Agentic procurement control plane

Let your AI agent buy software. On a leash.

Set a mandate once: a budget, hard per-purchase and daily caps, and the vendors you allow. Your agent then finds tools, compares them across the market, and buys inside those limits. Every move is logged, and one button stops all of it.

Cross-vendor optimality

The cheapest tool that clears your bar.

Not the cheapest sticker price. We compare 104 vendors across 17 categories against the capabilities and volumes you actually stated, then name the plan that meets them for the least money, and show what the runners-up were missing.

An MCP endpoint for buying agents

Your agent can do the work. Now it can buy the tools.

One MCP endpoint turns procurement into tools your agent calls: discover, compare across vendors, quote, purchase, fetch the receipt. Spend authority travels in a signed mandate, so the limits are enforced server-side, not by a prompt.

Private alpha. We onboard a small number of teams at a time.
agent session over MCP
> find_tool("keyword research, track 500 keywords")
read as: keyword_research, rank_tracking
limits : tracked_keywords >= 500
 
> compare_options(category="seo_tools")
Se Ranking / pro $55.20/mo clears the bar
Semrush / pro $139.95/mo clears the bar
Moz Pro / standard $99.00/mo tracked_keywords 300
 
> request_purchase("se-ranking", "pro")
cap check ok $55.20 of $200.00 monthly
reversible yes 7-day refund window
purchased receipt #4192, logged
104vendors in the catalog
17categories compared
2caps enforced per purchase
1button that stops everything
The gap

An agent that cannot buy is an agent that stops.

Your agent works out that it needs a SERP API, a transcription service, an enrichment provider. Then it hits a wall that has nothing to do with intelligence: someone has to pick a vendor, read the pricing page, put a card in, and file the receipt.

01

Handing over a card is not a plan

The fast workaround is a shared company card in a prompt. It has no per-purchase limit, no vendor allow-list, no record of which agent bought what, and no way to stop it that is faster than calling the bank.

02

Nobody actually compares

Whoever is unblocking the agent buys the first plan that works. The tool five times cheaper that also met the requirement never gets looked at, because looking takes an afternoon and the agent is blocked now.

03

The spend goes dark

Subscriptions accumulate under individual names and personal cards. At renewal nobody can say which agent needed it, whether it is still used, or what it replaced.

How it works

You set the limits once. The agent works inside them.

The authority to spend lives in a signed mandate on our side, not in your agent's context. A prompt cannot argue its way past it.

STEP 01

Set the mandate

A budget, a cap per purchase, a cap per day, and the vendors or categories you allow. Your agent can tighten its own limits at any time. Raising them is a human action in the workspace.

STEP 02

The agent finds and compares

It states a need in plain language. We turn that into concrete requirements, compare every vendor in the matching category, and return the cheapest plan that meets them, plus what each near-miss lacked.

STEP 03

It buys, or it asks you

Reversible purchases with a refund window go through unattended. Anything committed, an annual contract, a non-refundable plan, stops and escalates to a person. Both paths land in the same audit trail.

The comparison

"Cheapest" is a trap. The bar comes first.

A tool at a tenth of the price is not a saving if it tracks 300 keywords when you need 500. Every comparison starts from the requirements, and price only decides between options that already meet them.

  • Requirements, read from plain language. "Track 500 keywords for 3 users" becomes a capability set and a numeric floor, and we show you that reading so you can correct it before anything is bought.
  • Normalized to a monthly figure. Annual totals, per-seat pricing and per-request metering are converted to one comparable number at your expected volume.
  • Near-misses named, not hidden. A plan that fails the bar is shown with the exact capability or limit it missed, which is often what tells you the bar was wrong.
  • Untrusted pricing is excluded from auto-buy. Where we cannot verify a public price with confidence, the vendor stays visible for a human and is never bought unattended.

What "clears the bar" means

Every candidate must hold all the capabilities you asked for, at the depth you asked for, and satisfy every stated numeric limit. Only then does it get ranked, and the ranking is by normalized monthly cost, then by first charge, then by how confident we are in the price.

If nothing clears it, we say so and name the closest miss. We do not quietly relax the requirement to produce a recommendation.

Control surface

Every limit is checked where the money moves.

Not at the start of the session, and not by asking the agent nicely. At the fence, on every purchase.

Hard caps

Per purchase and per day, enforced server-side against the signed mandate. An agent may lower its own ceiling; only a human in the workspace can raise it.

Kill switch

One control stops new spending for the whole organization immediately, and tells you exactly what it left behind: what was already paid, and what was still in flight.

Audit trail

Every quote, refusal, purchase and receipt, with the mandate that authorized it. Refusals are recorded too, which is usually the entry you need when something did not happen.

Reversible vs committed

Classified before the decision, not after. The agent is told in words what buying this would actually do, including whether a real card gets charged.

Scoped vendors

Restrict a mandate to named vendors or whole categories. Anything outside the scope is refused at the fence, not filtered in the prompt.

One workspace

Humans see the same purchases, subscriptions, budgets and receipts the agent sees, and can revoke its token in one action without touching the underlying authority.

Where we are

Private alpha, and we would rather tell you than have you find out.

The control plane, the cross-vendor comparison, the caps, the audit trail and the MCP surface are built and running. Purchases go through today for the vendors we have wired end to end; for the rest, discovery and comparison work and a human completes the checkout.

We are in the middle of an alpha with working testers, and the list of what is not finished is written down and shared with them rather than smoothed over. If that is the wrong stage for you, it is worth knowing now. If it is the right stage, you get to shape what gets built next.

Request access

Tell us what your agent needs to buy.

We open access in small batches so every team gets a real conversation. Say what you are building and what it keeps getting blocked on, and we will tell you honestly whether we can help yet.

  • No self-serve sign-up, on purpose. Spending authority is granted deliberately.
  • You keep your own vendor accounts and your own card.
  • A short call, then a workspace and an MCP token if it is a fit.
We use this to decide who to onboard next, and nothing else. No newsletter.
Questions

The ones people actually ask.

Does the agent get my company card?

No. You register a payment method once in the workspace. The agent never receives card details and cannot read them back. It gets a signed mandate that says how much may be spent, on what, and until when, and every purchase is checked against that mandate on our side.

What stops a prompt injection from buying something?

The limits do not live in the agent's context, so nothing the agent reads can change them. A compromised agent can still make requests, and those requests are checked at the fence: over the cap, outside the vendor scope, or a committed purchase that requires a human, and it is refused and logged. The kill switch stops the rest.

How does my agent connect?

Over MCP. You mint a token in the workspace and point your agent at the endpoint; discovery, comparison, quoting, purchasing and receipts arrive as tools it can call. Anything that works with MCP works here, and there is nothing to install.

What happens with a subscription the agent buys?

It appears in the workspace with its price, period and renewal date, alongside the purchases made against it. A human can cancel from there. We are candid with our alpha testers about which parts of the renewal path reach the vendor automatically today and which still need a person, and you get the same list.

Which vendors are in the catalog?

104 across 17 categories today: SEO suites, SERP and web-search APIs, scraping and extraction, cloud browsers, OCR and document AI, vision, speech to text and text to speech, translation, embeddings and reranking, vector databases, proxies, B2B enrichment, email verification and geocoding. Prices come from each vendor's own public pricing page, and where we cannot verify one confidently it is never bought unattended.

What does it cost?

A subscription for the control plane, plus a percentage of what flows through it. We will put exact numbers in front of you on the call rather than a pricing page that does not yet match what we can deliver.