Open-source coding agent Kortix Suna gates merges behind explicit permission grants, discloses no insurance terms
The agent runs unattended on cron schedules and webhooks but requires a human-approved config change before it can widen its own access. SOC 2 audits are in progress, not complete.
Kortix, maker of the open-source AI agent Suna, publishes a permission model that requires an explicit, human-approved configuration change before the agent can expand what it is allowed to do, according to the company's website.
"Merge is default-deny for an agent and granted explicitly in kortix.yaml — so an agent cannot widen its own reach without a change someone else approves," the company states. Individual actions are gated the same way: permissions can be set to "allow, ask or block — down to the arguments it was given," and a sample runtime policy published on the site reads: "permission: edit: allow bash: git push: deny '*': allow."
The agent can act without a person initiating the session. "Cron schedules and signed webhooks start sessions with no one asking," Kortix states — a capability the company pairs with the merge-gating described above rather than leaving unattended.
Kortix says the agent connects to "3,000+ apps in a click, plus MCP, OpenAPI, Postman, GraphQL and raw HTTP," and is model-agnostic, connecting to Anthropic, OpenAI and Google models or a customer's own OpenAI-compatible endpoint. The product is open source and can be self-hosted for free or run as a managed service at "$40 / seat / mo + usage," per the company's pricing page.
On compliance, Kortix states two SOC 2 audits are underway but not complete: "SOC 2 TYPE I In progress SOC 2 TYPE II In progress GDPR." AI Dispatch records this as an in-progress claim, not a certification, because no completed audit or report date is published.
The company's pages disclose no information on insurance availability, named carriers, coverage limits, indemnification or liability caps for the service itself — four of the categories AI Dispatch tracks under its trust-gap rubric at aidispatch.news/methodology. That leaves the runtime permission system, not any insurance or indemnity backstop, as the sole disclosed control on what an unattended, cron-triggered coding agent can do to a customer's systems. All statements above are drawn from the vendor's own published material.
Entries in this piece 1
Published index entries backed by the same source documents this piece cites.
Sources 7
“Merge is default-deny for an agent and granted explicitly in kortix.yaml — so an agent cannot widen its own reach without a change someone else approves.”
www.suna.so · checked Aug 7, 2026“allow, ask or block — down to the arguments it was given”
www.suna.so · checked Aug 7, 2026“permission: edit: allow bash: git push: deny '*': allow”
www.suna.so · checked Aug 7, 2026“Cron schedules and signed webhooks start sessions with no one asking”
www.suna.so · checked Aug 7, 2026“3,000+ apps in a click, plus MCP, OpenAPI, Postman, GraphQL and raw HTTP”
www.suna.so · checked Aug 7, 2026“Self-host for free, or managed cloud at $40 / seat / mo + usage.”
www.suna.so · checked Aug 7, 2026“SOC 2 TYPE I In progress SOC 2 TYPE II In progress GDPR”
www.suna.so · checked Aug 7, 2026