SaveMinute
Toolkit Privacy Open workspace
Security

A fence per run. A lease per secret.

Agents are useful when they can reach mail, money, and files. They are dangerous when that reach is vague. SaveMinute makes the reach explicit. If a run cannot name the door, the door stays shut.

Sandboxed agents

Each run gets a box: outbound hosts you listed, a folder for scratch files, and a spend cap. A skill may ask to widen the box. You approve that on the agent, not in a prompt mid-flight.

Dry run is the same box with live rails taped over. Good for clones you do not trust yet.

Secrets management

The vault holds tokens and signing keys. An agent asks by name. The desk grants a timed lease. The raw value does not land in the memory file as a quote.

Cut a lease from the workspace if a run looks odd. Revoke the secret if the rail should go dark for everyone.

Payment caps

Daily and per-vendor limits live on the agent. Crossing a cap pauses the send and writes an exception. People handle those. Agents do not talk themselves into a higher cap.

Logs you can read

Who borrowed which secret, which host was called, what got paid. Parallel runs keep separate logs so one messy clone does not muddy the clerk that still works.

Breakouts are a bug. If an agent needs more room, it asks the desk, not the internet.
Open workspace