Blog: Art-Kubed

Introducing Operant Semantic Firewall and three more launches for expansive real-time controls and native agentic telemetry that you own

Introducing Operant Semantic Firewall and three more launches for expansive real-time controls and native agentic telemetry that you own

At Operant, we are proud that today we are shipping four announcements, led by our major release: Operant Semantic Firewall

Each announcement today, including Operant Token Meter, Operant Browser AI Protection, and Expanded Claude Coverage is driven by the same underlying challenge: knowing and controlling — what is this agent actually trying to do, right now, and should it be allowed to? — at the same speed as agents decide and act. Each capability is addressing different open gaps in the agent loop – the tool call, the token, the browser tab, the workspace panel – and is available today to all customers who need to solve these core security problems that are standing in the way of their AI road maps and agentic development velocity. And each one produces the same thing as a byproduct: a native record of what your agents actually did, in your environment, under your control.

The alternative most enterprises have been offered until now is a patchwork: a cost dashboard from one vendor, a browser extension from another, a DLP tool that was built for file uploads trying to reason about a chat window, and a roadmap slide promising that "real-time" enforcement is coming next quarter. None of those pieces talk to each other, and none of them were built for what agents actually are — systems that reason probabilistically and act at machine speed, with no fixed pattern to check against because the action they're about to take has never existed before.

Three Ways an Agent Goes Wrong — and Why They Share One Fix

Strip away the branding and every incident an agent causes falls into one of three buckets.

It gets manipulated. A prompt injection, a jailbreak, a poisoned document, a plugin with a hidden directive — something reshapes the agent's task mid-session, and it acts on an intent that was never the user's.

It drifts on its own initiative. No attacker required. The agent chases the goal it was given down whatever path gets there fastest, improvising a step no one authorized or chaining reasonable-looking actions into something no one would have approved if asked directly.

It's simply inefficient. Not compromised, not off-course — just wasteful, thousands of times over, at a speed no human review cycle can keep pace with. An agent that re-reads a full repository when it needed one file, or falls back to the most expensive model for a question that didn't need it, isn't malicious. It's just burning money in a way nobody was watching closely enough to catch.

Three failure modes, and the same underlying gap sits behind all of them: nothing was reading intent at the moment of action. Pattern-matching can't help, because there's no known-bad signature for a request that's never been made before. A monthly report can't help, because by the time it exists, the tokens are already spent and the data's already moved.

Neither can the layers you already instrument: the network sees an approved endpoint, the kernel sees a permitted syscall, and an agent's damage is almost always done through actions that are technically authorized. The risk lives in what an action means rather than whether it was allowed — and meaning exists only in the semantic layer, the prompt, tool call, and payload that no network or kernel control was ever built to read.

The only control that reaches any of the three is one that understands what an action means and can rule on it inline, before it executes — and once you build that capability, it turns out to apply to cost the same way it applies to a breach.

Semantic Firewall: The Control Plane for Intent

Operant Semantic Firewall reads the actual intent behind every prompt, tool call, command, and data movement, and returns an allow, block, or redact decision as the agent acts — not after. It's the first product built to catch what pattern-based tools structurally cannot: the manipulated agent and the self-directed one, at the same time, because both fail the instant they try to execute outside their scope. Tool Intent Guard catches the exfiltration and bulk access that look routine on the surface. Code Intent Guard catches the injection and privilege escalation hiding inside otherwise ordinary agent activity. Data Intent Guard enforces sensitivity labels the enterprise already trusts. And Scope Guard holds the agent to the purpose it was given as a running contract — checked continuously across the whole loop, not just the opening prompt — so an agent can't be walked step by step, or wander on its own, into work it was never authorized to do.

Token Meter: The Same Real-Time Read, Applied to Cost

The inefficiency bucket looks nothing like a breach on the surface, but it's the same shape of problem: a top-level, after-the-fact number that arrives once the spend is already gone, the same way a signature list arrives once the attack is already known. Operant Token Meter takes the real-time, granular read that Semantic Firewall applies to actions and applies it to consumption — metering usage down to the specific agent, team, user, and model, and enforcing budgets at runtime, mid-session, on the exact segment that's running hot. The agent that's re-reading a codebase on every step gets throttled. The rest of the fleet keeps working. It's the difference between a bill and a meter, and it closes the one gap where "malicious" was never the right word for the damage being done.

Browser Protection and Expanded Claude Coverage: Following the Agent Wherever It Runs

The last two pieces answer a question the first two don't: what happens when the agent isn't running somewhere Operant already has a foothold? The browser has quietly become a runtime — agentic browsers now read pages, hold authenticated sessions, and act on instructions embedded in whatever they load, and the instruction-in direction is a channel most enterprise controls were never built to inspect. Operant Browser Protection puts the same allow/sanitize/block decision inline on that surface, in both directions, running through the same policy engine and audit trail as everything else.

Expanded Claude coverage does the equivalent for the surfaces that have no endpoint to install anything on at all — a Slack mention, a mobile chat, a hosted Cowork session running on infrastructure the enterprise doesn't own. Inference hooks bring real-time verdicts to the surfaces where Operant can't sit in the data path, and for Cloud Cowork specifically, agent-loop tracing goes further still — tracing plan steps, tool calls, file operations, and sub-agent spawns individually, because a prompt-and-response view of an agentic session shows you the beginning and the end with the plot missing.

Nothing We’re Announcing Here Is Just “On a Roadmap”

That's the thread that ties the day together. Every enterprise moving agents into production has been asked to accept some version of "the real-time layer is coming" — from providers whose own visibility tops out at an account-level bill, from browser vendors whose containers are binary and blind to the conversation inside them, from point tools that cover one surface and leave the next one dark. The honest answer to "when will this be real-time" has too often been later.

Today it's a description of what's already running: intent understood and enforced inline across tools, code, data, and scope; cost metered and capped at the moment the tokens are spent, not the moment the invoice arrives; the browser and every Claude surface — desktop, mobile, Slack, hosted — covered by the same policy set and the same audit trail. One control plane, reading the same thing — what the agent means to do — at every layer where it can act. That's not a promise for the next generation of agent security. It's what enterprises can put in front of their agents right now.

Reach out to us for a live demo and trial for any of these today!