Delegus Check
Test what your agent does when it’s told not to.
Give your AI agent a permission and a test server for one hour. Paste in our tasks, which push past the permission, and watch every tool call arrive with the decision, the reason and a test receipt you can check in your browser.
- 01Choose what it may touchCode, files, email or payments, and the limits.
- 02Add the test serverPaste its address into any agent that accepts a custom MCP server over HTTP.
- 03Give it the tasksA normal one, one that drifts, and one with a planted instruction. Then cancel the permission mid-task.
- 04Read what happenedWhat it tried, what was refused, and what it did next.
The test server’s tools do nothing real. Your agent can’t sign Delegus requests, so the test server signs for this session’s test agent and checks every call at the tool, with the same engine that answers /verify. Receipts here are test receipts. The session lasts an hour, and nothing is kept unless you share the report. To run the same checks on your own machine, see Delegus Test.
Step 1
What will your agent touch?
Pick one or more. Each comes with a permission you can adjust.
Step 2
The permission
The sentence says exactly what the rules below allow. Everything else is refused.
Step 3
Add this server to your agent
In your agent’s settings, add a custom MCP server with this address (streamable HTTP).
Then give it these tasks, one at a time
Step 4
Every tool call, as it happens
Nothing yet. Once your agent calls a tool, each call appears here with its decision.
Step 5
The report
Counts only: what your agent tried and what was refused. No score.