Software agents are starting to take real actions — moving money, deleting data, shipping code. Someone accountable has to approve the risky ones, and be able to prove they did. Noa Mandate is where that approval happens, and the proof it leaves can be checked by anyone, offline, years later.
The last year moved agents from suggesting to doing. That is where the risk changed shape. A model that drafts an email is a productivity tool. A model that can issue the refund, drop the table, or merge to main is an operator — and operators need an accountable human on the consequential minority of their actions.
The fix was never a smarter model. It is a named person who approves or refuses the risky call, in the moment, with a record that survives the argument afterward. That layer does not exist as a standard yet. We are building it.
We track these incidents in the open, sourced and self-corrected, in our Signal series — the same discipline we hold our own claims to.
Read the Signal seriesAn agent asks to do something consequential. Instead of executing, the gate pauses it and routes one request to whoever is on call — with the exact action, its risk class, and the precise fields being changed.
Approve or refuse — refusal is a first-class decision, signed exactly like an approval. The signing key is generated on the device and never leaves it. Nothing is signed until a human deliberately does it.
Each decision becomes a tamper-evident receipt in a hash chain. Alter one and verification catches it. You do not have to trust our server, or us — the proof checks itself, with an open verifier.
Receipts verify offline with an open verifier — npx noa-receipt verify. Anyone can check a decision without our permission. Standards compound; dashboards get replaced.
The policy rules, receipt format, offline verifier, MCP proxy and SDK core are open source (Apache-2.0), live on npm today. Adoption starts with a function call, not a sales call. The managed governance plane is the business on top.
We publish verified, sourced analysis of real agent-accountability incidents — and correct ourselves in public when we get a detail wrong. That is how a category earns the right to define itself.
A trust product that oversells is a contradiction. We say what a receipt does not prove, in the app and on the box. That restraint is unusually hard to copy — and it is exactly what a security buyer trusts.
The three open-source packages — noa-receipt, noa-mcp-proxy, noa-mcp-adapter-core (all Apache-2.0) — were downloaded 2,985 times from npm in the month to 2026-08-09 (1,251 + 848 + 886), measured 2026-08-11 against the public npm downloads API — whose counts include mirrors and CI, as every npm number does.
3 Apache-2.0 packages — noa-receipt@0.8.0, noa-mcp-proxy@0.4.0, and noa-mcp-adapter-core@0.4.0 — were publicly available on npm when checked 2026-08-31. This is a package-availability fact, not a public-source-repository claim.
The enterprise console already ships SSO/SCIM, data retention, SIEM export, audit anchoring and per-tenant signing keys — and our own governance engine runs in production as its first user: we operate the product ourselves, and its own signed ceremonies gate our production changes.
Both mobile apps were submitted to the stores on 2026-08-11: Google Play (production release, no country restriction) and the App Store. Submitted is not available — neither can be downloaded until the stores approve, and this line changes the day that happens.
You will not find invented logos, a fabricated user count, or a ten-person team on this page. What is here is real and checkable — which is the whole point of the product.
One person built this — and here is the honest answer to that risk.
Everything above was built and is operated by a single founder. That is the capital efficiency of the approach — and a concentration risk we answer rather than hide. The structural half of the answer is already shipped: the receipt format and the verifier are open source and verify offline, so a customer’s evidence stays checkable even if this company disappears — proof that survives its vendor. The operational half — security response, support, compliance — is exactly what the first hires below exist to cover.
As autonomous agents enter regulated workflows, the accountability-and-audit gap becomes something regulators, auditors and insurers will price. The buyer is the person who owns AI risk — the CISO, the Head of AI governance. We land through the open-source core and expand into managed governance, per workspace and per approver.
The first buyer is the security or platform-engineering owner at a company already running agents against real systems. They can name their irreversible actions immediately — payments, deletions, production changes — they already answer audit questions, and their teams adopt open source without a procurement cycle. They start with the open-source gate in an afternoon; the console is the governed, managed layer their compliance function asks for next. The CISO and the Head of AI governance follow as the deployment grows.
Market size, bottom-up — argue with the inputs
We size bottom-up rather than quoting an analyst headline: organizations running agents with write access to real systems × approver seats per organization × a per-seat price in line with adjacent security tooling. Each input is an assumption, published so it can be attacked:
Multiplying the midpoints puts the serviceable market in the hundreds of millions of dollars per year. We publish the method instead of the headline so you can swap any input for your own and get your own number.
The real default: trust the model and hope. It costs nothing until the first irreversible mistake — and it leaves no answer to the auditor’s first question: who approved this?
A Slack button or a ticket gate — the pattern Noa is built to replace. It works until someone asks for proof: chat logs are editable, deletable and vendor-siloed. No signature, no offline verification, no portable evidence.
Agent frameworks and MCP hosts ship yes/no prompts, and the large platforms are adding human-in-the-loop features. The closest substitute — but session-scoped and vendor-siloed, with no signed, portable, offline-verifiable record.
Records that something happened, after it happened. Genuinely valuable, and complementary — but none of it holds an action before execution, or binds a named person’s signature to the decision.
The honest risk: any large platform could bolt signed approvals onto its own stack. Our bet, stated plainly, is that accountability evidence is only worth something if it outlives any one vendor — which favors a neutral, open format over a platform feature. That is a bet, not a certainty.
We are not running a raise. We are open to conversations with investors who work on agent infrastructure and security — the honest state of the company is on this page, and what capital would accelerate is listed below, in priority order. If that is a future you want to back, we would like to talk.
What capital would accelerate, in order
First hires, in order: a security engineer who owns incident response, an enterprise support engineer, and a compliance lead. The founder keeps building product.
This page makes no forward-looking financial promises, and every number on it carries its measurement date. Re-run them yourself: api.npmjs.org/downloads/point/2026-07-11:2026-08-09/noa-receipt (same URL shape for the other two packages), npm view noa-receipt@0.8.0, or npx noa-receipt verify. The market sizing above is labeled assumption, not measurement.