The command or the edit never runs until Mergen says so.
Mergen decides, deterministically, whether an agent's action runs, before it does.
I'll clean up the infrastructure.
$ terraform destroy -auto-approveThe handler was never called.
Simulated for illustration; a real decision returns faster.
Permission to use a tool isn't permission to perform every action through it.
An agent legitimately needs git, shell, cloud tooling, Kubernetes, Terraform, and once it can use them, nothing stops it from reaching production, credentials, and infrastructure through them. Detection after the fact is too late.
terraform destroyDROP DATABASErm -rf /hardcode a secret in a commitremove an auth checkMergen stops them before execution.
1 gate. 3 decisions.
A tool call needs an answer before the handler runs. Mergen answers it, locally and deterministically.
Execute normally
Safe work continues without interruption.
Ask a human
The action waits for approval, in Slack or the terminal.
Never execute
The handler never runs. The agent gets a reason and a safer path.
Your agent keeps working. Mergen intervenes only when an action crosses a policy boundary: no LLM in the critical path.
Your team shouldn't answer the same question twice.
Mergen records approvals, overrides, and the reasons behind them, and surfaces relevant past decisions when a similar action comes up for review.
Mergen doesn't auto-approve. It remembers.
See how decision memory works →“Approved for the staging migration after the backup completed.”
Enforcement happens where the action happens.
The agent asks to execute. Mergen evaluates locally: no cloud round-trip, no LLM in the loop, no dependency on being online. The action proceeds, waits for a human, or never reaches the handler.
From one developer to your entire fleet.
Same enforcement. More coordination as you scale.
- 01Machine
Local enforcement for commands and edits.
- 02Team
Shared policy, approvals, and decision memory.
- 03Organization
Fleet governance, RBAC, and auditability.

Protection that grows with your team
Mergen stops dangerous actions before they run: free, forever, no payment required. Sign in with an account.
- Deterministic enforcement
- Blocks destructive actions before execution
- Full local activity history
- Local policy controls
- +2 more
Sign in required · No payment required
Bring Mergen to your team. Share policies, approvals, agent activity, and operational context across developers and machines.
- Up to 10 developers
- Organization Memory
- Shared organization policies
- Slack approvals & escalation
- +6 more
Sign in required · Card required for trial · Cancel anytime
Govern AI-agent execution across your engineering organization. Control who can approve actions, where policies apply, and how execution decisions are reviewed and audited.
- Up to 25 developers
- Organization-wide policy governance
- Role-based approval routing
- Quorum & multi-approver rules
- +7 more
Sign in required · Card required for trial · Cancel anytime
Common questions
What comes up before anyone runs npx mergen-server, and before starting a trial.
Let your agents move fast.
Put a gate in front of the dangerous stuff.
Start locally in under two minutes. Connect your team when you need shared policy, approvals, and visibility.