AgentValet vs Tenure
Tenure and AgentValet share a lot of vocabulary: runtime enforcement, scoped agents, audit trails. They sit at different points in the call, and they aren’t really substitutes. Here’s where each one sits, and where each one wins.
Two approaches, in plain words
What Tenure is
Tenure is a self-hosted proxy that sits between your AI client and the model provider. You point your client’s base URL at it, and it does two jobs on the way through.
It manages governed memory: extracting beliefs from conversations and documents, merging them, flagging contradictions, and keeping memory scoped between teams, projects and users. And it checks consequential actions at the proxy, where it can allow, block or escalate them.
What AgentValet is
AgentValet is a broker on the platform call. It holds the credential for Slack, GitHub, Stripe or an MCP server, checks the agent’s grant and your rules on the real call, asks you first when a rule says so, and only then attaches the credential in memory.
It doesn’t manage what your model remembers or is shown. It manages what your agent can actually do.
The question that separates them
When the checked tool call comes back, whose key runs it?
With Tenure, the agent executes the approved call with keys it already holds. That’s the seam this comparison turns on: an agent with its own keys can act without asking, and any code path that doesn’t route through the proxy is outside its view.
A gateway only sees the traffic you route through it. That argument is usually made about gateways, and it holds one layer further down too.
- Your agent
- Tenure proxy checks context and tools
- Model
- Agent runs the call with its own keys (the key sits with the agent)
- Real platform
The keys stay with the agent. Take the proxy away and the governance goes with it, while the calls keep working.
- Your agent
- Any model
- Tool call
- Broker checks identity, grant and approval
- Credential attached in memory
- Real platform
The credential lives only in the vault. Take AgentValet away and the agent has nothing to call with.
What each one actually does
One line per cell. Open the detail underneath for the longer version.
| AgentValet | Tenure | |
|---|---|---|
| Where it enforces | On the platform call, where the broker attaches the credential. | On the model call, in a proxy between your client and the model provider. |
| Holds platform credentials | Yes, and the agent never sees them. | No, the agent keeps and uses its own keys. |
| What a bypass looks like | There isn’t a quiet one, because the agent has no key to call with. | Any call that doesn’t go through the proxy: a direct API call, a second code path, a key already in the environment. |
| Governed memory and context | Not a feature. | The core product, and genuinely good work. |
| Per-agent identity | A signing keypair per agent, so every call is attributable. | Token-authenticated agents within the proxy. |
| Human approval on a risky action | The call pauses at the broker until you approve it. | The proxy can allow, block or escalate an action, and the execution stays with the agent’s keys. |
| Audit trail | Append-only, with a signed receipt on every decision. | Tamper-proof audit of what passed through the proxy, as Tenure describes it. |
| Revocation | Revoke an agent and its next call fails closed, everywhere. | Removing proxy access doesn’t touch keys the agent already holds. |
| Deployment | Managed service; the parts on your machines are MIT open source. | Self-hosted by design, MIT licensed, with a Helm chart for teams. |
| Pricing | Priced on governed actions, not seats: free tier, paid plans from US$38 a month. | Free community edition; Small Team at US$25 per user per month, with a US$99 monthly minimum that includes four users. |
The detail behind 8 of these rows
- Holds platform credentials
AgentValet: Each credential is encrypted with its own key and decrypted in memory for one call, then dropped. It never reaches the agent, a log or a response.
- Governed memory and context
Tenure: Belief extraction and merging, contradiction flags, provenance, and memory scoped between teams, projects and users.
- Per-agent identity
AgentValet: Agents sign each request with their own RS256 key. Child agents can be issued their own short-lived identities, with scopes cut down to a subset of the parent’s and checked on every call.
- Human approval on a risky action
AgentValet: Approve with a passkey or email link on every plan, with push notifications on Team and above. The approved call then runs.
- Audit trail
AgentValet: Rows can be added, never edited or deleted, and they record what was executed, not only what was suggested. Receipts are signed ES256 and verifiable against a published key set.
- Revocation
AgentValet: Nothing was distributed, so there’s nothing to rotate. Revoking a parent agent stops its child agents on their next call too.
- Deployment
AgentValet: Hosted in Australia. The MCP server, command-line tool and adapters are MIT licensed.
- Pricing
Tenure: Tenure lists Pro (free) and Small Team as private beta, and Enterprise as a custom annual contract. All tiers are self-hosted.
Where Tenure genuinely wins
If your problem is what your agents remember and what context they’re fed, Tenure is built for that and AgentValet isn’t. Governed memory with provenance, belief merging across sessions and scoped isolation between teams is real, hard work, and no AgentValet feature replaces it.
Tenure is also self-hosted by design, so if nothing may leave your environment, their model fits and our managed broker doesn’t. And checking what the model sees before inference is a sound extra layer: fewer visible tools means fewer bad suggestions to catch later.
Where AgentValet wins
If your problem is what your agents can actually do, enforcement has to live where the action happens. AgentValet holds the credential, so the scope check, your approval and the audit row happen on the real call, and a compromised agent has no key of its own to fall back on.
Identity is per agent, revocation is immediate because nothing was handed out, and the record shows what was executed. None of it depends on which model, framework or proxy you use upstream.
The two stack. Govern context and suggestions at the model with Tenure if you like the approach, and put the keys behind a broker either way. They never touch the same seam.
Which one fits
Choose Tenure if
- Your main worry is what the model remembers and is shown.
- Everything must be self-hosted.
- Your agents’ keys are already locked down some other way.
Choose AgentValet if
- Your agents hold real keys to Slack, GitHub, Stripe or your mail.
- You want to say yes or no to a risky action before it runs.
- You need a record of what was executed, with a receipt you can check.
Run both if
- You want governed memory on the model side and no keys on the agent side.
- Different people own context quality and access control.
Checked against tenureai.dev, Tenure pricing and the Tenure GitHub README on 24 September 2026. If something has changed, report a correction and we’ll fix the page.
Try to make an ungoverned call.
Register one real agent on the free plan with npx @agentvalet/register, grant it one scope, then try to reach anything else. You’ll see the refusal, and the row it leaves behind.
npx @agentvalet/register