Packstub.

Early access — Packstub Agents

AI agents in your admin panel that wait for approval — and survive the wait.

Packstub Agents connects Claude, Cursor, and any MCP client to your Filament panel behind capability grants. Writes become previewed approvals a human signs off on. Runs checkpoint, release the worker, and resume when you decide — hours later, across deploys, without replaying a single step.

Checked against grants
Previewed before writes
Audited forever
Running in production packstub.dev/mcp/admin

This transcript is real.

This store's own admin panel is operated through Packstub Agents today. The session shown here is a genuine exchange with our production endpoint: the agent token was granted one read tool and one write tool — nothing else exists as far as it can tell.

  • Ungranted tools are invisible and uninvokable — probes still get audited
  • The write never touched the database — it became a pending approval with a field-level diff
  • Approve or reject from your Filament panel; grants are re-checked at apply time
mcp session — packstub.dev/mcp/admin
tools/list
list-packages · granted read
update-package-storefront · granted write
call list-licenses
✖ Tool [list-licenses] not found · never granted — audited anyway
call update-package-storefront {summary: …}
⏸ proposed change → Pending Approval #1
nothing written · diff waiting for a human in /admin
audit: allowed · denied · pending_approval — 3 entries recorded

Working today

A governance layer, not another chat widget.

  • Capability grants. Per-token, per-tool, read / write / destructive. Explicit opt-in — a tool an agent isn't granted doesn't exist.
  • Preview → approve writes. Mutations become field-level diffs a human approves in Filament. Grants are re-validated at apply time; previous values are recorded.
  • Append-only audit trail. Every decision — allowed, denied, pending — with arguments redacted by rule. Hand it to a compliance officer.
  • Rate limits & redaction. Per-token request budgets and per-field redaction before anything leaves your app.
  • Filament-native control plane. Agent tokens, pending approvals, and the audit log live in your admin panel, not a separate dashboard.

Where early access is headed

Durable runs: agents that survive.

Queueing an agent is easy. Keeping a multi-step run alive is not: a retry replays the whole loop, a deploy kills it, and an approval either blocks a worker or dies waiting. Early access builds toward durable execution:

  • Step-per-job checkpoints. One queue job per step; a retry re-runs one step, never the loop. No re-spent tokens, no double writes.
  • Suspend on approval. A run that needs a human checkpoint releases the worker and resumes from the next step when you decide — hours or days later.
  • Deploy-proof. In-flight runs pick up where they left off after a restart or release.
  • Run inspector. Step timeline with tool calls, tokens, latency, and cost; retry, resume, or replay with a different model.
  • Budgets & tenancy. Token and cost ceilings per agent, user, or tenant — with first-class Packstub Tenancy integration.

Early access

Lock the early-access price.

Packstub Agents launches at the prices below. Early-access signups get the first builds, a direct line to the maintainers, and keep launch pricing for life. No payment now — we'll email you when your access is ready.

Solo

1 project · 12 months of updates

$149 one-time

Pro

Unlimited projects · updates while subscribed

$249 / dev / year

Which plan would you pick? (optional)

Only emails about Packstub Agents — nothing else, unsubscribe anytime. See our privacy policy.