Authorize
checks the calling agent against the ceilings a named human set and has a risk classifier score the action, then refuses or escalates to a person above either ceiling.
The agent worked. Procurement is what killed the pilot. Nobody in the room disputed the first part: it read the tracker, drafted the standup and opened the pull request for six weeks.
Then someone asked what it would cost at forty people, and which region the content is processed in. Six weeks of evidence lost to two questions with no written answer.
A model risk-scores every action and a rate card prices it before it runs. A log line records it after.
€0.004
per executed action, on a rate card published on this page
EU only
executed and risk-scored in Sweden, never copied out
10,000 actions
free, no card, metered and logged like paid ones
Compare
| Question a buyer asks | Ferrule | CORE |
|---|---|---|
| What does it cost at 40 people | ✓€0.004 per action, published, arithmetic anyone can do | ✕Fees are usage, storage and tier; no figure is published |
| Which region processes content | ✓EU only: AWS Stockholm, Azure Sweden Central | ✕AWS, no region named |
| Which model providers see it | ✓Azure OpenAI in Sweden Central, zero retention, to score risk | ✕OpenAI, Anthropic or Google Gemini when AI features are used |
| Is there a no-training commitment | ✓Yes, over everything, with no corpus exception | ✕Written for Google user data only |
| Does it remember your work | ✓Yes. We keep caching for you. | ✓A temporal knowledge graph over six vector namespaces |
| Can it plan and act on its own | ✓Yes. You decide. We execute. | ✓Tasks draft a plan, wait for approval, then run |
| How many apps out of the box | ✓We integrate new MCPs with a user request. | ✓50+ through one MCP endpoint |
Scope
Pricing
The rate card is the whole rate card. It is on this page because a page without one is why you are here.
€0.004
per action
Why it works this way
A published per-action rate is easy to undercut and easy to dismiss. It tells a large buyer exactly how much room they have before the first call, and we lose room we would otherwise have had.
We publish it anyway, because the alternative is the thing that killed your pilot. An unpriced platform cannot enter a procurement process; it can only enter a sales conversation, and those take a quarter.
The cost is real and it lands on us. Some deals we would have won on a negotiated quote we now lose on arithmetic. A buyer who wants to feel negotiated with does not enjoy this page.
The same rule runs through the region. The terms name both: AWS in Stockholm for execution and the log, Azure in Sweden Central for the two models. Moving processing outside the EU is not an option we kept.
Features
Not a platform. Four verbs.
Each of the four produces a record you can export. That is the whole product surface, and the reason the rate card fits in one line.
checks the calling agent against the ceilings a named human set and has a risk classifier score the action, then refuses or escalates to a person above either ceiling.
quotes the action against the public rate card before it executes, so an agent can be told what it is about to spend.
performs the call in your connected tool using the grant you gave, and reports what the third party actually returned.
writes the call, its risk score, its price, its authorizer, its result and a trace id, retained 400 days, with anomaly detection flagging what an agent has never done before.
The AI layer
A risk classifier inside Authorize, and anomaly detection over the Log.
A routine action and a harmful one often call the same endpoint with the same shape of parameters. The difference is in what the parameters say, which is the part a rule cannot read and a model can.
Risk classifier - before an action is priced, a model reads the tool, the operation and the parameters, and scores risk and intent. Over your risk ceiling it refuses or escalates.
Anomaly detection - a baseline per agent from its own 400-day log, flagging a tool it never called, a volume it never reached or a refusal rate that climbs.
Refuse or escalate, never approve - neither model can raise a ceiling, choose a tool or call one. A fooled model can only let through what your ceiling already allowed.
Where it runs - in Sweden. The models on Azure OpenAI, with nothing retained, and Azure Machine Learning; the gateway and its log on AWS in Stockholm.