Open-source AI agent control plane in Rust for runtime governance, agent identity, permissions, memory, human approvals, budget controls and auditable receipts. Bring existing agents or assemble one here. Active development; production coverage is being validated.
Rust
4
56 commits
updated Oct 6, 2026
Control what AI agents can do—not only what they can say.
Website · Quick start · Architecture · Security
Connector is an open-source control plane for AI agents that take real actions. It gives every agent an identity, explicit authority, per-action admission, runtime enforcement, operator stop controls, and an evidence trail.
Use your existing agent or assemble one in Connector. Before it sends a request, changes data, calls a tool, spends money, or contacts another agent, Connector decides whether that specific action may proceed.
Agent frameworks help agents reason and use tools. API gateways route traffic. Policy engines evaluate rules. Observability systems record events. None of these alone answers the whole operational question:
Should this agent be allowed to perform this action, in this situation, right now—and can an operator stop the next action?
Connector joins that decision to identity, grants, runtime enforcement, and the resulting receipt.
| Without Connector | With Connector |
|---|---|
| A tool credential often authorizes the whole process | Authority is scoped to the agent and action |
| Instructions and permissions are mixed in prompts | Knowledge, directives, memory, and authority remain separate |
| Approval may happen outside the execution record | Ask stays open until an operator decides it |
| Logs explain activity after the fact | Admission and observed consequence share an evidence trail |
| Stopping depends on model cooperation | Cease fences the generation and stops future admission |
| Each backend has a separate operator workflow | Connector presents one workspace and manages the backends |
Connector is for teams whose agents can affect real systems:
If an agent only produces text in a disposable sandbox, Connector may be more infrastructure than you need.
git clone https://github.com/GlobalSushrut/connector-oss.git
cd connector-oss
./up.sh
Open http://127.0.0.1:9091/ and choose Open on this machine. The local development token stays on your computer.
Then:
rustup target add wasm32-unknown-unknownA smaller library server without the operator UI is documented in docs/quickstart.md.
The action path is:
agent → proposed effect → PATE admission → runtime enforcement
→ external effect → receipt and observed consequence
The seven workspace dimensions describe how an agent is governed; they are not the seven external backends. PATE is the admission authority. A permit can still be denied at runtime. Cease fences the current generation, voids its context, and stops future admission.
./up.sh downloads pinned components, starts them with local defaults, and keeps
their operation behind Connector.
| Role | Components |
|---|---|
| Identity | Keycloak, SPIFFE/SPIRE |
| Enforcement | NVIDIA OpenShell, OPA/Rego, Firecracker |
| Evidence | OpenTelemetry, Sigstore cosign |
| Traffic-plane target | agentgateway for LLM, MCP, A2A, HTTP, and gRPC |
Connector also supports MCP, A2A, and OpenAI-compatible agent interfaces. Pasting an address never creates a grant.
The workspace, PATE admission, receipts, Cease, TraceTramp, WitnessCtl, and seven-backend boot path are present.
Important limits:
This repository does not claim production readiness, security, correctness, safety, or compliance.
Read CONTRIBUTING.md before opening a pull request.
Report exploitable findings privately through SECURITY.md.
Libraries under oss/ use the Apache License 2.0. The node under
platform/ uses the Business Source License 1.1.
Open-source AI agent control plane in Rust for runtime governance, agent identity, permissions, memory, human approvals, budget controls and auditable receipts. Bring existing agents or assemble one here. Active development; production coverage is being validated.
Rust
4
56 commits
updated Oct 6, 2026
Control what AI agents can do—not only what they can say.
Website · Quick start · Architecture · Security
Connector is an open-source control plane for AI agents that take real actions. It gives every agent an identity, explicit authority, per-action admission, runtime enforcement, operator stop controls, and an evidence trail.
Use your existing agent or assemble one in Connector. Before it sends a request, changes data, calls a tool, spends money, or contacts another agent, Connector decides whether that specific action may proceed.
Agent frameworks help agents reason and use tools. API gateways route traffic. Policy engines evaluate rules. Observability systems record events. None of these alone answers the whole operational question:
Should this agent be allowed to perform this action, in this situation, right now—and can an operator stop the next action?
Connector joins that decision to identity, grants, runtime enforcement, and the resulting receipt.
| Without Connector | With Connector |
|---|---|
| A tool credential often authorizes the whole process | Authority is scoped to the agent and action |
| Instructions and permissions are mixed in prompts | Knowledge, directives, memory, and authority remain separate |
| Approval may happen outside the execution record | Ask stays open until an operator decides it |
| Logs explain activity after the fact | Admission and observed consequence share an evidence trail |
| Stopping depends on model cooperation | Cease fences the generation and stops future admission |
| Each backend has a separate operator workflow | Connector presents one workspace and manages the backends |
Connector is for teams whose agents can affect real systems:
If an agent only produces text in a disposable sandbox, Connector may be more infrastructure than you need.
git clone https://github.com/GlobalSushrut/connector-oss.git
cd connector-oss
./up.sh
Open http://127.0.0.1:9091/ and choose Open on this machine. The local development token stays on your computer.
Then:
rustup target add wasm32-unknown-unknownA smaller library server without the operator UI is documented in docs/quickstart.md.
The action path is:
agent → proposed effect → PATE admission → runtime enforcement
→ external effect → receipt and observed consequence
The seven workspace dimensions describe how an agent is governed; they are not the seven external backends. PATE is the admission authority. A permit can still be denied at runtime. Cease fences the current generation, voids its context, and stops future admission.
./up.sh downloads pinned components, starts them with local defaults, and keeps
their operation behind Connector.
| Role | Components |
|---|---|
| Identity | Keycloak, SPIFFE/SPIRE |
| Enforcement | NVIDIA OpenShell, OPA/Rego, Firecracker |
| Evidence | OpenTelemetry, Sigstore cosign |
| Traffic-plane target | agentgateway for LLM, MCP, A2A, HTTP, and gRPC |
Connector also supports MCP, A2A, and OpenAI-compatible agent interfaces. Pasting an address never creates a grant.
The workspace, PATE admission, receipts, Cease, TraceTramp, WitnessCtl, and seven-backend boot path are present.
Important limits:
This repository does not claim production readiness, security, correctness, safety, or compliance.
Read CONTRIBUTING.md before opening a pull request.
Report exploitable findings privately through SECURITY.md.
Libraries under oss/ use the Apache License 2.0. The node under
platform/ uses the Business Source License 1.1.