■ Runtime safety layer for AI agents

Let agents touch prod.
Keep the undo.

Unhappen sits between AI agents and your systems. Reversible actions roll back in one command. Irreversible ones are stopped before they run.

or write to hi@unhappen.dev

FIG. 1 — AGENT SESSION
FIG. 2 — WHY NOW

Why now

9 s

Coding and DevOps agents now hold write access to real databases, repos and cloud accounts. When they get it wrong, they get it wrong fast.

  1. Apr 2026

    A coding agent hit a credential mismatch in staging, found an over-scoped API token and deleted a startup's production volume with one API call. Backups lived on the same volume. It took 9 seconds.

    Source: GIGAZINE ↗
  2. Jul 2025

    During an explicit code and action freeze, an AI app builder's agent deleted a live production database with records for more than 1,200 executives and 1,190 companies.

    Source: Fortune ↗

Observability tells you after the fact. Built-in agent checkpoints restore local files, not your database or your cloud. Nothing in between catches the action itself.

FIG. 3 — HOW IT WORKS

Two modes. Every action lands in one.

01 — HAS STATE

Reversible → rolled back

Files, git, Postgres, Terraform. We snapshot exactly what the agent is about to touch, let it run, and record a semantic diff. One command undoes the whole session.

02 — LEAVES THE BUILDING

Irreversible → stopped

Deleting volumes and backups, sending email, moving money, calling external APIs. Blocked by policy, or held until a human says yes.

FIG. 3a — DECISION PATH FOR EVERY TOOL CALL
agent --> unhappen --> reversible? -- yes --> snapshot --> run --> semantic diff --> session journal                            |                            +-- no --> policy --+-- dangerous --> stop, or ask a human                                                |                                                +-- safe -------> run

What the agent touches

  • Files and gitRollbackSnapshot of the working copy; commits and branches restored
  • Postgres — Supabase, NeonRollbackSnapshot or branch of the touched tables before the change
  • TerraformRollbackState captured before apply, restored through IaC
  • Deleting volumes, backups, whole databasesStopBlocked by policy or confirmed by a human
  • Email, payments, messages, external APIsStopBlocked or confirmed before anything is sent
  • SaaS — Notion, HubSpot, SalesforceRollback · laterInverse actions through the system's own API

How we sit in the path

  1. 01

    Agent hooks — Claude Code and Cursor show us every tool call before it runs

  2. 02

    MCP gateway — every MCP tool the agent uses goes through us

  3. 03

    CLI wrappers — psql, terraform, kubectl, aws, gcloud for agents in terminals and CI

FIG. 4 — WHERE WE FIT

A neutral layer across every agent and every system.

Stops before it runsRolls back databases & cloudWorks across agentsNo backup platform to adopt
ObservabilityLangSmith, Langfuse, BraintrustTraces and evaluates — after the factnonoyesyes
RubrikAgent Rewind + Agent IdentityEnterprise, runs on Rubrik Security Cloudyesyesyesno
CommvaultAI ProtectMonitors and reverts, can't stop third-party agentsnoyesyesno
MCP gateways & guardrailsPolicy on tool callsMCP calls only — no snapshots, no undoyesnoyesyes
Built-in agent checkpointsClaude Code, Cursor, CodexGreat for local files, one agent at a timeyesnonoyes
UnhappenHooks + MCP gateway + CLI wrappersTarget: installs in an hour, starts in watch-only modeyesyesyesyes

Sources:Commvault AI Protect — The Register ↗Rubrik Agent Rewind — Computerworld ↗Rubrik Agent Identity — SiliconANGLE ↗