AI software change control · Built in Sweden

Move faster with AI-generated code—without surrendering control.

alienctl turns an observed AI coding session into a customer-owned decision: proceed, stop for missing evidence, or request human approval.

Local/BYOC · Agent-neutral · Buyer-controlled evidence · No hosted dashboard required

What is alienctl?

The customer-owned control and evidence layer for AI-produced software changes.

Runtime guardrails control what an agent may do. Enterprise governance platforms oversee AI risk. alienctl answers the engineering question between them: does this resulting change have enough evidence and approval to proceed?

The control gap

The diff is visible. The run behind it often is not.

AI-generated pull requests can reach reviewers without a reliable answer to four basic questions:

  • What was the agent authorized to change?
  • Which files and sensitive surfaces did it touch?
  • Which verification actually ran?
  • What evidence or approval is still missing?

How it works

One local control loop before human review.

No agent wrapper. No new dashboard. No replacement for CI.

  1. 01

    Observe

    Bracket the local AI-agent session and record repository changes.

  2. 02

    Check

    Evaluate declared verification, policy boundaries, and sensitive surfaces.

  3. 03

    Decide

    Tell the reviewer to begin, block for evidence, or request approval.

  4. 04

    Retain

    Archive the receipt and explicit gaps for later reconstruction.

The operating rule

No valid Run Control Receipt.
No AI-agent PR review.

A failed receipt stops unready work before reviewer time is spent—not after the change has already been treated as reviewable.

One receipt, clearer decisions

Useful to every owner of the review boundary.

01

Engineering leaders

Scale AI-assisted delivery without making agent activity invisible.

02

Security

See sensitive changes, policy violations, and approval gaps before review.

03

Platform engineering

Use a local/BYOC, machine-readable gate inside buyer-owned workflows.

04

Reviewers

Know whether to begin review without reconstructing raw agent chat.

The missing engineering layer

Runtime control, review control, and enterprise governance solve different problems.

01

Runtime guardrails

Decide whether an agent action or tool call may execute.

02

alienctl review control

Decide whether the resulting software change has enough evidence and approval to begin review.

03

Enterprise governance

Oversee AI assets, organizational risk, controls, compliance, and business outcomes.

alienctl complements these layers. It does not replace runtime policy, CI, code review, or enterprise GRC—and it does not prove code correctness.

European operational sovereignty

Keep control of the workflow, evidence, and exit path.

Swedish-built for European engineering organizations that need vendor independence without abandoning the AI tools their teams prefer.

Customer-controlled

The current pilot runs locally or in buyer-owned infrastructure. Evidence stays under the buyer’s control.

Agent-neutral

Build the review boundary around the resulting change instead of committing governance to one coding agent.

Portable evidence

Retain machine-readable receipts and explicit gaps without requiring an alienctl-hosted dashboard.

Operational sovereignty is a deployment and control property—not a claim of regulatory compliance, legal immunity, or software correctness.

Two-week design-partner pilot

Test the rule on one real AI-agent workflow.

The pilot is for teams already using AI agents in a repository where review ambiguity or sensitive changes matter.

What we define together

  • One repository, owner, and reviewer
  • Required verification commands
  • Sensitive surfaces and approval rules
  • A buyer-controlled evidence archive
  • A pass, expand, integrate, or stop decision

For two weeks, failed receipts block review as ready.

Practical guidance

Build a review boundary your team can actually enforce.

Field guides for engineering, security, and platform teams governing AI-generated changes.

Frequently asked questions

The short answers.

Is alienctl a European alternative to US coding agents?

No. alienctl is an agent-neutral control and evidence layer, not a coding model or assistant. European teams can keep their preferred agents while retaining the review decision and evidence in their own environment.

What is AI-agent change control?

It is a workflow for checking an agent’s authorized scope, observed repository changes, declared verification, sensitive surfaces, and evidence gaps before human code review begins.

What is a Run Control Receipt?

A reviewer-readable record of a bounded AI-agent run. It shows what changed, what checks ran, which policy boundaries applied, what blocks review, and what remains unproven.

Does alienctl replace CI or code review?

No. CI checks code and builds, while human reviewers judge the change. alienctl provides a pre-review decision about whether the run has enough evidence and approval to begin review.

Does alienctl send source code to a hosted service?

The current pilot is local and buyer-controlled. It does not require a hosted dashboard, third-party analytics, or alienctl-managed credentials.

Can alienctl prove AI-generated code is correct?

No. alienctl records bounded-run evidence and explicit gaps. It does not prove code correctness, production safety, compliance, or ROI.

Who is the pilot for?

CTO, CISO, platform, AppSec, developer-productivity, and engineering teams already using AI agents in a repository with a real review or security control problem.

What happens during the two-week pilot?

We define one repository, its required verification, sensitive surfaces, owners, and archive. The team then requires a valid receipt before each meaningful AI-agent change begins human review.

Design-partner application

Make your next AI-agent review decision explicit.

Tell us where AI-generated changes create review or security ambiguity. We will reply personally to assess whether a one-repo pilot is a fit.

Apply for a one-repo pilot No mailing list. No automated sales sequence. A direct conversation.