Thursday, October 1, 2026

OpenAPPA

★925Must watch
API

Deterministic guardrails between an agent and its tools — every tool call is checked against where sensitive data is allowed to go.

OpenAPPA

Why it matters

OpenAPPA sits in front of tool calls and answers one question before each one runs: is this data allowed to reach this destination? It tracks the sensitivity and trust of everything the agent has read, then applies a declarative TOML policy (APPA — Agentic Permissions Policy Algebra). The engine decides from the event log alone, with no network or file side effects, so the same log always gets the same decision. You can run it in-process or as a sidecar, and there is a Claude Code plugin path plus a broader Archestra proxy path for other agents.

Most agent safety today is soft: classifiers, PII detectors, or hope the model behaves. Founders shipping agents that touch customer data need a hard gate that does not flake. OpenAPPA is that gate — policy you can replay in CI, not a vibe check at runtime.

How it works

Write a TOML policy that labels sources and allowed sinks. Install the runtime (curl install or embed). On each tool call the agent proposes, OpenAPPA checks the data lineage against the policy and allows or blocks before the call runs. Use `appa describe --check` and `appa replay` to validate policies offline, then wire the same checks into CI so a bad policy never merges. For a quick demo, install the Claude Code plugin and run a protected session with `/appa-guide`.

Unlike probabilistic classifiers or sandbox-only runtimes, OpenAPPA is a deterministic data-flow permission layer: same event log, same decision, every time. It complements skill scanners and OS sandboxes by answering a different question — not “is this code safe” or “can the process touch the disk,” but “may this payload leave through this tool.”

Capabilities

API
  • API / SDK surface

Similar tools

agentssecurityguardrailspermissionsdevtools
Source ↗

Via github

X