“You, in the loop”is a guarantee, not a slogan.
Supasprinkles takes real actions across your business, so the question that matters isn't which badges we hold. It's what the agents can do, and whether you can see and stop them. Every mechanism on this page is the answer.
What can each agent actually do?
Every agent runs under strict, revocable scopes. You decide how far each one can go, and you can see exactly what it's allowed to touch.
Scoped permissions per agent
Each agent only touches the tools and data you grant it.
Read-only vs action-enabled
Decide whether an agent observes, or observes and acts.
Human-in-the-loop approvals
Anything irreversible waits for your sign-off.
Rate-limited system actions
Hard ceilings on what agents can do in any window.
Continuous behaviour monitoring
Every agent is watched for drift from its scope.
Some things agents can never do.
Regardless of configuration, autonomy level, or who asks. These aren't settings, they're hard limits built into the platform.
Slam the brakes. Undo anything.
The most important control isn't what an agent can do; it's that you can stop it instantly, and take any action back.
One-click pause
Freeze a single agent, a whole team, or every agent at once.
Roll back any action
Every change is reversible and restores the prior state.
Auto-pause on incidents
Conditional and scheduled pauses for risky windows.
Nothing irreversible without you
Destructive or costly actions always wait for approval.
Every action is fully traceable.
User, agent, workflow, integration and permission events, all captured, all explained in plain language.
Complete forensic visibility for security, compliance and governance.
We never train on your data.
Not our models. Not anyone else's. Your operational data is used to run your operation, nothing more.
Never used for training
Your data never trains our models, or anyone else's.
UK & EU residency
Stored and processed in UK/EU regions, under UK GDPR.
Always yours
Export or erase your data at any time.
Security by design, not by afterthought.
A security-first, zero-trust architecture: isolated, encrypted, and scoped to exactly what you allow.
Multi-tenant isolation
- No cross-tenant data visibility
- Enforced at the database policy level
- Encryption boundaries per tenant
- Dedicated audit streams per organisation
Encryption everywhere
- AES-256 encryption at rest
- TLS 1.2+ encryption in transit
- Encrypted secrets management
- Secure API token storage
- Automatic key rotation
You choose the access level
- Read-only access
- Event-based triggers
- Full automation permissions
- Revocable at any time
Enterprise identity, built in.
- Role-based access control (RBAC)
- Fine-grained permissions, feature and data level
- Multi-tenant access isolation
- Multi-factor authentication (MFA)
- Session management & device trust
Only the right people can see or change the right things, always.
Built for regulated environments.
We badge status honestly. The control mechanisms above carry the weight.
Resilient operations, even at scale.
Run autonomous operations
securely.
The power of AI automation, with the controls your security team demands, and the brakes you can hit any time.