Agents do what you allow. Everything is on the record.
Baton sits between your team and your agents. It decides what an agent may do alone, what needs a person, and it writes down who asked for every action.
Allow, Ask or Never, per project
Set what agents may do alone: run tests, deploy to staging, push a branch, change dependencies, deploy to production, touch main. Ask turns the action into an approval. Never is a hard stop.
One owner per approval
Any approver can claim a request. Once claimed, only they can approve or deny it.
Every action says who asked
Agent work is credited to the person who requested it, in the session, the audit log and usage.
Previews are isolated
Each dev server gets its own database, KV and secrets scope, and is torn down when the branch merges.
Audit log · larkline
Example audit log: every agent action is recorded with who asked for it and whether it was allowed, sent for approval, approved, blocked or denied.
Your server, your code
With your own servers, code and previews stay on them. baton-runner only sends session events and logs you choose to share.
Model keys stay with you
Agents use your own model keys or subscriptions. Baton never proxies prompts.
SSO and SCIM
Available on Enterprise, with role mapping to Owner, Maintainer, Developer and Reviewer.
Audit export
Stream the audit log to your SIEM or download it as JSON.