Sallyport and Britive
Per-call approval for MCP tool calls, and only for MCP tool calls.
Britive comes from just-in-time cloud access and has brought a real approval step to agent tool calls. Time-boxed grants and continuous evaluation signals sit behind it. On MCP they are one of the few vendors doing the thing we do.
| Them | Sallyport | |
|---|---|---|
| Per-call human approval | MCP tool calls | MCP, HTTP and SSH, one policy across all three |
| Arbitrary HTTP host | No | Yes, through the reverse proxy |
| SSH with per-call approval | No | Yes, and the executor holds no private key |
| Time-boxed grants | Yes | Yes, checked at the boundary of every call |
| Tamper-evident journal | Logging | Hash-chained, sealed, with an open verifier |
Where they are ahead
Cloud entitlement depth. If your agents mostly need short-lived roles in AWS, Azure and GCP, that is their home ground and they have been on it for years.
Where the difference is
Agents do not stay inside one protocol. The same agent opens a pull request, calls a payment API and restarts a service over SSH in the same session. One broker across the three keeps one policy, one approval inbox and one journal instead of three.