Wrong place
Agent emails the wrong person or posts in the wrong channel. Instant reputation damage.
Candlelit prevents agent “oops moments” — wrong recipients, bad permissions, prompt injection side effects — and creates receipts for every action so you can ship with confidence.
The problem
Your agent can plan, reason, and write. But the minute it needs to send an email, post a message, or update a record — you're one bad prompt away from disaster.
Agent emails the wrong person or posts in the wrong channel. Instant reputation damage.
Agent has more access than it needs. One prompt injection away from a security incident.
Agent reads a doc with hidden instructions and does exactly what the attacker wanted.
How it works
Your agent proposes a side effect — send email, post message, create ticket. Candlelit intercepts it.
Review and approve with one click — or let a policy auto-approve safe patterns. Convert any approval into a reusable rule.
The action runs securely. Your agent never sees credentials. Every execution gets a tamper-evident receipt.
Use cases
Let your support agent send email replies — only to existing threads, only to known contacts.
Post Slack updates during incidents — with channel restrictions and sensitive-channel approvals.
Draft outreach emails and approve them before they go out. Build a policy as you go.
Let copilots post updates safely — rate-limited, channel-scoped, and always receipted.
Why Candlelit
Agents never see secrets. Candlelit executes actions on their behalf using isolated OAuth tokens.
Turn any approval into a reusable policy with guardrails. Ramp autonomy at your pace.
Action-level constraints, domain allowlists, channel restrictions, and rate limits — all built in.
Every action gets a receipt: payload, approver, timestamp, and policy version.
Works with any agent stack via a simple API. OpenAI, LangGraph, or your custom agent.
Run a Safety Check in 60 seconds. No signup required.
Email only to export. You'll get a Safety Pack you can forward to your cofounder.