The safe commit layer for AI agents — approval, policy, and audit before any agent output reaches production