KIFF · Cards for AI agents
Give the agent a Card.
The Card holds a set amount of authority, and the agent uses it up as it acts. You can give it more or take it back, and the agent never changes.
refunds-agent
€5,000 a day€20,000 a dayNo authority
€1,000 left today€14,500 left todayHistory kept on its statement
the owner
refunds-agent wants to refund €1,500 on a paid order. Already used today: €4,000.
agent code changed0 linessample dataKIFF answers, your system acts
A permission says yes. A Card says how far.
- asks
- May refunds-agent refund?
- answers
- Yes
- after a refund
- Still yes
- asks
- How much can it still refund?
- answers
- €1,000 left today
- after a refund
- Remaining authority changes
A Card is authority the business can hand over, watch being used, and take back.
Permissions still decide what an agent may touch. The Card is checked on top of them and decides how far.
Now do it across the company.

What authority have we put into the world, and how much is left?
KIFF Cloud
Your Cards, in one place.
KIFF Cloud lists every Card by the agent that holds it. Each Card shows what remains and keeps its revision history. Every decision has its own receipt.
tap a Card to revoke it
Revoking a card withdraws only the authority that card granted. The others keep working.
revisions
- rev 314:20limit €5,000 → €8,000anna@retailer.example
- rev 2Monlimit €20,000 → €5,000anna@retailer.example
- rev 1Frilimit €5,000 → €20,000marc@retailer.example
not a mockup · the real app, sample data
busy weekend · refunds limit €5,000 → €20,000
Same change. Two ways.
- Open a ticket
- Edit the prompt or config
- Review and test
- Deploy
- Monday: do it all again
2 releases
- Owner sets €20,000
- Monday: owner sets €5,000
0 releases
Both changes saved, with who made them.
how teams adopt KIFF
Free to build. Paid when it runs your business.
Framework + Guard
Open source. Put KIFF in front of any agent action, on any stack. No contract, no procurement.
Start building →For the company
- Company workspace
- Owner controls for every card
- Dashboard and statements
- Full history and evidence
- Grows with your agents
Production Launch
We connect your first real action, issue the first cards, test the controls and hand it over.
Get it live with us →Questions teams ask first.
Do I have to rewrite my agent?
No. You add one call before the action. If KIFF says no, your code stops. It works with Agno, LangGraph, OpenAI, Google ADK, Strands, n8n or your own code.
d = kiff.decide("issue_refund", order=order, amount=amount)
if not d.allowed:
return d
payments.refund(order, amount) # your code, unchangedCan the agent raise its own limit?
No. The agent’s key can only ask for a decision. Only an owner or admin of your KIFF account can issue, change or revoke a card.
Does every action need a Card?
No. You choose which actions require one. Permissions and the state of the record are checked first; a Card can narrow and cap what they allow, never widen it.
What if KIFF cannot read the balance?
The answer is no. An unknown balance is never treated as zero, and a retried request is only counted once.
Does KIFF run the action or touch payments?
No. KIFF only answers whether the action is allowed. Your system runs it, as it does today.
Is it only for money?
No. A card can limit amounts, or how many times something happens: three account deletions an hour, two deploys a day.
Can a new model start small?
Yes. Give it its own card with a low limit, and raise it when its statement looks right. The other agents never change.
We build agents for clients. Does it fit?
Yes. Ship the same agent to every client. Each client holds its agents’ cards in its own KIFF account and changes them without calling you.
Start with one Card.
Open your assistant with a prompt to read llms-full.txt and answer from it.