Agents with production access
Let agents merge and release on their own. Guards add a layer of confidence on top of their reviews, in production.
For teams that let AI agents ship to production
Rollguard makes every release reversible, feature by feature. Guards watch your metrics and roll back on their own the moment something breaks, so you can give your agents more autonomy with less risk.
In development · Android first · GitHub Actions and GitLab CI
Illustrative example. No human had to step in.
Why now
Reviews catch a lot before the merge. Some problems only show up with real users, on real devices. That is where Rollguard adds a layer of confidence.
How it will work
Your agent writes the new version next to the old one, inside a versions block. Nothing changes for users until the config says to play the new one.
versions("checkout") {
44 { CheckoutV2() } // written by the agent
base { CheckoutV1() } // safe fallback
}Per-feature rollback
Release 44 ships four features. One breaks. A classic rollback throws away all four, and the revenue the other three were bringing in.
Rollguard rolls back only the broken one. Need the whole version back? One rule does that too.
Mobile, desktop, TV, embedded
On a server, you redeploy and everyone has the fix. On a phone, a TV or a customer's device, a broken release stays broken until the store approves your fix and every user updates. Each of those days costs users and revenue.
Days with a broken checkout on every device
Minutes, on a fraction of your users
15.4% of users uninstall an app after a single crash. Luciq 2026
53.2% abandon a purchase during a sale because of a crash or slowdown. Luciq 2026
Custom rules
Roll back only where it breaks. Combine conditions with AND and OR, on the signals you already have.
Use cases
Let agents merge and release on their own. Guards add a layer of confidence on top of their reviews, in production.
Twelve agent PRs in one release, one of them faulty: roll back that PR and keep the other eleven.
A Crashlytics alert or a webhook comes in: a rule tightens the rollout or triggers a rollback, no human in the loop.
Releases climb step by step, Friday included. If anything drifts, they come back down on their own.
A first look at the SDK
Each level of a versions block is the code of one app version. The SDK plays the level the signed config tells it to, and falls back to the previous one on a crash, even offline.
You decide when a switch applies: next launch, next screen or instantly, per feature.
@Composable
fun CheckoutScreen(cart: Cart) {
versions("checkout", applyAt = NextForeground) {
44 { CheckoutV2(cart) } // new version
43 { CheckoutV1(cart) } // previous version
base { LegacyCheckout(cart) }
}
}
Built for agents
A dashboard for humans, an API and an MCP server for your agents. One engine behind all three.
Agents can always tighten a rule. Loosening one takes proof: a simulation on real data and a limited budget.
Every decision sent to devices is signed. The SDK rejects anything that doesn't come from your project.