1.3: One switch on every enforced path, and the CLI on npm#
8 October 2026
- Stop agent stops every enforced path. A stopped agent is refused on model calls, token counts, every MCP proxy method and plain HTTP upstreams, with nothing reaching the provider. “Stop every agent” also refuses person, service and admin keys on the gateway. Through builders and SDKs it is still a check the agent’s code asks for. The kill switch.
- The CLI on npm.
npx immiscible tryruns the demo on your own machine, offline and with no account;npx immiscible verifychecks a receipt.npx immiscible initsets up the agent, its rule,.envand the Claude Code hook. - Set up by your AI agent. Tell a coding agent “Set up Immiscible for this project”: For AI agents and llms.txt give it the steps, and a person allows the sign-in once.
- A sample workspace with something in it. “Open the sample workspace” opens Amethyst, the demo company, with its agents, its spend and three requests waiting for a person.
- Google and Microsoft sign-in, first on the sign-up and sign-in pages wherever a deployment has switched them on.
- Pricing by governed agents, not people. People are free on every paid plan, and watching is free and unlimited. Free covers 3 governed agents and 5 people; Team is £39 a month billed yearly with 10 agents; Business is £499 a month billed yearly with 100 agents, SCIM and ten years of records; Enterprise, for regulated firms, is priced with you. Billing shows how many agents you governed this month; it enforces nothing yet, and we tell you before anything changes. Startups can apply for half price for 12 months. Pricing.
1.2: Integrations, SCIM and approvals in Slack#
5 October 2026
- Integrations without pasting keys. One page in the console lists every integration, whether it is connected and what to do next. OpenRouter, MCP servers, Ramp, Xero, QuickBooks and PagerDuty connect with OAuth sign-in, GitHub through the GitHub App and Microsoft Teams through the Teams app. OpenRouter, Ramp, MCP.
- SCIM and directory sync. Okta, Microsoft Entra ID or any SCIM 2.0 client can add, update and remove members and teams. Deactivating someone ends their membership, revokes their keys, agent keys included, and signs out their sessions and phones in the same request. Google Workspace and Entra can be read on a schedule instead.
- Slack App Home. The Immiscible tab in Slack shows what is waiting for you, your digest settings and a freeze button for any agent.
- A clearer public site. Every public page now shares one design, with type served from our own domain, so the site makes no third-party requests. The homepage has a sample approval queue to try, four real decisions from the policy engine, and a receipt your browser can check for itself.
1.1: Agents, Verify and personal workspaces#
September 2026
Immiscible now governs what AI agents do, not only what AI spend buys. The same three ideas carry over: a mandate is a budget for actions, the gate is pre-flight enforcement, and the receipt is an evidence record someone else can check.
- Agents. Register the agents that act for you or your company (ChatGPT, Claude, Gemini or your own; Muse when Meta opens it), each with its own agent key. An agent holds no card number and no password; it asks Immiscible each time it needs something. A kill switch freezes an agent’s actions and its inference in one tap. Overview and threat model.
- Mandates. Standing authority for payments, data releases and other actions, with per-transaction and per-period limits, merchant allow and block lists, approval thresholds and expiry. Signed when created. Mandates.
- The gate.
POST /v1/actions/authorizereturns allow, deny or approval required, with reasons in plain English. Risk signals include the Rule of Two, lookalike domains, injection language and velocity. Missing provenance counts as untrusted, and anything that cannot be decided is denied. - Approvals. A person is asked when a mandate says so or when the request looks risky, whatever the mandate says. One tap to approve or deny, from email or the console. Approvals.
- The vault. Personal details sealed per workspace and per field, released only to the recipient a mandate allows. Passport, national ID, bank, card and health fields always need a person unless a mandate names the field and the recipient.
- Receipts and Verify. Every allowed action carries an Ed25519-signed receipt. Merchants and payment providers can check one free at
/v1/verify, or offline against the keys at/.well-known/immiscible-keys.json. Receipts and Verify. - MCP server and Claude Code hook. Connect any agent that supports remote MCP servers at
/mcp, or put a PreToolUse hook in front of every Claude Code tool call. MCP, the hook. - Sensitive data in prompts. The gateway now finds card numbers, IBANs, National Insurance numbers, SSNs, emails and phone numbers before a prompt leaves, and records, redacts or blocks them as you choose. DLP.
- Personal workspaces. Personal is free for 2 agents and 3 mandates. It takes no share of anything your agents buy, and nor does any team plan. New consumer terms cover it.
- Team and Scale now include agent governance for every governed seat.
Not in this release, and said plainly: Immiscible is not yet a Muse connector (we have applied to Meta’s programme) and does not issue virtual cards. OAuth sign-in for connectors followed in 1.2. See Muse and personal agents.
1.0: Launch#
September 2026
The first generally available release of Immiscible.
- Hosted workspaces. Sign up, invite your team, and govern traffic in ten minutes. Five roles: owner, admin, analyst, auditor, member.
- Shadow mode, and the assessment. Every workspace starts observing only. The Assessment view turns shadow traffic into findings: what routing would have saved, priced on your real token counts; where every request’s data went; how much spend could not be attributed.
- Native passthrough and streaming. Claude Code, Cursor, Cline and every SDK work unchanged. Tool use, prompt caching, extended thinking and streaming pass through intact; requests that carry tools are only routed to models that speak their protocol.
- Sessions become tasks. Claude Code sessions and chat conversations are grouped into tasks automatically, so yield means something without instrumentation.
- GitHub outcomes. Merged pull requests report themselves as outcomes.
- Bring your own keys. Provider keys are sealed per workspace. We never resell inference.
- Durable evidence. The hash-chained ledger is written to disk before each response returns, and verifiable from the console or the API at any time.
0.9: Design-partner build#
September 2026
Four-axis routing, yield-scaled budgets, the waste decomposition, the evidence ledger, jurisdiction-aware policy profiles, aggregator and cloud-marketplace upstreams, committed-spend modelling, and hosted-agent reconciliation.