Give AI agents tools.
Keep control.
Wardn is the control plane for governed AI tool access—one place to approve MCP servers, protect credentials, run agents, and account for every action.
Built for platform engineering, security, and AI teams
Prepare release notes
- Request received
Summarize merged changes since the last release.
- Policy evaluatedPassed
github.list_pull_requests allowed
- Tool called
GitHub MCP · 14 pull requests returned
- Response delivered
Posted to #product-releases
Govern tools across your stack
The last mile of agent adoption isn’t intelligence. It’s control.
Local configs and one-off bots work—until every agent carries a different set of credentials, policies, and blind spots. Wardn turns that sprawl into an operating model.
Unknown tools
Know which MCP servers are approved, which version is installed, and which tools each agent can reach.
Scattered credentials
Keep secrets behind managed handles and bind access to workspaces—outside prompts, scripts, and local config files.
Invisible actions
Trace prompts, tool calls, approvals, errors, token use, and cost without stitching together another observability stack.
From discovery to execution,
the guardrails stay attached.
Wardn keeps trust decisions in the path of every run—whether an agent starts in chat, on a schedule, or from a connected channel.
Curate what enters your stack.
Review server metadata, versions, transport, and tools before a workspace can install them.
- Organization-owned catalog
- Endpoint and tool validation
- Version-aware installations
Everything between
the model and the action.
A compact control plane for the parts that become fragmented when agent programs move beyond a proof of concept.
Approve once.
Deploy with confidence.
Curate server metadata, install into scoped workspaces, validate real tools, and run with local or Kubernetes-oriented isolation.
Policy before execution.
Restrict tool use, require a human decision, and bind approval to the exact action and arguments.
One agent, many ways to work.
Run through chat, recurring tasks, Slack, Telegram, or WhatsApp—with the same tools and policy path.
Credentials stay out of the prompt.
Connect model providers and managed secret handles without handing raw credentials to every agent.
Every run tells the whole story.
Follow tool calls, approvals, failures, model use, token volume, and cost from organization health down to one execution.
Engineering gets velocity.
Security gets control.
Build the useful thing.
Give teams approved tools and reusable agents without rebuilding auth, runtime management, scheduling, and traces for every project.
- 01Validated MCP installations
- 02Reusable agents and skills
- 03Multiple models and channels
Know what it can do.
Keep trust, credentials, limits, and approval decisions centrally managed while preserving a complete record of agent activity.
- 01Tool-level access rules
- 02Human approval routes
- 03Usage and audit visibility
Own the control plane.
Keep your boundaries.
Run Wardn where your tools and data already live. Start locally, connect PostgreSQL and your model providers, then move MCP execution into Kubernetes when you need stronger isolation.
git clone https://github.com/abhi1693/wardn-ai.gitcd wardn-aicp wardn/backend/.env.example wardn/backend/.env(cd wardn/backend && uv sync --extra dev && uv run alembic upgrade head)npm installcd wardn/backend && uv run uvicorn app.main:app --port 8000 --reloadcd wardn/backend && uv run python -m app.manage runmcpjobsnpm run web:devYour agents can move fast.
Your standards can keep up.
Bring tools, policy, execution, and evidence into one governed path.
Configure PostgreSQL and required WARDN_* settings