Security
Control is part of the product
Nerve does not hand an AI model unrestricted access. Actions are governed through capabilities, identities, permissions, approvals and an audit trail, and tenants are sealed off from each other by design.
Every action is checked, in order
Connecting an application never means every Agent can use it. NerveTools asks six questions before anything runs.
- 1
Who is acting
Every action runs as an identity: a person, or a service account with its own limits.
- 2
What it may do
The capability must be granted explicitly, to this Agent, for this workspace.
- 3
Which connection
The connection must be connected, healthy and allowed for that capability.
- 4
How risky it is
Nerve classifies each action. Consequential ones wait for a person.
- 5
Is it still allowed
Authority is checked at the moment of the action, not when it was set up.
- 6
What happened
The result and the decision are written to an append-only record.
What it means in practice
- 01Least privilege
- An Agent starts with nothing. It gets only the capabilities you give it, for only the applications you connect.
- 02Explicit capabilities
- What an Agent can do is a named list you can read: look up a calendar, send an email, update a record.
- 03Execution identities
- Work runs as an identity with its own limits, not as an all-powerful account.
- 04Approvals
- Consequential actions pause for a person, with what will happen, why and who asked.
- 05Current authority
- Permissions are checked when an action runs, not when it was set up. Remove access and it stops.
- 06Auditability
- Approvals, changes and actions are recorded in an append-only trail you can review.
- 07MCP review
- New MCP tools are reviewed before any Agent can use them, and a changed tool needs review again.
- 08Controlled integrations
- Only reviewed integrations are offered, and each connection stays inside the boundary you set.
What we claim, and what we don't
Nerve is self-hosted, so how it runs depends on the infrastructure you run it on. Approvals reduce risk; they do not make autonomous work always safe, and no AI model is free of mistakes.
We do not claim certifications or compliance that Nerve does not hold. If you need an architecture and security review for your organization, we will do it with you.
Deploy your first Nerve Agent
Start with one conversation your team handles every day. Give the Agent what it needs to know, connect the tools it should use, and decide where a person steps in.