EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2026

Decawork bets employee-built AI agents need an IT control plane: PH #2, 332 votes

YC S26 startup Decawork gives IT one place to deploy, govern, and retire AI agents built in Claude Code, Codex or Cursor — PH #2 on August 24, 2026.

Decawork

The betIT will buy one control plane to deploy, govern, and retire employee-built agents — identity, scoped credentials, approval gates — instead of ignoring or blocking them.Live

What the business is

Decawork is an agent control plane for IT. An employee connects an agent built in Claude Code, Codex, Cursor, n8n, LangGraph or any other tool; Decawork runs it on company accounts with its own identity and scoped credentials, requires IT sign-off before it goes live and approval for sensitive actions, logs and attributes every action, alerts on failures or suspicious activity, and retires agents nobody uses.

How it started

Aman built the AI compliance platform at Barclays and then hand-wired credentials for every internal agent he shipped while serving 100K+ monthly users; Sarthak built AI systems at NVIDIA that were deployed at OpenAI and Meta. Both kept hitting the same gap: teams build agents easily, but nothing turns them into company-owned systems with controlled access, approval and audit, so IT either ignores them or blocks them. They founded Decawork in YC S26 to standardize that handoff.

What happened

Decawork launched on Product Hunt on 2026-08-24, reaching #2 Product of the Day with 332 upvotes and 31 comments, with the hunt posted by Garry Tan. The launch conversation centered on agent governance: commenters called identity and access management the hardest problem of the agentic era, asked whether Decawork can detect "risk drift" when a developer silently changes an approved agent's prompt or code, and raised the offboarding case of an agent whose builder leaves — which the founders say the platform handles by transferring it to company-owned scoped credentials.

No ending yet — it is still running.

Background

Decawork is an agent control plane for IT teams. An employee builds an agent in Claude Code, Codex, Cursor or any other tool and connects its repository; Decawork runs the agent on company accounts under an official corporate identity with scoped credentials, so IT can approve it before it goes live, gate sensitive actions, see every action in an audit log, alert on failures, and pause or retire agents nobody uses.

Co-founders Aman and Sarthak came from opposite sides of the same problem: Aman built the AI compliance platform at Barclays and hand-wired credentials for agents serving 100K+ monthly users, while Sarthak built AI systems at NVIDIA that were deployed at OpenAI and Meta. Their pitch is that agent sprawl leaves IT with two bad options — ignore the agents or block them — and that a control plane turns employee-built experiments into governed company assets.

The Product Hunt launch on 2026-08-24 reached #2 Product of the Day with 332 upvotes and 31 comments, with the hunt posted by Y Combinator president Garry Tan. Community discussion, covered by Coding4Food, zeroed in on the hard edges of the bet: detecting when an approved agent's prompt or code silently changes its effective risk, and what happens to an agent when the employee who built it leaves the company.

What has to be true

  • Shadow AI is a live pain: agents get built in every team's tooling, and IT that cannot see them ends up ignoring or blocking them — so a platform that makes them governable hits a real need.
  • The bet is on the handoff, not the build — builders keep their tools, and the value sits in identity, scoped credentials, approvals and audit, the layer enterprises already pay for everywhere else.
  • The buyer is unambiguous: IT and security teams are the ones exposed by agent sprawl, and they control procurement, so the wedge opens inside the department that decides.
  • The launch proved audience fit: #2 Product of the Day with 332 upvotes and a Garry Tan hunt put the product in front of the operator and founder audience YC alumni need.

What can be applied

When employees can build agents anywhere, control moves to deployment: give IT one standard way to approve, watch, and retire agents, and shadow AI becomes a governed asset instead of a threat.

Aftermath

As of September 2, 2026, Decawork is live at decawork.ai, marketed as the one place for IT to manage internal agents across teams and tools, and no funding round has been disclosed. The August 24 Product Hunt launch — #2 of the day, 332 upvotes, 31 comments — is its clearest demand signal so far. Whether agent governance becomes a standalone product category or folds into identity and security platforms is still unproven.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases