NORNR
Control layer between intent and settlement.
Control layer for autonomous spend
One governed laneControl autonomous spend before it becomes real.
NORNR sits between agent intent and real settlement. It returns a policy decision before money moves, binds mandate and counterparty to the same path, and keeps one defended record alive through receipt trail and audit export.
Start repo-first by default. Switch only when buyer proof or shadow proof gets to one defensible lane faster.
browser-use/browser-use should start with one browser checkout lane.
Launch preview already names the first consequential seam, the smallest first patch and the next screen worth opening. Full audit confirms the exact files and packet.
A vendor-side request often becomes consequential at the final request or checkout step.
Upload one usage export. See the wasted spend before engineering installs anything.
Spend Audit is the business-side first move: one OpenAI or Stripe export, one ambient-spend readout, one suspicious pattern summary and one next lane to install back in engineering.
Use a usage export the team already has instead of asking for runtime changes first.
Name recurring waste, vendor sprawl and the one lane that needs control first.
Send one buyer-safe packet to engineering or finance after the value exists.
Connect one existing flow in shadow and get the 2-minute report first.
Shadow Connect is the breakout wedge when the team already runs agents: no blocking, no silent enforcement, just a concrete shadow report that says where the action would have become real, what NORNR would have queued, and which one lane should install next.
Keep the runtime and start with one shadow-only ingress.
Name the consequential boundary, the likely queue point and the defended record still missing today.
Email the shadow report, then use Weekly Risk Pulse as the returning artifact before full install.
Moment of truth
An agent attempts a $240 vendor action. The question is whether it may clear.
This is the real product moment: judge the action before settlement, attach the reason immediately, and keep one defended record alive afterward.
The action executes. The explanation comes later, if it comes at all.
The agent calls the final provider or checkout step with no lane-scoped decision surface in front of it.
The cost becomes real before anyone evaluates mandate, counterparty scope or approval need.
Ops, finance and engineering now have rows and logs, but not one defended record that explains why the action was legitimate.
The same action becomes a judged path before money moves.
The action hits a reviewed boundary that knows owner mandate, threshold posture and allowed counterparties.
NORNR approves, queues or blocks before settlement, with a plain-language reason and one next owner action.
The same defended record carries the decision into replay, packet, receipt trail and audit export without rewriting the story.
One clear flow from intent to defended export.
No-signup first value
See the first defended path before we ask for an account.
Repo signals only, no blocking yet. But the page should still hand back three useful things now: one shadow read, one install path and one packet path worth keeping.
NORNR would stage one decision before the path becomes real.
Show the first consequential step, the likely decision posture and the calmest next move without forcing enforcement first.
The first trust step is simple: show what NORNR would have judged.
One lane, one framework, one first outcome.
Hand back one installer path that fits the lane, not a broad platform tour.
Why buyers move
When agents can trigger real spend, the hard part is deciding what may clear.
Without a control layer, teams inherit cost, counterparties and approvals they cannot explain later from one record.
Best fit
Start with one lane. Widen only after the first defended record is live.
- Start with browser checkout or one governed runtime call.
- Name one owner, one counterparty scope and one packet path before widening.
- Add MCP review, finance close and portfolio control after the first lane works cleanly.
Control plane
Start with one lane. Add the broader control stack later.
Start with browser checkout or one governed runtime path. Add MCP review and finance close only after the first lane is already defensible.
Intent hits one governed lane
An agent submits one consequential vendor or tool action.
NORNR returns a verdict
Approved, queued or blocked before settlement, with the reason attached.
The same record survives later
Decision, approval, receipt trail and export stay attached to the same action.
Governed runtime
Make one consequential tool call or paid action policy-aware before it executes.
policy decision · mandate · receipt trailBrowser checkout governance
Pause risky click-through, vendor checkout and browser-side purchases before the action completes.
checkout review · anomaly posture · counterparty stateMCP control server
Carry the same review model into Claude Desktop, Cursor or Agent Zero once the first lane is already defensible.
local tools · queued review · finance-safe request trailFinance close packet
Produce the packet finance receives, signs, retains and exports from the governed trail itself.
audit export · finance packet · close bundlePortfolio controller
Show which lane is overspending, overloaded in review or not yet ready to widen beyond pilot.
portfolio posture · review pressure · rollout readinessBuyer Proof
One governed action should already produce proof someone else can trust.
The same path should show intent, decision, approval, settlement and export posture without forcing finance or ops to reconstruct the story later.
Live governed settlement completed
0xf8ff5d333d1bdaf932673314853e02406f1ce3e73e0c782ec5e3c007526fe927
Intent evaluated, released under mandate and locked into a provable receipt trail.
The request crossed threshold and counterparty review before settlement
The same record keeps the threshold breach, anomaly context, approval reason and release state attached instead of splitting them into side systems.
Finance receives signed proof and close artifacts without manual cleanup
Artifacts persist to object storage, resolve through artifacts.nornr.com and stay ready for finance handoff as one defensible packet.
Decision, review and finance close resolve from the same governed record
The SDK is one entry point. The product value is that the same control plane governs spend, routes review and hands finance a defensible export afterward.
Founding Cohort
Best fit for teams already close to real agent spend.
We are looking for near-production workflows in browser checkout, governed runtime spend, or local-tool control where policy, review and finance evidence must hold outside the demo.
Apply
Tell us the first lane you need to govern.
Best fit if agents are already close to browser checkout, vendor APIs or runtime spend in production-like workflows. We review asynchronously and only take teams with one concrete lane first.