■ Runtime safety layer for AI agents
Let agents touch prod.
Keep the undo.
Unhappen sits between AI agents and your systems. Reversible actions roll back in one command. Irreversible ones are stopped before they run.
or write to hi@unhappen.dev
Why now
9 s
Coding and DevOps agents now hold write access to real databases, repos and cloud accounts. When they get it wrong, they get it wrong fast.
- Apr 2026
A coding agent hit a credential mismatch in staging, found an over-scoped API token and deleted a startup's production volume with one API call. Backups lived on the same volume. It took 9 seconds.
Source: GIGAZINE ↗ - Jul 2025
During an explicit code and action freeze, an AI app builder's agent deleted a live production database with records for more than 1,200 executives and 1,190 companies.
Source: Fortune ↗
Observability tells you after the fact. Built-in agent checkpoints restore local files, not your database or your cloud. Nothing in between catches the action itself.
Two modes. Every action lands in one.
01 — HAS STATE
Reversible → rolled back
Files, git, Postgres, Terraform. We snapshot exactly what the agent is about to touch, let it run, and record a semantic diff. One command undoes the whole session.
02 — LEAVES THE BUILDING
Irreversible → stopped
Deleting volumes and backups, sending email, moving money, calling external APIs. Blocked by policy, or held until a human says yes.
agent --> unhappen --> reversible? -- yes --> snapshot --> run --> semantic diff --> session journal | +-- no --> policy --+-- dangerous --> stop, or ask a human | +-- safe -------> run
What the agent touches
- Files and gitRollbackSnapshot of the working copy; commits and branches restored
- Postgres — Supabase, NeonRollbackSnapshot or branch of the touched tables before the change
- TerraformRollbackState captured before apply, restored through IaC
- Deleting volumes, backups, whole databasesStopBlocked by policy or confirmed by a human
- Email, payments, messages, external APIsStopBlocked or confirmed before anything is sent
- SaaS — Notion, HubSpot, SalesforceRollback · laterInverse actions through the system's own API
How we sit in the path
- 01
Agent hooks — Claude Code and Cursor show us every tool call before it runs
- 02
MCP gateway — every MCP tool the agent uses goes through us
- 03
CLI wrappers — psql, terraform, kubectl, aws, gcloud for agents in terminals and CI
A neutral layer across every agent and every system.
| Stops before it runs | Rolls back databases & cloud | Works across agents | No backup platform to adopt | |
|---|---|---|---|---|
| ObservabilityLangSmith, Langfuse, BraintrustTraces and evaluates — after the fact | no | no | yes | yes |
| RubrikAgent Rewind + Agent IdentityEnterprise, runs on Rubrik Security Cloud | yes | yes | yes | no |
| CommvaultAI ProtectMonitors and reverts, can't stop third-party agents | no | yes | yes | no |
| MCP gateways & guardrailsPolicy on tool callsMCP calls only — no snapshots, no undo | yes | no | yes | yes |
| Built-in agent checkpointsClaude Code, Cursor, CodexGreat for local files, one agent at a time | yes | no | no | yes |
| UnhappenHooks + MCP gateway + CLI wrappersTarget: installs in an hour, starts in watch-only mode | yes | yes | yes | yes |
Sources:Commvault AI Protect — The Register ↗Rubrik Agent Rewind — Computerworld ↗Rubrik Agent Identity — SiliconANGLE ↗
Founder
Dmitrii Novikov
Dmitrii builds developer tools for AI agents and ships them end to end — CI, releases for Homebrew, Scoop, PyPI and GitHub Actions. Unhappen is built on his open-source work: mcpxray classifies dangerous agent actions, datadiff explains exactly what changed.
mcpxray ↗
v1.0 · 254 tests
Security linter and 0–100 scorecard for MCP servers, mapped to the OWASP MCP Top 10, with opt-in runtime capture of tools.
→ classifies dangerous actions
datadiff ↗
100,000 objects in 0.4 s
Semantic diff for JSON, YAML, CSV, TOML and XML, written in Rust. Ignores key order and formatting, reports changes as data paths.
→ explains what changed
skillcraft ↗
PyPI · drift checks in CI
Lint, sync and scaffold for agent configs — CLAUDE.md, AGENTS.md, SKILL.md, Cursor rules, Copilot instructions.
→ knows the agent ecosystem