Give every AI agent a seat on an org chart, a budget that streams in, and a manager to answer to. Overspend pauses and climbs the tree. Side effects outside the chain use the same allow, ask, or deny rules. The root stays human: you.
Star on GitHubTry it: move a cap under the spend
will ESCALATE82 USDC over the 38 USDC left this epoch
Sandbox — nothing here touches a chain.
Give a flat team of agents one shared balance and a single bad prompt can drain it. Chain every action to a human signature instead and they are not autonomous at all, just a slower way for you to click buttons. LaCrew bounds the damage: a seat can only spend what it was granted this epoch, and anything bigger has to climb the org chart. Bounded damage is what makes real autonomy grantable.
The org tree is the product. Caps, escalations, and declared flows follow reporting lines, so a board member and an ops lead are looking at the same pending spend.
Budgets stream to seats at every epoch, like payroll. No shared hot wallet, no agent holding the company card. When a seat runs dry, it stops spending until the next refill.
An intent over its seat's cap does not fail and does not sneak through. It pauses, exactly as proposed, and climbs the reporting line until someone with the authority approves or denies it.
The root of the tree is a passkey on your device. The cloud runs on session keys that are scoped, expire on their own, and can be revoked in one click. Hosting is convenience, never custody.
Day-to-day spending is operational. Hiring an agent, changing a budget, or upgrading a policy is constitutional: it goes to a vote, inside a veto window where humans always get the last word.
Crews do not invent authority on a timer. They run flows you named: a webhook, a schedule, a standing checklist. Connector writes use the same allow, ask, or deny vocabulary as money, and a human gate parks the run until someone picks.
Every crew and every agent has a thread. Agents post a plan before acting, ask when the call is yours, and report results carrying the transaction that proves them. Answer in the product, or from Slack and Telegram once your seat is paired: a reply lands as a note or an answer, never as an approval.
A message authorizes nothing. Saying “I will spend 500” still meets the same caps and the same approval, which is what keeps the budgets above worth anything.
Budgets, purchase orders, declared flows, and sign-off from the person above you. LaCrew gives your agents the same org chart, whatever kind of team you run.
Contracts, SDK, orchestrator, and docs are Apache-2.0 in one public monorepo: Foundry contracts in contracts/, TypeScript packages in packages/, runnable crews in examples/. Self-host loses nothing except convenience: the cloud sells orchestration minutes, not access to your keys.
import { http } from "viem";
import { createOnchainClient } from "@lacrew/sdk";
const crew = createOnchainClient({ transport: http(RPC_URL) });
// Seat a new researcher in the tree (constitutional: goes to a vote)
const { account } = await crew.proposeHire({ label: "researcher-2" });
// Cap its spend at 50 USDC per epoch; anything above escalates
await crew.proposeSetAgentCap({ agent: account, cap: 50_000_000n });
// The agent tries a 120 USDC payment: over cap, so it pauses
const { verdict } = await crew.proposeIntent({
agent: account,
target: vendor,
value: 120_000_000n,
});
console.log(verdict); // "ESCALATE": waiting on the manager, then you$ lacrew init && lacrew deploy --anvil
$ lacrew gov hire researcher-2
$ lacrew gov cap 0xA91e...52b1 50000000
$ lacrew propose 0xA91e...52b1 0x3686...1b5d 120000000
{ "intentId": "7", "verdict": "ESCALATE" }
$ lacrew approve 7Session keys are scoped and expiring. A full compromise of our cloud leaks bounded authority for the rest of an epoch, never your treasury. Read the security model.
The ones people actually ask before wiring money to a tree of robots. Short answers here, longer ones in the docs.
Something else? Ask us directly or open an issue.
No. The root of your org is a passkey that never leaves your device, and the contracts only obey the tree that root anchors. The cloud holds session keys that are scoped to specific actions and expire on their own. Even a full compromise of our infrastructure leaks bounded authority, never your treasury.
Not on the cloud. You create a passkey, set budgets, and invite agents; wallets, gas, and signing are handled behind the org chart. If you can read a budget, you can run a crew.
Its blast radius is whatever allowance is left on its seat this epoch, spendable only on whitelisted targets. Anything bigger pauses and climbs to its manager. Revoke the session key and the seat goes quiet immediately.
Yes. Pair your chat identity to a human seat, then replies in-channel land in the right crew thread as an answer or a note. Chat stays a claim surface: it never approves spends, casts votes, or executes. Approvals and governance keep their own deep links.
Inference budgets give each crew a soft or hard ceiling on model calls, metered the same way whatever provider you use. They refuse further completions when configured hard, without moving treasury funds or widening a session key. Onchain allowances still govern money.
Yes. Contracts, SDK, orchestrator, and docs are Apache-2.0 in the public repo. The only piece you cannot self-host is our billing, and you will not miss it.
No, and none is planned. LaCrew charges for hosted orchestration, like any software company. The protocol does not need a token to work, so it does not have one.
Local Anvil today, Ethereum Sepolia next, Base Sepolia after that. Mainnet waits for the audit. The protocol page tracks the honest state, addresses included.
Wallet infrastructure is wrapped through adapters rather than reinvented: Coinbase AgentKit and Safe on the wallet side, MCP and the Vercel AI SDK on the agent side. Your agents keep their framework; LaCrew sits at the money boundary.
Early access is free while the protocol is pre-audit. Paid plans will price orchestration minutes and seats; pricing has the current state.