Shield Agent AI
Pricing

How much agent activity do you govern?

A governed event is one tool call your agents make that Shield allows, reviews, or denies — recorded on your trail. A governed agent is an AI agent you register with Shield — one Claude Code, Cursor, or custom bot acting on your systems. Events are metered, never dropped. Console seats are humans who sign in.

Free

100k

governed events / month

$0

See it · 5 agents · 2 seats · 30-day trail visibility

Full console, policy, approvals, trail API

Start free

Starter

500k

governed events / month

$29 / month

Run it · 25 agents · 5 seats · 30-day trail visibility

One team's agents in production

Get started

Pro

5M

governed events / month

$149 / month

Prove it · 250 agents · 25 seats · 90-day trail visibility

Signed evidence bundles · claim verify API

Get started

Scale

custom

governed events / month

$499 / month

Prove it org-wide · unlimited agents + seats · 365-day trail

SSO / SCIM · Gatekeeper included · Scale support

Get started

Plan details

Feature Free · $0 Starter · $29/mo Pro · $149/mo Scale · $499/mo
Usage & limits
Governed events per month
One tool call your agents make that Shield allows, reviews, or denies — recorded on your trail. Metered, never dropped: at the quota you get a warning — what happens past it is in the Overage row below.
100,000 500,000 5,000,000 Custom
Overage
What happens past the monthly event quota. Events are never dropped.
Upgrade for more Metered, billed monthly — events never dropped Metered, billed monthly — events never dropped Custom
Governed agents
An AI agent you register with Shield — one Claude Code, Cursor, or custom bot acting on your systems. Distinct identities (ACTIVE or SUSPENDED) at one time. Kill or revoke frees a slot.
5 at a time 25 at a time 250 at a time Unlimited
Console seats
Humans who sign in to approve and operate. Not company headcount. Revoking an invite or removing a member frees a seat.
2 5 25 Unlimited
Trail visibility
How far back you can read the trail — dashboard windows, trail API, session trails. Visibility only: nothing is ever deleted, and upgrading shows further back immediately.
30 days 30 days 90 days 365 days (custom on request)
Identity & registry
Agent registry (register, list, status) Yes Yes Yes Yes
Agent passport (HTML + JSON download) Yes Yes Yes Yes
Policy-gated spawn (agent creates agent) Yes Yes Yes Yes
Human mint mode (allow / break-glass / approve) Yes Yes Yes Yes
Session clearance (Read / Build / Deploy) Yes Yes Yes Yes
HIGH-risk shrink mode (operator / auto / approve) Yes Yes Yes Yes
Signed agent passport + session claim Yes Yes Yes Yes
Verify claim API No No Yes Yes
Orphan / parent-tree report No No Yes Yes
Version hash on register (prompt + tools + policy) Yes Yes Yes Yes
Kill / revoke agent Yes Yes Yes Yes
Policy & human approval
Runtime policy: ALLOW / DENY / REQUIRE_APPROVE Yes Yes Yes Yes
Fail-closed defaults (missing approval → deny) Yes Yes Yes Yes
Policy playground (console evaluate) Yes Yes Yes Yes
Policy evaluate API (MCP / OpenAPI / HTTP) Yes Yes Yes Yes
Approvals queue (approve / reject) Yes Yes Yes Yes
PII redaction before model calls Yes Yes Yes Yes
Observe, evidence & trail
Session ingest + session list Yes Yes Yes Yes
Session timeline (tools, risk, raw payload) Yes Yes Yes Yes
Session risk only raises severity (never auto-allows) Yes Yes Yes Yes
Evidence & cases Yes Yes Yes Yes
Hash-chained event / audit trail Yes Yes Yes Yes
Shield Verified badge endpoints
Public SVG / JSON on every plan — anyone can check a badge.
Yes Yes Yes Yes
Case export (JSON) Yes Yes Yes Yes
Evidence graph dual-write (audit module) Yes Yes Yes Yes
KYA metrics (console) Yes Yes Yes Yes
KYA metrics JSON API Yes Yes Yes Yes
Edge & complements
Edge status page (Gatekeeper complement flags) Yes Yes Yes Yes
Shield Agent Gatekeeper (edge after Shield approves) No No Optional Included / assisted
Connectors & install
Marketplace install (Claude, ChatGPT, Grok, Gemini, AWS, Azure, GCP) Yes Yes Yes Yes
MCP connector surface Yes Yes Yes Yes
OpenAPI / GPT Actions surface Yes Yes Yes Yes
Install agents hub in console Yes Yes Yes Yes
Console, tenant & access
Hosted operator console (dashboard + all KYA pages) Yes Yes Yes Yes
Tutorial mode + welcome tour Yes Yes Yes Yes
Tenant isolation Yes Yes Yes Yes
Roles: OWNER / ADMIN / OPERATOR / READ_ONLY
OWNER manages SSO. OPERATOR can approve Holds; READ_ONLY cannot.
Yes Yes Yes Yes
API keys (machine access) Yes Yes Yes Yes
SSO / SAML / OIDC login
One IdP per workspace. Operators only — agents keep API keys.
No No No Yes
SCIM 2.0 user & group sync No No No Yes
IdP group → role maps (group RBAC) No No No Yes
Profile, security, billing settings Yes Yes Yes Yes
Support & onboarding
Email support Community (docs + GitHub) Standard Priority Priority
Slack or dedicated channel No No No Yes
Severity response targets
Product policy for first response — not credits or indemnity. See Scale support.
No No No Yes · Sev-1–4
Guided setup / onboarding help No No No Yes
Local free for development (self-host, see repo docs) Included for every plan. No seat charge on local-only runs

Prefer to try first? Create a free console account or sign in. Local development stays free (see repo docs). Marketplace install is on every plan. Install hub.

How KYA works · Scale support · Product home · Console