howldr wolf watermark
Open-source gate · MIT
Product → agent & automation control
[ leaps and bounds ]
Move by leaps, stay in bounds.

Your automations already act on your behalf — sending mail, moving files, touching customer records, calling APIs. Add an AI agent and the blast radius grows without the paperwork catching up. leaps and bounds puts a deterministic gate in front of every action: nothing runs unless it was explicitly allowed, and everything that runs leaves a receipt you can replay.

Automation is easy.
Accounting for it isn't.

A scheduled script, a Zapier flow, an n8n workflow, an AI agent with tool access — each one can take a real action against a real system, and most of them run with a standing credential and no record beyond a log line. When something goes wrong, or an insurer asks what your automations are permitted to do, the honest answer is usually a shrug. leaps and bounds is the layer that makes that answerable: a boundary that says what is allowed, and a log that says what happened.

Five steps,
one of them says no.

Every request follows the same path. The gate is not advisory and it is not a suggestion to a model — it is a check against a boundary row, and it fails closed.

This step is the product. A boundary row names the actions this actor may take and the limits on them — how many recipients, which hours, which data. The check is deterministic code against that row, not a judgement call, and it fails closed: absent an explicit allow, the answer is no. There is no override flag, because a gate that can be overridden under pressure is a gate that will be overridden under pressure.

Boring on purpose.
That's the feature.
Default deny
If an action was not explicitly allowed, it does not run. There is no override flag. A boundary can hold an action for a named person to approve, but an approval never turns a deny into an allow. Widening a boundary is a deliberate change, not a button someone clicks under pressure.
No model in the decision
A model may propose an action. It never participates in allowing one. The check is deterministic code against a stored boundary, so the same request always produces the same answer — and you can prove it did.
Replayable receipts
Every decision — allowed or denied — is appended with the actor, the parameters, and the boundary version in force at the time. Re-run the log and you get the same decisions back. That is the evidence.
Agents don't hold credentials
Secrets stay in your secrets manager and are dereferenced at the point of use by the worker. What the platform stores is a pointer and a fingerprint — never the secret itself.
The log is the rate limiter
Limits are counted from the same append-only record that proves what happened — so the thing enforcing your caps and the thing evidencing them cannot disagree with each other.
Wraps what you already run
n8n, Zapier, cron, queues, your own scripts — leaps and bounds governs them by sitting in front of the action, not by asking you to rebuild your automation stack somewhere else.
One animal,
two aspects.

howldr is named for the wolf's voice. leaps responds to the call; bounds assures a safe gate. Same animal, different capability — which is why this is its own product rather than a feature of something else.

The pairing turned out to describe the problem better than we expected. A wolf pack is close to a literal picture of what this software governs: distributed actors moving independently, inside a territory with hard edges, coordinating by signal. Wolves are disciplined about range. That is the whole idea.

A boundary here is a row in a database, not a paragraph in a policy. It names the actions an actor may take and the limits that apply to them, and it is checked before anything runs. Absent an explicit allow, the answer is no. There is no override flag, and an approval can release a held action but never overturn a deny. Widening a boundary is a deliberate change somebody makes on purpose, which is precisely what makes the record of what was permitted, and when, worth something a year later.

Read the gate.
Then talk to us.

The gate is open source: bounds is on GitHub under the MIT license, free to read and run yourself. The full product is in active development, with early access opening one organization at a time. If you are running automations you cannot fully account for, or about to give an agent real permissions, that is exactly the conversation to have. The license covers the code, not the names, so a fork can't be called howldr or Leaps and Bounds.

No spam, no commitment — just a conversation about your setup.