Your automations already act on your behalf — sending mail, moving files, touching customer records, calling APIs. Add an AI agent and the blast radius grows without the paperwork catching up. leaps and bounds puts a deterministic gate in front of every action: nothing runs unless it was explicitly allowed, and everything that runs leaves a receipt you can replay.
Accounting for it isn't.
A scheduled script, a Zapier flow, an n8n workflow, an AI agent with tool access — each one can take a real action against a real system, and most of them run with a standing credential and no record beyond a log line. When something goes wrong, or an insurer asks what your automations are permitted to do, the honest answer is usually a shrug. leaps and bounds is the layer that makes that answerable: a boundary that says what is allowed, and a log that says what happened.
one of them says no.
Every request follows the same path. The gate is not advisory and it is not a suggestion to a model — it is a check against a boundary row, and it fails closed.
Something starts it: a cron entry at 3am, a webhook from your CRM, a person clicking a button, or an agent deciding on its own that the next thing to do is send an email. Where it came from is recorded and never used to skip a check. A request from a human gets the same scrutiny as one from a model, because "someone asked for it" is how most bad actions get justified after the fact.
Intent stops being prose here. "Email the overdue invoices to accounts payable" becomes a named action with named parameters — an action, a recipient list, a count. You cannot gate a sentence. Structuring the request is also what makes it identifiable: the same request resolves to the same fingerprint, so a trigger that fires twice replays instead of sending twice.
This step is the product. A boundary row names the actions this actor may take and the limits on them — how many recipients, which hours, which data. The check is deterministic code against that row, not a judgement call, and it fails closed: absent an explicit allow, the answer is no. There is no override flag, because a gate that can be overridden under pressure is a gate that will be overridden under pressure.
Only once the decision is committed and written down. The order is deliberate — decide, record, then act — so there is never a window where something ran but nothing says why. The worker holds the credential and resolves the secret at the moment of the call; the agent never sees it. What the agent was given was permission, not access.
Actor, action, parameters, decision, outcome, timestamp, and the boundary version in force when it was judged. Appended, never edited, and replayable — run the log again and the same decisions come back. Denials are written exactly as allows are, which is the part most people miss: evidence that your controls stopped something is worth more to an insurer than evidence that nothing was ever attempted.
That's the feature.
two aspects.
howldr is named for the wolf's voice. leaps responds to the call; bounds assures a safe gate. Same animal, different capability — which is why this is its own product rather than a feature of something else.
The pairing turned out to describe the problem better than we expected. A wolf pack is close to a literal picture of what this software governs: distributed actors moving independently, inside a territory with hard edges, coordinating by signal. Wolves are disciplined about range. That is the whole idea.
Speed is the point. An automation that needs a person at every step isn't an automation, and an agent you have to approve action by action is just a slower way of doing the work yourself. This is the half that moves — the scheduled job, the event-driven flow, the agent choosing its own next step. leaps and bounds doesn't slow that down or ask you to rebuild it somewhere else. It wraps what you already run, so the motion stays yours.
A boundary here is a row in a database, not a paragraph in a policy. It names the actions an actor may take and the limits that apply to them, and it is checked before anything runs. Absent an explicit allow, the answer is no. There is no override flag, and an approval can release a held action but never overturn a deny. Widening a boundary is a deliberate change somebody makes on purpose, which is precisely what makes the record of what was permitted, and when, worth something a year later.
Then talk to us.
The gate is open source: bounds is on GitHub under the MIT license, free to read and run yourself. The full product is in active development, with early access opening one organization at a time. If you are running automations you cannot fully account for, or about to give an agent real permissions, that is exactly the conversation to have. The license covers the code, not the names, so a fork can't be called howldr or Leaps and Bounds.