← 开源
archestra-ai

OpenAPPA

Deterministic guardrails that don't break agents

AI EngineeringTest & guardRust
在 GitHub 打开
增长势头
+4224 小时新增 Star+3.0%
1.42k
Star
61
Fork
—
本周
15
贡献者
创建于 2026-08-18 · 更新于 2026-10-05 · 今日第 273 名
主要开发者
README

OpenAPPA

Deterministic guardrails that don't break agents.

Website · How it works · Policy reference · Benchmarks · Paper · Discord

License: MIT NeurIPS 2026 Workshop Status: Preview & RFC Discord


OpenAPPA sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination?

It is powered by APPA (Agentic Permissions Policy Algebra). OpenAPPA tracks the sensitivity and trust of everything an agent reads and checks each tool call against it before the call runs, so sensitive data never reaches an unauthorized tool. Classifiers and PII detectors are probabilistic, while this check is deterministic and returns the same decision on every run.

Policy is declarative TOML. The engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. Run it in-process, or as a sidecar process that checks each tool call before it runs.

Benchmarks

Agent security has two axes: an agent that permits unauthorized flows is unsafe, and an agent that refuses valid work is useless. We measure both on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench (OWASP Top 10 for Agentic Applications), with standard and adversarial prompts. No scored attack succeeded against OpenAPPA in 1,320 evaluations, while it completed 88–90% of tasks; Microsoft FIDES let 28–35% of attacks through, and Claude Code auto mode let 10 through across the two suites.

OpenAPPA Claude Auto mode FIDES (Microsoft)
Task completion 89% 90% 41%
Attacks that succeeded 0% 10% 31%

Read the full benchmark results

Try it: Claude Code

The Claude Code integration is a playground for the model, not the product. It is the fastest way to watch a policy make a decision on real work:

curl -fsSL https://openappa.com/install.sh | sh &&
  ~/.local/bin/appa plugin install claude-code

Then start a protected session and run the policy setup skill:

clappa
/appa-guide

A protected Claude Code session refuses to post content from a private meeting recording to a public GitHub repo, and explains why

Other agents

Add to your agent →

Embed the APPA runtime in your own agent from any language, or connect an agent through hooks.

Try at the LLM proxy level →

Archestra's 1.4 Release Candidate implements OpenAPPA for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and any other agent that talks to a model through its LLM proxy.

Testing

The APPA CLI provides two commands to check policy decisions before you merge a change, without running your agent's tools:

  • appa describe --check checks that your configuration loads.
  • appa replay checks scripted tool calls against the decisions you expect.
appa describe --config appa.toml --check
appa replay --config appa.toml policy-tests/

Run them locally, or make them a required CI check to block merges when validation fails. Validation has a GitHub Actions workflow and a worked example.

Status & Paper

OpenAPPA is a preview and an RFC. The model is settled enough to build against and deliberately open to argument — config and wire surfaces may break without shims.

The formal algebra and recovery guarantees are published in:

Latest evaluation numbers are updated on the website. Read the paper, then open an issue — or come argue in the Discord.

License

MIT · Contributors · Brand assets