Skip to content

Get started

What is Immiscible?

Short, plain answers: what Immiscible is, how it differs from AI gateways, observability tools and card controls, what it costs, whether you can run it yourself, and what it does not do.

#What is Immiscible?

An independent control layer for AI agents and AI spend. Before an agent pays, shares personal data, calls a tool or sends a model request, Immiscible decides against rules a person wrote: allow with a signed receipt, approval_required so a person decides, or deny. It can stop any agent at once, and every decision goes into a signed, hash-chained ledger you can verify offline. See decisions.

#Who is it for?

Teams that let AI agents act: pay invoices, buy things, write code, send email, fill in forms with personal data. Finance gets limits, approvals and spend by team; security gets the kill switch, identity and evidence; engineers get one HTTP call, an MCP server, SDKs and a model gateway.

#How is it different from an AI gateway?

A gateway routes and meters model requests. Immiscible includes one (OpenAI-shaped and Anthropic-shaped, with budgets checked before each call), but its centre is the decision about what an agent may do: payments, data releases and tool calls, with mandates, approvals by a person, receipts and a kill switch. A gateway alone sees prompts, not the payment the agent makes next. See compare.

#How is it different from LLM observability tools?

Observability records what happened so you can debug and evaluate it. Immiscible decides before it happens, and can refuse or hold it for a person. It keeps a record too, but as signed evidence for auditors and merchants, not as traces for evaluating answer quality.

#How is it different from corporate card controls?

Card controls limit a card: amounts, merchant categories, freezes. Immiscible decides per action, with the agent’s identity, its mandate, what influenced the request (an email, a web page) and a person’s approval, and covers data releases, tool calls, crypto and x402 as well as cards. With the card rail, the card issuer asks Immiscible before money moves, so the two work together.

#Do agent frameworks’ built-in guardrails not already do this?

They run inside one framework, configured by whoever built the agent. Immiscible sits outside every agent, so one set of rules, one kill switch and one record cover Claude, ChatGPT, your own agents and the rest, held by you rather than by any agent vendor. Its SDK integrations wrap framework tools so the two can be used together.

#Which agents and tools does it work with?

Anything that can make an HTTP request or speak MCP. Shipped integrations: a Claude Code hook, an MCP server and an MCP proxy (Claude, ChatGPT, Cursor and other MCP clients), SDKs for TypeScript and Python with adapters for the OpenAI Agents SDK, LangChain and the Vercel AI SDK, x402, card issuers, and no-code builders through OpenAPI. Muse is coming soon; Instinct publishes no API, so there is no Instinct connector. See agents without an API.

#How much does it cost?

We charge for the agents we govern, never for the people who approve, and never a share of spend or token volume. Watching (spend from bills, the agent inventory, shadow mode) is free and unlimited. Free is £0 with no card: 3 governed agents, up to 5 people, 100 approvals a month in Slack or Teams and 7 days of records. Team is £39 a month billed yearly (£49 paid monthly), about $53 and $66, with 10 governed agents, then £5 an agent a month up to 50. Business is £499 a month billed yearly (£599 paid monthly), about $675 and $810, with 100 governed agents, then £4 an agent a month up to 500, SCIM and ten years of records. Enterprise has no published price: it is for regulated firms and for running it in your own cloud, with ten years of records, a named engineer and your MSA and DPA; talk to us. People are free on every paid plan. Every new workspace starts with thirty days of Business, with no card, then moves to Free; nothing is deleted. We charge in pounds. The details, the startup programme and the Enterprise evaluation are on the pricing page.

#How do you count an agent?

A governed agent is anything with its own key, mandate, MCP connection or hook install that asked Immiscible for at least one decision in the month, with your rules enforced. Each person’s coding assistant (Claude Code, Cursor, Codex) is one agent. Five people who only send chat through the gateway count as one agent. An agent counts once more for every further 100,000 decisions it asks for in a month. Agents that asked for nothing, and anything only watched, are not counted. Billing shows the count for this month against your plan; it enforces nothing yet, and we tell you before anything changes. Immiscible never resells inference; model traffic runs on your own provider contracts.

#What happens if we go over a limit?

Nothing stops today. The governed-agent count is recorded and shown on Billing, and we tell you before anything changes. Going over Free’s 5 people starts seven days of grace and an email to the owner. Whatever the plan or the bill, an agent asking to pay, share or act is still decided: no billing state refuses or holds a decision.

#Can I run it myself?

Yes. It is one Node process with zero runtime dependencies and one SQLite file, shipped as a read-only Docker image, so it runs in your own VPC. Self-hosting is offered on the Enterprise plan; the server’s source code is not public (the SDKs and the CLI are, under MIT, at efr7-7/immiscible-sdks). Hosted plans run in the EU (Frankfurt). See deploy and backups.

#Can an agent just skip it?

If the only integration is the agent calling the API, yes: asking is then the agent’s choice. That is why the docs lead with paths an agent cannot route around: the MCP proxy holds the tool’s credential, the Claude Code hook is run by Claude Code rather than the model, and the card rail makes the issuer ask before money moves. See ways in.

#What does it not do?

  • It does not host, resell or fine-tune models.
  • It does not score answer quality or run evaluations.
  • It does not hold funds or wallet keys, or sign transactions; the card issuer, wallet or x402 client moves the money after an allow.
  • It cannot enforce on inference that runs in a vendor’s own backend (Devin, GitHub Copilot, Cursor’s hosted models); that usage is reconciled from the vendor’s API and marked as not governed.
  • It has no hosted region outside the EU yet: the hosted service runs in Frankfurt, and a US region is not live.

#Where do I start?

The quickstart gets a first decision in five minutes; for AI agents is the same in one page for an agent or the person wiring one up.