the problem
giving autonomous ai agents direct access to private keys is a catastrophic security risk. whether an agent hallucinates, falls victim to prompt injection, or encounters a malicious target contract, a fully custodial agent wallet means your entire treasury is exposed. traditional multisigs require human intervention, defeating the purpose of autonomy. custodial hot wallets are reckless.the solution
shugo (守護) is a zero-custody policy delegation protocol built on solana. instead of giving an ai agent a wallet containing funds, you give it an allowance tied to strict, on-chain cryptographic rules. shugo leverages solana’s official subscriptions & allowances (s&a) program to provide a velocity limitation layer, formally verified via aws kani.zero custody
agents never hold the private keys to the treasury. access is delegated via cpi and can be instantly revoked.
velocity caps
enforce hard limits on how much value an agent can move per epoch, bounding maximum potential loss.
target allowlists
restrict agents to specific pre-approved smart contracts (e.g., only jupiter routing or raydium pools).
formal verification
core program logic is formally verified via aws kani to guarantee policy enforcement mathematically.
how it works
- the treasury (human): a standard solana wallet or multisig holding funds.
- the guardrail (shugo): an on-chain policy that defines exactly what the agent is allowed to do.
- the agent (ai): a lightweight keypair that signs transactions. the treasury delegates execution authority to this keypair, bounded by the shugo policy.

