In a system where agents delegate to agents, the central risk is authority growing at each hop. Attenuable warrants make that impossible.
Orchestrator → researcher → summarizer → tool: every arrow is a delegation, and every delegation is a chance to over-grant. Instructing agents to "only do X" doesn't bind, because the model choosing the action can be manipulated. You need authority that is structurally incapable of growing.
Each agent passes a attenuated warrant to the next. The chain is verifiable end to end; a sub-agent can never exceed its delegator; and revoking the root collapses the whole tree at once. Combined with spend caps and audit, a sprawling crew stays bounded and accountable.
Free to self-host. 10,000 free decisions on the hosted gateway — no card.
Get an API key Read the docs