hn.today

OpenAPPA: Deterministic guardrails that don't break agents

github.com10 points2 comments
Screenshot of OpenAPPA: Deterministic guardrails that don't break agents

OpenAPPA is a guardrail system that intercepts every agent tool call and deterministically answers whether a given piece of data is allowed to go to that destination. It implements APPA (Agentic Permissions Policy Algebra) to track sensitivity and trust for everything an agent reads, evaluating access from the event log alone so the same inputs always yield the same decision; classifiers and PII detectors remain probabilistic, but the policy check itself is deterministic. Policies are declared in TOML, the engine makes no network or file calls during decisioning, and the runtime can be embedded in-process or run as a sidecar to block unauthorized flows before any tool executes.

Evaluations use two suites - Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for agentic apps) - and report that no scored attack succeeded in 1,320 runs while completing 88-90% of tasks, outperforming Microsoft FIDES and Claude Code auto mode on the safety/completeness tradeoff. Integrations and examples include Claude Code, Claude Desktop, Cursor, Codex, Copilot CLI and others; a CLI (appa describe, appa replay) supports local and CI policy testing. The project is released under MIT, labeled Preview & RFC, and is accompanied by a formal NeurIPS 2026 workshop paper describing the algebra and recovery guarantees.

Read on github.com2 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in AI

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.