For AI-agent security

Give autonomous tools less ambient authority.

Explore the permission model for files, commands, network destinations, secrets, tools, and delegation before the native runtime is built.

Working sequence

From extension identity to a recorded decision.

01

Select a principal

Identify the agent, extension, or delegated tool making the request.

02

Describe the grant

Bind capability, action, resource, workspace, and expiration.

03

Audit the result

Record allow, deny, or prompt with a stable reason and policy version.

Built for the role

Less noise. More decision context.

Patch-first writes

The runtime target makes agent changes reviewable before applying them.

Brokered destinations

Network access is designed around explicit destinations rather than ambient egress.

Delegation visibility

Agents and tools keep distinct principals so authority cannot silently expand.

Start with a real workflow

Explore the GuardRails permission prototype.

Use the working product surface now; no future runtime capability is presented as already shipped.

Get started