Priced per agent you actually govern
Not per seat, and not per token. You pay for the agents Warden is authorising and the decisions it makes on their behalf — so the bill tracks the risk you moved under control, not how many people opened a dashboard.
Design Partner
For teams already running agents with write access who want the control plane in front of them now, and are willing to shape it.
- Up to 5 agents, 1 environment
- Warden Cloud, shared inference fleet
- Full policy engine, approvals and audit ledger
- Weekly working session with the engineering team
- Locked preferential pricing at general availability
Team
For a platform or security team putting the first fleet of production agents under a single, enforced policy.
- Up to 25 agents, unlimited environments
- 5M decisions per month included
- MCP proxy, tool-call gateway and egress broker
- Behavioural baselines and nightly red-team runs
- Slack, Teams and PagerDuty approval routing
- SIEM export with full decision context
- Google and Microsoft SSO
Enterprise
For organisations that cannot send prompt content to a vendor, or that are governing agents across many business units.
- Unlimited agents and decision volume
- Self-hosted inference in your VPC, or fully air-gapped
- Dedicated GPU capacity for the guard models
- SAML SSO, SCIM provisioning, custom roles
- Policy-as-code pipelines and simulation against your own traffic
- Evidence packs for NIST AI RMF, EU AI Act and SOC 2 audits
- Named engineer, 24/7 incident line, contractual SLA
Warden is in private preview. These figures are indicative and will be confirmed at general availability — design partners keep the pricing they start on. Prices exclude tax.
The controls are not the upsell
Security features that only appear in the top tier are how breaches happen at everyone below it. Every plan gets the whole enforcement path.
Full policy engine
Identity, data-class scope, spend caps, blast radius and egress control — the same engine in every plan.
Human-in-the-loop holds
Any action can be held for an owner rather than allowed or blocked outright, on every tier.
Tamper-evident ledger
Hash-chained, signed decision records with full replay. Retention is what differs between plans, not the record.
Guard models inline
Injection, sequence and PII models run on every decision. There is no cheaper tier that skips the inference.
Kill switch
Freeze one agent, one tool or the whole fleet from the console or one API call.
Simulation mode
Run a new policy against yesterday’s traffic before you enforce it. Included everywhere.
Before you ask us
What counts as an agent?
What counts as a decision?
What happens if we go over the included volume?
Why is self-hosted inference Enterprise-only?
Can we start on Design Partner and move up?
Do you offer a free trial?
Start with the agents that can cost you something.
Tell us what your agents are allowed to do today. If a design-partner slot fits, we will say so; if it does not, we will tell you that too.