Insights2 min read

Agents under grants: how Niiko lets AI act without letting it charge

AIEngineeringNiikoMCP

GRANTED.// AGENTS ACT · THEY NEVER CHARGE
A grant, drawn: a dotted violet-to-orange field with one gate open and the rest closed

We wire AI models into the centre of an operation, not as decoration. The model proposes; the code decides. Above a threshold, a human signs — and if there is nobody to sign, nothing gets charged.

A language model is fluent at the exact moment it should be silent: it will propose a price, a date or a discount with the same confidence whether or not it has any right to. That is the whole problem with letting it act. So Niiko's agents do not act. They propose a typed intent, and everything that has consequences happens in code that does not care how persuasive the model was.

The price comes from the database or it does not come

An agent in Niiko can say «quote this» but cannot say «for $58». The price is looked up, by the code, from the catalog the business maintains. If the lookup fails, the quote fails — loudly, with a refusal that is recorded as carefully as a success. The model may supply search terms, never identifiers; a forged identifier does not compile into anything.

Capabilities, not permissions

Each thing an agent may do is a capability with its own cap, in its own unit, granted explicitly. A cap on «messages per hour» and a cap on «dollars per day» are not the same kind of number, and a system that stores them in the same column cannot compare either. Autonomy belongs to the capability, not to the agent: when one degrades, the others keep working.

Above a threshold — the business sets it — a human signature is mandatory. The arguments the model proposed are frozen at that moment, so what the human approves is exactly what executes, not a version the model quietly revised while waiting. Human approval is not a defence on its own; freezing the arguments is.

The same rules for your agents

Everything an agent can do inside Niiko is exposed the same way outside it: a remote MCP server (connect Claude or any OAuth-capable client, and every action you grant becomes a tool), SDKs in TypeScript and Python, a CLI, an n8n node. Same manifest, same refusals, same caps. Your agents operate under the rules the business already wrote, not a looser copy of them.

  • ratchet — per-capability autonomy for AI agents: caps in their own unit, and refusals you can act on. Open source, on npm.
  • typed-refusals, search-terms-not-identifiers, freeze-the-arguments, per-capability-autonomy — public repositories, each one a lesson with its failing test.
  • niiko-mcp-server, niiko-sdk-typescript, niiko-sdk-python, niiko-cli, n8n-nodes-niiko — generated from one action manifest.

// Experience itSee the repositories on GitHub