AgentValet vs Tenure

Tenure and AgentValet share a lot of vocabulary: runtime enforcement, scoped agents, audit trails. They sit at different points in the call, and they aren’t really substitutes. Here’s where each one sits, and where each one wins.

Two approaches, in plain words

What Tenure is

Tenure is a self-hosted proxy that sits between your AI client and the model provider. You point your client’s base URL at it, and it does two jobs on the way through.

It manages governed memory: extracting beliefs from conversations and documents, merging them, flagging contradictions, and keeping memory scoped between teams, projects and users. And it checks consequential actions at the proxy, where it can allow, block or escalate them.

What AgentValet is

AgentValet is a broker on the platform call. It holds the credential for Slack, GitHub, Stripe or an MCP server, checks the agent’s grant and your rules on the real call, asks you first when a rule says so, and only then attaches the credential in memory.

It doesn’t manage what your model remembers or is shown. It manages what your agent can actually do.

The question that separates them

When the checked tool call comes back, whose key runs it?

With Tenure, the agent executes the approved call with keys it already holds. That’s the seam this comparison turns on: an agent with its own keys can act without asking, and any code path that doesn’t route through the proxy is outside its view.

A gateway only sees the traffic you route through it. That argument is usually made about gateways, and it holds one layer further down too.

Tenure enforces at the model call
  1. Your agent
  2. Tenure proxy checks context and tools
  3. Model
  4. Agent runs the call with its own keys (the key sits with the agent)
  5. Real platform

The keys stay with the agent. Take the proxy away and the governance goes with it, while the calls keep working.

AgentValet enforces at the platform call
  1. Your agent
  2. Any model
  3. Tool call
  4. Broker checks identity, grant and approval
  5. Credential attached in memory
  6. Real platform

The credential lives only in the vault. Take AgentValet away and the agent has nothing to call with.

What each one actually does

One line per cell. Open the detail underneath for the longer version.

AgentValet compared with Tenure
AgentValetTenure
Where it enforcesOn the platform call, where the broker attaches the credential.On the model call, in a proxy between your client and the model provider.
Holds platform credentialsYes, and the agent never sees them.No, the agent keeps and uses its own keys.
What a bypass looks likeThere isn’t a quiet one, because the agent has no key to call with.Any call that doesn’t go through the proxy: a direct API call, a second code path, a key already in the environment.
Governed memory and contextNot a feature.The core product, and genuinely good work.
Per-agent identityA signing keypair per agent, so every call is attributable.Token-authenticated agents within the proxy.
Human approval on a risky actionThe call pauses at the broker until you approve it.The proxy can allow, block or escalate an action, and the execution stays with the agent’s keys.
Audit trailAppend-only, with a signed receipt on every decision.Tamper-proof audit of what passed through the proxy, as Tenure describes it.
RevocationRevoke an agent and its next call fails closed, everywhere.Removing proxy access doesn’t touch keys the agent already holds.
DeploymentManaged service; the parts on your machines are MIT open source.Self-hosted by design, MIT licensed, with a Helm chart for teams.
PricingPriced on governed actions, not seats: free tier, paid plans from US$38 a month.Free community edition; Small Team at US$25 per user per month, with a US$99 monthly minimum that includes four users.
The detail behind 8 of these rows
Holds platform credentials

AgentValet: Each credential is encrypted with its own key and decrypted in memory for one call, then dropped. It never reaches the agent, a log or a response.

Governed memory and context

Tenure: Belief extraction and merging, contradiction flags, provenance, and memory scoped between teams, projects and users.

Per-agent identity

AgentValet: Agents sign each request with their own RS256 key. Child agents can be issued their own short-lived identities, with scopes cut down to a subset of the parent’s and checked on every call.

Human approval on a risky action

AgentValet: Approve with a passkey or email link on every plan, with push notifications on Team and above. The approved call then runs.

Audit trail

AgentValet: Rows can be added, never edited or deleted, and they record what was executed, not only what was suggested. Receipts are signed ES256 and verifiable against a published key set.

Revocation

AgentValet: Nothing was distributed, so there’s nothing to rotate. Revoking a parent agent stops its child agents on their next call too.

Deployment

AgentValet: Hosted in Australia. The MCP server, command-line tool and adapters are MIT licensed.

Pricing

Tenure: Tenure lists Pro (free) and Small Team as private beta, and Enterprise as a custom annual contract. All tiers are self-hosted.

Where Tenure genuinely wins

If your problem is what your agents remember and what context they’re fed, Tenure is built for that and AgentValet isn’t. Governed memory with provenance, belief merging across sessions and scoped isolation between teams is real, hard work, and no AgentValet feature replaces it.

Tenure is also self-hosted by design, so if nothing may leave your environment, their model fits and our managed broker doesn’t. And checking what the model sees before inference is a sound extra layer: fewer visible tools means fewer bad suggestions to catch later.

Where AgentValet wins

If your problem is what your agents can actually do, enforcement has to live where the action happens. AgentValet holds the credential, so the scope check, your approval and the audit row happen on the real call, and a compromised agent has no key of its own to fall back on.

Identity is per agent, revocation is immediate because nothing was handed out, and the record shows what was executed. None of it depends on which model, framework or proxy you use upstream.

The two stack. Govern context and suggestions at the model with Tenure if you like the approach, and put the keys behind a broker either way. They never touch the same seam.

Which one fits

Choose Tenure if

  • Your main worry is what the model remembers and is shown.
  • Everything must be self-hosted.
  • Your agents’ keys are already locked down some other way.

Choose AgentValet if

  • Your agents hold real keys to Slack, GitHub, Stripe or your mail.
  • You want to say yes or no to a risky action before it runs.
  • You need a record of what was executed, with a receipt you can check.

Run both if

  • You want governed memory on the model side and no keys on the agent side.
  • Different people own context quality and access control.

Checked against tenureai.dev, Tenure pricing and the Tenure GitHub README on 24 September 2026. If something has changed, report a correction and we’ll fix the page.

Try to make an ungoverned call.

Register one real agent on the free plan with npx @agentvalet/register, grant it one scope, then try to reach anything else. You’ll see the refusal, and the row it leaves behind.

npx @agentvalet/register