v1.9.1 · Open-source control for AI agents
Let agents move fast.
Keep the final say.
Rampart places a policy boundary between AI agents and the tools they use. Routine work continues. Your rules block prohibited actions. When an integration supports approval, consequential decisions come back to you.
- Local-first
- Open source
- Built for real agent workflows
The boundary
Give access
a precise edge.
A tool request has a name, a target, and consequences. Rampart evaluates the action your integration exposes against your policies.
Example request
read → ~/.ssh/id_ed25519
Standard policy: block-credential-access
Matches **/.ssh/id_*; public keys ending in .pub are excluded.
The decision
Your rules.
A visible record.
The matching policy denies the request. The decision enters the audit trail, with the rule and action connected for review.
Private-key readDenied
Matching policyblock-credential-access
Decision recordedAudit trail
This example illustrates a configured boundary. An audit decision does not prove that an action executed.