Failure map
The exact risky action, trigger, accountable owner, current safeguard, and missing proof.
Hard allow/deny at the tool-call boundary. Audit entry written at decision time. Every approval teaches the next gate.
Dual path (buy + book): $499 Diagnostic maps one expensive failure on Claude Code, Cursor, Codex, or similar agents and installs a hard gate with proof — or self-serve Pro at $19/mo if you already know the loop. Free local evaluate stays free.
npx thumbgate init free local evaluate · first hard gate usually minutes after install · how we stack up
No governance novel. Corrections become reviewable local lessons; relevant lessons are re-ranked; repeated negative patterns can become explicit gates; and the next action is checked before execution. Click a step to see what happens under the hood.
Record explicit 👍 or 👎 feedback with the action and outcome context that made it useful or wrong.
Under the hood ↓Store a reviewable lesson that survives sessions and model changes without sending the control history into model weights.
Under the hood ↓Re-rank relevant lessons for the action. Repeated negative patterns can promote from warnings to blocking gates; stale gates expire.
Under the hood ↓The action is allowed, warned, or denied before the tool proceeds.
Each reviewed outcome closes the loop—under your control. Lessons are re-ranked per action, repeated failures can promote into gates, and stale auto-promoted gates expire. The firewall improves from explicit feedback without retraining the model or silently rewriting policy.
This is the enterprise entry offer for one workflow, not an org-wide hosted platform license.
The exact risky action, trigger, accountable owner, current safeguard, and missing proof.
One supported local rule wired to deny, warn, or require a human before execution.
The working test, rollout check, rollback boundary, and evidence receipt for the installed gate.
proposed git push --force origin main mode strict enforcement rule protect-main source core protection · strict mode decision DENY reason force-push to protected branch next decision recorded before execution
Detected secret exfiltration and attempts to kill or bypass the gate process are denied by default. Matching destructive actions warn by default and deny in strict mode.
The example shows the strict-mode decision the managed install would specify and test. It is not a claim that every free install blocks every risky command automatically.
Read the test-backed verification evidence →npm pack thumbgate and read it yourself. Your lessons live in a local SQLite file you own, not a server you can't query. Paid tiers add hosted sync, the dashboard, and adapter coverage, not access to intelligence withheld from the free install.Pro is the self-serve subscription for operators. The $499 enterprise gate is a managed install for one painful workflow—not another policy deck.