Deterministic guardrails that don't break agents
See the codeDeterministic guardrails that don't break agents.
Website · How it works · Policy reference · Benchmarks · Paper · Discord
OpenAPPA sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination?
It is powered by APPA (Agentic Permissions Policy Algebra). OpenAPPA tracks the sensitivity and trust of everything an agent reads and checks each tool call against it before the call runs, so sensitive data never reaches an unauthorized tool. Classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.
Policy is declarative TOML. The engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. Run it in-process, or as a sidecar process that checks each tool call before it runs.
Agent security has two axes: an agent that permits unauthorized flows is unsafe, and an agent that refuses valid work is useless. We measure both on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for Agentic Applications), with standard and adversarial prompts. No scored attack succeeded against OpenAPPA in 1,320 evaluations, while it completed 88–90% of tasks; Microsoft FIDES let 28–35% of attacks through, and Claude Code auto mode let 10 through across the two suites.
| OpenAPPA | Claude Auto mode | FIDES (Microsoft) | |
|---|---|---|---|
| Task completion | 89% | 90% | 41% |
| Attacks that succeeded | 0% | 10% | 31% |
Read the full benchmark results
The Claude Code integration is a playground for the model, not the product. It is the fastest way to watch a policy make a decision on real work:
curl -fsSL https://openappa.com/install.sh | sh &&
~/.local/bin/appa plugin install claude-code
Then start a protected session and run the policy setup skill:
clappa
/appa-guide

Add to your agent →Embed the APPA runtime in your own agent from any language, or connect an agent through hooks. |
Try at the LLM proxy level →Archestra's 1.4 Release Candidate implements OpenAPPA for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and any other agent that talks to a model through its LLM proxy. |
The APPA CLI provides two commands to check policy decisions before you merge a change, without running your agent's tools:
appa describe --check checks that your configuration loads.appa replay checks scripted tool calls against the decisions you expect.appa describe --config appa.toml --check
appa replay --config appa.toml policy-tests/
Run them locally, or make them a required CI check to block merges when validation fails. Validation has a GitHub Actions workflow and a worked example.
OpenAPPA is a preview and an RFC. The model is settled enough to build against and deliberately open to argument — config and wire surfaces may break without shims.
The formal algebra and recovery guarantees are published in:
Latest evaluation numbers are updated on the website. Read the paper, then open an issue — or come argue in the Discord.
6 followers · starred Sep 2026
Rust
67.8%
Python
20.2%
TypeScript
5.8%
Go
4.1%
Deterministic guardrails that don't break agents
See the codeDeterministic guardrails that don't break agents.
Website · How it works · Policy reference · Benchmarks · Paper · Discord
OpenAPPA sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination?
It is powered by APPA (Agentic Permissions Policy Algebra). OpenAPPA tracks the sensitivity and trust of everything an agent reads and checks each tool call against it before the call runs, so sensitive data never reaches an unauthorized tool. Classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.
Policy is declarative TOML. The engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. Run it in-process, or as a sidecar process that checks each tool call before it runs.
Agent security has two axes: an agent that permits unauthorized flows is unsafe, and an agent that refuses valid work is useless. We measure both on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for Agentic Applications), with standard and adversarial prompts. No scored attack succeeded against OpenAPPA in 1,320 evaluations, while it completed 88–90% of tasks; Microsoft FIDES let 28–35% of attacks through, and Claude Code auto mode let 10 through across the two suites.
| OpenAPPA | Claude Auto mode | FIDES (Microsoft) | |
|---|---|---|---|
| Task completion | 89% | 90% | 41% |
| Attacks that succeeded | 0% | 10% | 31% |
Read the full benchmark results
The Claude Code integration is a playground for the model, not the product. It is the fastest way to watch a policy make a decision on real work:
curl -fsSL https://openappa.com/install.sh | sh &&
~/.local/bin/appa plugin install claude-code
Then start a protected session and run the policy setup skill:
clappa
/appa-guide

Add to your agent →Embed the APPA runtime in your own agent from any language, or connect an agent through hooks. |
Try at the LLM proxy level →Archestra's 1.4 Release Candidate implements OpenAPPA for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and any other agent that talks to a model through its LLM proxy. |
The APPA CLI provides two commands to check policy decisions before you merge a change, without running your agent's tools:
appa describe --check checks that your configuration loads.appa replay checks scripted tool calls against the decisions you expect.appa describe --config appa.toml --check
appa replay --config appa.toml policy-tests/
Run them locally, or make them a required CI check to block merges when validation fails. Validation has a GitHub Actions workflow and a worked example.
OpenAPPA is a preview and an RFC. The model is settled enough to build against and deliberately open to argument — config and wire surfaces may break without shims.
The formal algebra and recovery guarantees are published in:
Latest evaluation numbers are updated on the website. Read the paper, then open an issue — or come argue in the Discord.
6 followers · starred Sep 2026
Rust
67.8%
Python
20.2%
TypeScript
5.8%
Go
4.1%