Product1 distinct publisher3 min readPublished
Guard for Agents pulls policy documents out of Notion and Drive, turns them into a rule list you can toggle, and checks outgoing text before it ships. The extraction step, not the block, is what a buyer approves.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The extracted rule list is the actual product, and it is where a rollout goes quietly wrong. A handbook paragraph written for people carries hedges that a reader resolves with judgment. ZeroDrift's answer is to show its work: customers inspect the rules its model pulled out of the document and choose which ones to enforce and how [7], and rules can be switched on or off while the application is running and configured per agent [10]. Founder and CEO Kumesh Aroomoogan describes the position as "the pre-send layer," saying that "at the generation of the message, we're intercepting" [16].
Teams tend to treat the source document as settled: it says what the company's policy is. In practice, what it usually holds is several years of accreted exceptions, plus a paragraph two departments read differently. Reviewing a machine-extracted version of it is a cheap policy audit whatever you decide about enforcement.
The pricing is legible, which is rarer than it should be. At one cent per validation [2], that is $10 per thousand messages and $10,000 per million [23]. An agent answering 20,000 customer emails a month costs $200 a month to gate, or $2,400 a year [24]. What actually matters isn't the invoice, it's what the same review costs when you pay a general-purpose model to grade another model's output, and ZeroDrift says third-party benchmarks are still to come [14].
The sorting question is a two-by-two. One axis is how literal the rule is. The other is what a wrong block costs. Handling violations with no human in the loop [17] belongs only in the literal-and-cheap corner: a Social Security number in outgoing text [8], a message promising a guaranteed investment return [9]. Rules that need judgment, where a held message means a customer waiting on an answer they were entitled to, belong in the escalate box, and the same endpoint supports that by returning a severity and recommending review instead of acting [4].
The artifact worth the most on Friday is the log. ZeroDrift records the original message, the rule that fired, the action taken and the resulting output [11]. That converts "we have a policy" into a dated record of what the agent tried to say and what the company did about it. Note the authorship boundary: automatic rewrites apply to machine-generated content, not to messages a person wrote [18], so who drafted the text decides whether the system edits or merely flags.
The test I would run before signing is a replay. Take last month's agent transcripts, run them against the extracted rules in report-only mode, and count two things: how many messages a rule would have touched, and how many of those interventions you would defend to the customer who received them. If a rule would have caught hundreds and you would stand behind a handful, the rule is wrong, and a cent a message buys a well-documented argument with your own customers.
Ranked by verification strength, evidence, and original report placement.
ZeroDrift Inc. introduced Guard for Agents, a service that lets developers turn written company policies into enforceable rules to check AI agents' communications before they reach customers.
ZeroDrift charges one cent per validation, which can cover messages sent via email, text message or Slack post.
Guard for Agents ships as an API with connectors that import policy documents from Notion Labs Inc., Linear Orbit Inc. and Google LLC's Drive, using Model Context Protocol.
Developers send an agent's output to a validation endpoint; the service checks the text against rules and returns information about any violation, including its severity, and depending on the policy can supply a replacement, recommend blocking the message or escalate the issue for human review.
The controls operate on outgoing responses rather than incoming prompts, making the service a check on what agents communicate.
ZeroDrift's proprietary small language model identifies rules in the imported policy text.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
APIs built for human judgment now answer to agents that have none1 distinct publisher
build
Google's legal AI bundle lands a day after a $40M model, and the connector list tells you why2 distinct publishers
invest
Scalable Capital puts ChatGPT, Claude and Grok inside the European order ticket2 distinct publishers
build
Nine of twenty-one upstream API change types break an MCP tool outright1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one interview, no outside check
Product mechanics are described precisely enough to be falsified by anyone who signs up — a validation endpoint, an OpenAPI spec, three named document connectors — and that precision is what keeps this score off the floor. Everything above the mechanics is ZeroDrift describing ZeroDrift to SiliconANGLE. The claim that matters most to a buyer, how reliably a small language model turns a policy document into the right rule list, is not measured anywhere in this reporting, and the millisecond figure comes with the reporter noting no numbers were supplied.
Shipped, not yet seen in anyone's hands
What exists is a launch and a rate card. Nobody in this reporting has bought it: no customer, no pilot, no message volume, no throughput figure. The demand described — voice agents in financial services and healthcare, startups wanting a bolt-on compliance layer — is a founder characterising his pipeline, which is a sales signal rather than a usage one. The Command console it builds on presumably has users, but none are named or counted here either.
Speed and savings claimed ahead of the tests
The overreach is narrow but lands precisely where a buyer would push: milliseconds with no measurement, and cheaper-and-faster-than-a-general-purpose-reviewer with the benchmarks still on the roadmap. Against that, the language is mostly restrained — the service recommends blocking rather than promising compliance, rewrites are scoped to machine-generated text, and SiliconANGLE puts the missing performance data in its own last paragraph instead of burying it. A launch that told readers what it had not yet proven does not earn a large penalty; it earns this one.
The seller wrote the record
Trace any detail here and it ends at ZeroDrift: the announcement, the interview, the example violations, the promised benchmarks that the company would commission and publish about its own model. Two structural incentives deserve naming. Customer metadata and enforcement decisions feed model improvement, so buyers of the compliance layer are also unpaid labelers for it. And a vendor whose value is measured per validation has no reason to make its rule extraction less eager, since a rule that fires is a rule that bills.
Solid on what it is, thin on how well it works
Split the question and the answer stops being murky. That Guard exists, prices at a penny a check, imports policies over Model Context Protocol and returns severities and rewrites — that is reported specifically by a trade outlet that talked to the founder, and it would be strange to get wrong. Whether the extracted rules match the policy, whether latency survives a synchronous send path, whether any of the described demand converts — none of that is knowable from this record, and a second account or a single named deployment would move the number more than any further vendor detail.