archestra-ai/OpenAPPA

Deterministic guardrails that don't break agents

Rust

608

716 commits

updated Sep 30, 2026

See the code

See what people are saying

README

OpenAPPA

Deterministic guardrails that don't break agents.

Website · How it works · Policy reference · Benchmarks · Paper · Discord

License: MIT NeurIPS 2026 Workshop Status: Preview & RFC Discord


OpenAPPA sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination?

It is powered by APPA (Agentic Permissions Policy Algebra). OpenAPPA tracks the sensitivity and trust of everything an agent reads and checks each tool call against it before the call runs, so sensitive data never reaches an unauthorized tool. Classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.

Policy is declarative TOML. The engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. Run it in-process, or as a sidecar process that checks each tool call before it runs.

Benchmarks

Agent security has two axes: an agent that permits unauthorized flows is unsafe, and an agent that refuses valid work is useless. We measure both on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for Agentic Applications), with standard and adversarial prompts. No scored attack succeeded against OpenAPPA in 1,320 evaluations, while it completed 88–90% of tasks; Microsoft FIDES let 28–35% of attacks through, and Claude Code auto mode let 10 through across the two suites.

OpenAPPAClaude Auto modeFIDES (Microsoft)
Task completion89%90%41%
Attacks that succeeded0%10%31%

Read the full benchmark results

Try it: Claude Code

The Claude Code integration is a playground for the model, not the product. It is the fastest way to watch a policy make a decision on real work:

curl -fsSL https://openappa.com/install.sh | sh &&
  ~/.local/bin/appa plugin install claude-code

Then start a protected session and run the policy setup skill:

clappa
/appa-guide

A protected Claude Code session refuses to post content from a private meeting recording to a public GitHub repo, and explains why

Other agents

Add to your agent →

Embed the APPA runtime in your own agent from any language, or connect an agent through hooks.

Try at the LLM proxy level →

Archestra's 1.4 Release Candidate implements OpenAPPA for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and any other agent that talks to a model through its LLM proxy.

Testing

The APPA CLI provides two commands to check policy decisions before you merge a change, without running your agent's tools:

  • appa describe --check checks that your configuration loads.
  • appa replay checks scripted tool calls against the decisions you expect.
appa describe --config appa.toml --check
appa replay --config appa.toml policy-tests/

Run them locally, or make them a required CI check to block merges when validation fails. Validation has a GitHub Actions workflow and a worked example.

Status & Paper

OpenAPPA is a preview and an RFC. The model is settled enough to build against and deliberately open to argument — config and wire surfaces may break without shims.

The formal algebra and recovery guarantees are published in:

Latest evaluation numbers are updated on the website. Read the paper, then open an issue — or come argue in the Discord.

License

MIT · Contributors · Brand assets

guardrails
guardrails-ai
security

Significant stargazers

Aleksandr Sarantsev

6 followers · starred Sep 2026

archestra-ai/OpenAPPA

Deterministic guardrails that don't break agents

Rust

608

716 commits

updated Sep 30, 2026

See the code

See what people are saying

README

OpenAPPA

Deterministic guardrails that don't break agents.

Website · How it works · Policy reference · Benchmarks · Paper · Discord

License: MIT NeurIPS 2026 Workshop Status: Preview & RFC Discord


OpenAPPA sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination?

It is powered by APPA (Agentic Permissions Policy Algebra). OpenAPPA tracks the sensitivity and trust of everything an agent reads and checks each tool call against it before the call runs, so sensitive data never reaches an unauthorized tool. Classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.

Policy is declarative TOML. The engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. Run it in-process, or as a sidecar process that checks each tool call before it runs.

Benchmarks

Agent security has two axes: an agent that permits unauthorized flows is unsafe, and an agent that refuses valid work is useless. We measure both on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for Agentic Applications), with standard and adversarial prompts. No scored attack succeeded against OpenAPPA in 1,320 evaluations, while it completed 88–90% of tasks; Microsoft FIDES let 28–35% of attacks through, and Claude Code auto mode let 10 through across the two suites.

OpenAPPAClaude Auto modeFIDES (Microsoft)
Task completion89%90%41%
Attacks that succeeded0%10%31%

Read the full benchmark results

Try it: Claude Code

The Claude Code integration is a playground for the model, not the product. It is the fastest way to watch a policy make a decision on real work:

curl -fsSL https://openappa.com/install.sh | sh &&
  ~/.local/bin/appa plugin install claude-code

Then start a protected session and run the policy setup skill:

clappa
/appa-guide

A protected Claude Code session refuses to post content from a private meeting recording to a public GitHub repo, and explains why

Other agents

Add to your agent →

Embed the APPA runtime in your own agent from any language, or connect an agent through hooks.

Try at the LLM proxy level →

Archestra's 1.4 Release Candidate implements OpenAPPA for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and any other agent that talks to a model through its LLM proxy.

Testing

The APPA CLI provides two commands to check policy decisions before you merge a change, without running your agent's tools:

  • appa describe --check checks that your configuration loads.
  • appa replay checks scripted tool calls against the decisions you expect.
appa describe --config appa.toml --check
appa replay --config appa.toml policy-tests/

Run them locally, or make them a required CI check to block merges when validation fails. Validation has a GitHub Actions workflow and a worked example.

Status & Paper

OpenAPPA is a preview and an RFC. The model is settled enough to build against and deliberately open to argument — config and wire surfaces may break without shims.

The formal algebra and recovery guarantees are published in:

Latest evaluation numbers are updated on the website. Read the paper, then open an issue — or come argue in the Discord.

License

MIT · Contributors · Brand assets

guardrails
guardrails-ai
security

Significant stargazers

Aleksandr Sarantsev

6 followers · starred Sep 2026

Languages

Rust

67.8%

Python

20.2%

TypeScript

5.8%

Go

4.1%