You've used ChatGPT and Claude for real work. They just do the task. No record of what they touched, no approval on the risky step, nothing you could hand your security team. Great UX, zero governance. Enterprise tools flip it: total control, an interface nobody wants to open. Lunen is what automated AI should be, the clean UX and the full transparency, not one or the other. Now in early access.
Hey Product Hunt 👋, I'm Mike, from the Lunen founding team.
You've used ChatGPT and Claude for real work by now. You ask for something, it goes and does it. That's the pitch, and it's also the problem. It just does it. No record of what it touched, no point where it stops and lets you approve the risky part, nothing you'd feel good putting in front of your security team. Amazing to use, impossible to govern.
The enterprise tools that fix the governance side have the opposite problem. Locked down, fully audited, and nobody wants to open them. So every company I talk to is quietly picking one. Fast and ungoverned, or safe and unused.
My belief is you should never have to pick. Lunen is the AI you already know how to use, except you can see and control every move it makes.
It works because we refused to build it the normal way. Normally the people who want agents grab a tool IT never signed off on, and IT buys a governance layer nobody wants to touch. Two products, two teams, a gap in the middle where the AI project quietly dies. In Lunen it's one path. The same steps someone in accounting takes to describe an agent are the steps that scope its data, set its permissions, and log what it does.
What that gets you:
Describe the agent in plain language and the plan writes itself. Named tools, scoped data, a schedule. No builder to learn, no YAML. Allow the reads, approve the writes. Every tool is a policy decision. It runs on its own, or it waits for human-in-the-loop before it calls, like a 2FA checkpoint. Same rules for every agent and every one-off run.
Every action on the record. People and agents land in one audit log. Click any event and you see who did it, what got approved, which model ran, and what data it touched. Hand it straight to a reviewer. Agent have their own identity, so you can easily see and track what YOU did with an agent, what an agent did independently, and what an agent did on your approval.
Where this comes from:
We built Lunen inside REDspace, where we've spent 25+ years shipping enterprise platforms for some of the biggest media and tech companies out there. We watched a lot of good AI work die in security reviews. Got tired of it. Built this. So we first started by solving the problem for ourselves and now it's time to share it outwards.
We're in early access now, working hands-on with the teams we bring on. If your org is trying to get AI past its own security review, come get early access and I'll get you set up.
I'm in the comments all day. What's the riskiest thing you've let an AI do with no record of it?
The agent-identity piece is what I'd dig into first, @mikerudolph_ . You mention agents get their own identity, and permissions scope down to the individual MCP tool call. When an agent actually hits a connected MCP service, does that downstream service see the agent's own scoped credential — or is Lunen brokering one shared token behind the policy layer? That's the difference between real least-privilege at the source vs. only inside Lunen.
Two more, since MCP is doing the heavy lifting: can I bring my own self-hosted MCP servers, or is it a curated catalog to start?
And the audit log records which model ran — can I pin or route models per agent, and is that model choice itself a governed policy decision, or just logged after the fact?
the approval-on-the-risky-step idea is the part that actually matters here, most agent tools either block everything or nothing. curious how you define what counts as risky by default - is that something the team configures per action type or does the agent itself flag it based on context?
the framing really nails it, putting governance on equal footing with experience instead of bolting it on after. that takes discipline most teams skip.
The approve-the-risky-step checkpoint is exactly what's missing from most agent tools — they fire and you reconstruct what happened afterward. Before wiring this into a real workflow I'd want to know where the action record actually lives: a hosted store only, or something I can export or self-host to hand the security team? And is the approval gate rule-based per action type, or does a human get pinged on every write?
Congrats on the launch, Mike. The control layer is the part most agent builders skip, and it is the first thing a regulated buyer asks about. I run a HIPAA-compliant AI suite for clinicians, and "who can run what, with which data" is half of every security review we go through. How granular do the permissions get, can an admin scope which data sources an agent touches per team member? And can the audit log be exported to hand to a compliance team during a review?
The thing that stands out to me is keeping a clear record of what the AI actually did. Wanting the convenience without giving up the ability to answer for it later feels like the sensible way to approach all of this.
Finally a tool that keeps the consumer feel but actually shows you what happened under the hood. The approval flow for risky steps felt thoughtful, not bureaucratic.
One thing that would help my team a lot is a side-by-side replay viewer that shows what the agent did step by step with diffs, so I can review an overnight run in a few minutes instead of digging through logs. That kind of timeline with redo and undo per step would make the whole governance story actually usable day to day.
Having built self-hosted MCP agents, governance is always the bottleneck: defining unattended vs. human-in-the-loop actions and auditing the aftermath. You can ignore this solo, but it kills enterprise adoption.
The "allow reads, approve writes" approach with unified audit logs targets this perfectly, though I'm curious if it survives a real security review.
For anyone running agents in production: where do you draw the line for human intervention? That’s the boundary I find hardest to define.
The control surface matters as much as the agent. For team-run agents, I would want permissions, dry-run mode, approval points, and logs to be first-class, because the failure mode is not that the agent is slow; it is that it acts confidently in the wrong system.
Finally something that doesn't make me choose between a nice interface and actual visibility. Tried a small workflow and the audit trail was already there without me digging for it.
Clean interface that doesn't feel like another enterprise dashboard, and I was surprised the approval workflow didn't slow things down.
Finally tried it this morning and the approval log before risky steps actually feels useful, not just busywork. The fact that I can see exactly what the agent touched makes me way more comfortable letting it loose on real files.
I've had access to Lunen for a few weeks and have an agent that runs daily that is saving me hours of work per week, and will only continue to get better as I refine and have an agent that can build these agents for me.
Finally got access this week and the activity log is the standout for me, I can actually see every file and step it took without digging through chat scrollback. The approval prompt for risky actions feels like the right amount of friction too.
Would love to see a side-by-side replay of the agent's exact tool calls with diffs against what it intended to do, makes post-hoc review way easier when something feels off.
The governance view is genuinely useful, I could actually see what ran and approve the risky steps before anything shipped. Wish more AI tools handled the boring compliance stuff this smoothly.
The "2FA checkpoint" framing for risky calls is the interesting part to me. Most agent tools either gate everything behind a human click or trust the model fully — you're doing something in between. How is the read vs. write / auto-allow vs. approve line actually drawn? Is that a threshold an admin configures per tool/data source, or does Lunen infer it from the action type itself? And for scheduled agents running unattended — if a write needs approval and nobody's there to click it, does it just sit and wait, or fall back to a pre-set policy?
About Lunen.ai on Product Hunt
“Build AI agents your whole team can run, and control”
Lunen.ai launched on Product Hunt on July 20th, 2026 and earned 125 upvotes and 30 comments, placing #13 on the daily leaderboard. You've used ChatGPT and Claude for real work. They just do the task. No record of what they touched, no approval on the risky step, nothing you could hand your security team. Great UX, zero governance. Enterprise tools flip it: total control, an interface nobody wants to open. Lunen is what automated AI should be, the clean UX and the full transparency, not one or the other. Now in early access.
Lunen.ai was featured in Productivity (656.5k followers), Artificial Intelligence (474.1k followers) and Security (2.8k followers) on Product Hunt. Together, these topics include over 260.6k products, making this a competitive space to launch in.
Who hunted Lunen.ai?
Lunen.ai was hunted by Mike Rudolph. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Want to see how Lunen.ai stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.