated
  • Rule: refunds need a signed manager approval
  • Approval matches this order and amount
  • Single use authorization issued

Signed record

{
  "decision": "APPROVED",
  "policy": "customer-refund@1.2.0",
  "signature": { "algorithm": "ed25519" },
  "verify": "offline, with your public key"
}

AI asks. Parmana checks. Only what you allowed goes through.

Signatures
Ed25519, with optional ML-DSA-65
Human approval
Signed by your approver, used once
Policy changes
One person proposes, another approves
Verification
Offline, with your public keys

How it works

A checkpoint between your agents and your systems.

Parmana sits outside the systems you already run. Requests that go through it reach those systems only when your rules allow them. Nothing you run today has to change.

  1. 01

    A request comes in

    An agent, an app or a person requests an action, such as a refund, a merge or a message. The request names the action, the target and the details.

  2. 02

    Parmana checks it

    The request is checked against your rules, and against a signed approval when your rules need one. If anything fails, nothing is signed and nothing runs.

  3. 03

    Only what you allowed runs

    An allowed request gets a signed, single use authorization. The gateway checks it again before the action reaches your system.

  4. 04

    You keep the proof

    Every decision leaves a signed record. Anyone with your public keys can check it later, without Parmana.

Example

Your rule: refunds over ₹10,000 need a manager's signed approval.

A refund agent sends three requests. Pick one to see what Parmana does with it. Saying "approved" is not enough; the approval has to be signed by someone you trust.

Refund request

ORD-1042
Requested by
Refund agent
Amount
₹15,000
Manager approval
Missing

Stopped

Over your limit with no signed manager approval. Stopped before it reaches your payment processor.

Outcomes

Your policies don't change. Agents prove they follow them.

1

Deploy safely

Put agents on real work. Every request that goes through Parmana is checked against your limits before it runs.

2

Prove compliance

A signed record of every decision, allowed or stopped, ready when an auditor or a customer asks.

3

Protect systems

Requests that go through Parmana reach your systems only when your rules allow them. Agents never hold the credentials to your systems.

Same rules, any system

Paytm

Refunds within your limits, with a signed approval when needed.

HubSpot

Deal stage and amount updates, checked against the real deal.

GitHub

Pull request merges, only for the pull request that was approved.

Slack

Messages, only to the channel that was approved.

Your API

Any HTTPS endpoint, registered without a deploy and released with a signature.

Developers

One call between your agent and your system.

TypeScript and Python SDKs, a REST API, and connector SDKs for your own systems. Run it yourself, including on a network with no route to the internet.

refund-agent.ts
import { ParmanaClient, createBusinessTransaction } from "@parmana/sdk";

const parmana = new ParmanaClient({
  endpoint: process.env.PARMANA_ENDPOINT,
  apiKey: process.env.PARMANA_API_KEY,
});

// Allowed requests run once and return a signed record.
// Anything your rules refuse is stopped and nothing runs.
const record = await parmana.execute(
  createBusinessTransaction({
    principalId: "refund-agent",
    purpose: "Customer refund",
    action: "paytm:refund",
    target: "order/ORD-1042",
    parameters: { orderId: "ORD-1042", amount: 15000 },
    policy: { name: "customer-refund", version: "1.2.0", schemaVersion: "1.0.0" },
    signals: { managerApproved: true, approvalArtifact },
  }),
);

Trust

Built to be checked, not taken on trust.

Every claim is tied to the code and tests that back it. Evaluators get a guide that names where requests are stopped and what an attacker controls in each case.

Checked at more than one point

The caller, the decision, the signed authorization and the release to your system are each checked. A refused request never gets an authorization.

People decide, twice

A policy takes effect only after one person proposes it and a different person approves it with their own signature.

Proof anyone can check

Records are signed with Ed25519, and optionally ML-DSA-65 as well. They verify offline with the open source @parmana/sign.

Honest about limits

Parmana protects what goes through it, while its signing keys are safe. We publish what we do not claim, alongside every claim we do.

Start with one workflow.

You set the rules. Parmana checks every request before it runs. You get proof.