shugo: on-chain guardrails
for ai agents
a zero-custody policy engine. enforce cryptographic velocity caps and execution bounds directly on solana.
built on the solana foundation's official delegations program
no. the agent does not possess the treasury's private keys. it only possesses execution authority bounded by shugo's on-chain cpi proxy. if an agent attempts to exceed its epoch cap or call a non-allowlisted program, the anchor program rejects the transaction.
multisigs require synchronous human signatures for every transaction, defeating the purpose of an autonomous agent. shugo is a delegation engine: humans sign once to establish cryptographic bounds, and the agent executes autonomously within them.
the velocity tracking accumulators and mathematical bounds are formally verified using the aws kani model checker. we mathematically prove that integer overflows and epoch-bypass vectors are impossible under any execution path.
no. shugo is strictly a zero-custody protocol. assets remain in your native solana wallet. we leverage the official solana subscriptions & allowances (s&a) program to act solely as a strict authorization proxy.
the attacker is mathematically bound by the exact same velocity caps and target allowlists. furthermore, the treasury owner can revoke the agent's cpi execution authority instantly via a single `shugo revoke` instruction.
a zero-custody policy engine. enforce cryptographic velocity caps and execution bounds directly on solana.
built on the solana foundation's official delegations program