The command or the edit never runs until Mergen says so.

Mergen decides, deterministically, whether an agent's action runs, before it does.

AGENT

I'll clean up the infrastructure.

$ terraform destroy -auto-approve
MERGEN
BLOCK0.62ms
Destructive infrastructure operation
Policy: production-destroy

The handler was never called.

$

Simulated for illustration; a real decision returns faster.

Permission to use a tool isn't permission to perform every action through it.

An agent legitimately needs git, shell, cloud tooling, Kubernetes, Terraform, and once it can use them, nothing stops it from reaching production, credentials, and infrastructure through them. Detection after the fact is too late.

terraform destroyDROP DATABASErm -rf /hardcode a secret in a commitremove an auth check

Mergen stops them before execution.

1 gate. 3 decisions.

A tool call needs an answer before the handler runs. Mergen answers it, locally and deterministically.

PASS

Execute normally

Safe work continues without interruption.

HOLD

Ask a human

The action waits for approval, in Slack or the terminal.

BLOCK

Never execute

The handler never runs. The agent gets a reason and a safer path.

Your agent keeps working. Mergen intervenes only when an action crosses a policy boundary: no LLM in the critical path.

Your team shouldn't answer the same question twice.

Mergen records approvals, overrides, and the reasons behind them, and surfaces relevant past decisions when a similar action comes up for review.

Mergen doesn't auto-approve. It remembers.

See how decision memory works →
PREVIOUS DECISION
“Approved for the staging migration after the backup completed.”
Sarah · Tuesday · migration policy

Enforcement happens where the action happens.

The agent asks to execute. Mergen evaluates locally: no cloud round-trip, no LLM in the loop, no dependency on being online. The action proceeds, waits for a human, or never reaches the handler.

Local enforcementPolicy stays in the execution path, even offline.
Your code stays localFree needs an account, not payment — binds to your machine.
Optional coordinationPaid plans sync policy, approvals, and fleet visibility.

From one developer to your entire fleet.

Same enforcement. More coordination as you scale.

  1. 01
    Machine

    Local enforcement for commands and edits.

  2. 02
    Team

    Shared policy, approvals, and decision memory.

  3. 03
    Organization

    Fleet governance, RBAC, and auditability.

See how it scales →
Mergen
Mergen VS Code extension sidebar showing runtime connected, 73 actions allowed
Mergen companion panel in VS Code
Claude CodeCursorVS CodeSlackPagerDutyDatadogGitHub Actions

Protection that grows with your team

Free
$0/forever

Mergen stops dangerous actions before they run: free, forever, no payment required. Sign in with an account.

Included
  • Deterministic enforcement
  • Blocks destructive actions before execution
  • Full local activity history
  • Local policy controls
  • +2 more
Usage: 10,000 protected tool calls/month. After the limit, enforcement pauses until the month resets or you upgrade.
Get Started Free

Sign in required · No payment required

Starter
$79/month

Bring Mergen to your team. Share policies, approvals, agent activity, and operational context across developers and machines.

Everything in Free, plus:
  • Up to 10 developers
  • Organization Memory
  • Shared organization policies
  • Slack approvals & escalation
  • +6 more
Usage: Unlimited protected tool calls
Start 14-Day Starter Trial

Sign in required · Card required for trial · Cancel anytime

Compare full plans →

Common questions

What comes up before anyone runs npx mergen-server, and before starting a trial.

Let your agents move fast.
Put a gate in front of the dangerous stuff.

Start locally in under two minutes. Connect your team when you need shared policy, approvals, and visibility.

Get Started Free