Built this because AI agents keep getting access to infrastructure with zero guardrails. Opsy sits between the agent and your cloud — agents propose changes, you approve before anything runs.
No credentials exposed to agents. They talk to Opsy through CLI or MCP, write drafts in YAML, and nothing touches prod without approval.
Works with Claude Code or any agent that supports MCP out of the box.