Now live · Pre-action gates · Not a prompt · Not a postmortem

Stop AI agent mistakes before they cost you.

Hard allow/deny at the tool-call boundary. Audit entry written at decision time. Every approval teaches the next gate.

Dual path (buy + book): $499 Diagnostic maps one expensive failure on Claude Code, Cursor, Codex, or similar agents and installs a hard gate with proof — or self-serve Pro at $19/mo if you already know the loop. Free local evaluate stays free.

Capture feedback Rank lessons Promote gates Block next action
ThumbGate: thumbs up and thumbs down become a pre-action gate that can ALLOW, WARN, or DENY before the tool call runs
See a strict-mode deny example ↓ See how the self-improving loop works ↓

npx thumbgate init free local evaluate · first hard gate usually minutes after install · how we stack up

Dashboard: npx thumbgate dashboard --open · /thumbgate-dashboard · bin thumbgate-dashboard if global · demo

$499one time · cash path

Diagnostic Gate

Managed AI Agent Workflow Gate. Bring the failure. Leave with one hard gate and proof — ranked burn, configured pre-action check, regression test. Not a strategy deck.

Secure Stripe · no subscription · one workflow. Prefer a call first? See how it works or email after checkout.

  • 60-minute working review for one workflow
  • One configured local gate and its regression test
  • Rollout and rollback proof within two business days
Why it’s called ThumbGate

Thumbs teach. The gate enforces.

Without ThumbGate the same AI agent mistake repeats. With ThumbGate one thumbs-down becomes a local pre-action gate that can refresh or expire.
Agent proposes a tool, ThumbGate decides ALLOW WARN or DENY, thumbs feedback becomes a rule that closes the loop.
Self-improving product loop

Pre-action checks—and the systems that refine them.

Corrections become local lessons; repeated negatives become gates; the next action is checked before execution. Click a step for the under-the-hood demo.

Self-improving ThumbGate loop: thumbs up or thumbs down become a local lesson, then a prevention rule, then ALLOW WARN or DENY on the next tool call. The loop closes under your control without retraining the model.
Is it really self-improving? Yes — the control layer, not the LLM. 👍/👎 → local lesson → ranked rule → next tool call gated. No model retrain.

Each reviewed outcome closes the loop—under your control. Lessons are re-ranked per action, repeated failures can promote into gates, and stale auto-promoted gates expire. The firewall improves from explicit feedback without retraining the model or silently rewriting policy.

What the $499 enterprise gate buys

A managed gate for one painful workflow.

Enterprise entry for one workflow—not an org-wide platform license.

Failure map

The exact risky action, trigger, accountable owner, current safeguard, and missing proof.

Configured gate

One supported local rule wired to deny, warn, or require a human before execution.

Regression and rollout proof

The working test, rollout check, rollback boundary, and evidence receipt for the installed gate.

Boundary: the offer covers one supported local workflow. Multi-system implementation, legal or compliance certification, guaranteed savings, and hosted team features require separate scope. If the workflow cannot be reduced to one supported gate, the order is refunded instead of silently upsold.
What “stop” honestly means

Hard deny where configured. Honest warning everywhere else.

proposed  git push --force origin main
mode      strict enforcement
rule      protect-main
source    core protection · strict mode
decision  DENY
reason    force-push to protected branch
next      decision recorded before execution

Detected secret exfiltration and gate-process bypass attempts are denied by default (process-kill/environment-override self-disable floors). Matching destructive actions warn by default and deny in strict mode.

Managed strict-mode example—not a claim that every free install blocks every risky command automatically.

Read the test-backed verification evidence →

White paper · Scorecard · Architecture · Cases

Before you buy

Five questions, answered plainly.

One 60-minute working review for one repeated AI-agent workflow failure, one configured local gate for a supported workflow, its regression test, and a written rollout and rollback proof within two business days after access and the agreed materials are available.
No. Detected secret exfiltration and gate-process bypass attempts are denied by default. Matching destructive actions warn unless strict enforcement is enabled. The managed gate defines the right boundary for your workflow instead of pretending every warning is a firewall.
Yes. The $499 Enterprise Workflow Gate is the enterprise entry offer for one supported workflow. It is not an org-wide hosted platform license: shared hosting, SSO, compliance packaging, and multi-workflow rollout require separate scope and are not generally available.
No. ThumbGate does not change model weights and does not silently rewrite production policy. Self-improving under your control means explicit approvals and feedback teach the local control layer what to allow, block, or escalate next time: lessons are stored and re-ranked, repeated negative patterns can promote into gates, and stale auto-promoted gates expire.
No. The promotion, demotion, and lesson-ranking logic ships in the public npm bundle under an MIT license — run npm pack thumbgate and read it yourself. Your lessons live in a local SQLite file you own, not a server you can't query. Paid tiers add hosted sync, the dashboard, and adapter coverage, not access to intelligence withheld from the free install.
Two cash paths

Start self-serve, or bring the failure that already cost you time.

Pro is self-serve for operators. The $499 gate is a managed install for one painful workflow—not a policy deck.

Start Pro — $19/mo Buy the $499 enterprise gate