v1.9.1 · Open-source control for AI agents

Let agents move fast. Keep the final say.

Rampart places a policy boundary between AI agents and the tools they use. Routine work continues. Your rules block prohibited actions. When an integration supports approval, consequential decisions come back to you.

  • Local-first
  • Open source
  • Built for real agent workflows

The boundary

Give access
a precise edge.

A tool request has a name, a target, and consequences. Rampart evaluates the action your integration exposes against your policies.

Example request read → ~/.ssh/id_ed25519

Standard policy: block-credential-access

Matches **/.ssh/id_*; public keys ending in .pub are excluded.

The decision

Your rules.
A visible record.

The matching policy denies the request. The decision enters the audit trail, with the rule and action connected for review.

Private-key readDenied Matching policyblock-credential-access Decision recordedAudit trail

This example illustrates a configured boundary. An audit decision does not prove that an action executed.

The boundary evaluates what the integration exposes

The premise

Autonomy
needs an edge.

Agents are useful because they can act. That same access can turn a bad instruction, poisoned context, or confident mistake into a real system change.

Rampart gives that access a boundary.

Define what can proceed, what needs approval, and what must stop.

Precisely scoped. Rampart evaluates actions delivered through configured hooks, plugins, proxies, APIs, and process boundaries. It is a control layer, not a sandbox or a claim of universal interception. Read the threat model

ALLOW

Routine work moves through.

ASK

Approval-capable integrations return consequential actions to a human.

DENY

Rules deny prohibited requests at the configured boundary.

WATCH

Activity stays visible without interruption.

Put it to work

From installed
to inspected.

A working boundary starts with the integration you actually use. Install Rampart, configure protection, then check what that setup can prove.

  1. 01

    Install

    One binary. Policies you can read and change.

    brew install peg/tap/rampart
    Linux, macOS & Windows installation
  2. 02

    Protect

    Discover supported installed tools and configure their Rampart boundary.

    rampart protect
    Follow the quickstart
  3. 03

    Verify

    Run safe canaries and read the evidence level for each configured integration.

    rampart verify --all
    Understand verification coverage

Verification does not invoke a model or execute the represented actions. Host verification and adapter checks provide different evidence; the result tells you which boundary was checked.

Meet your tools where they act

One policy layer.
Specific boundaries.

Use the integration's documented path. Protection, approval, and failure behavior depend on what the host exposes.

Managed native guard

OpenClaw

Connect the bundled plugin to Rampart's local policy service. A live plugin-boundary verifier checks the configured installation.

rampart protect openclaw OpenClaw setup and limits

Native hooks

Claude Code

Apply local policy through the native hook interface. Verification checks installed configuration and adapter behavior; it does not prove host ingestion.

rampart setup claude-code Claude Code setup and limits

Codex, Cline, Copilot, MCP, and more.
Support levels and approval paths vary. Experimental integrations stay clearly labeled.

See the complete support matrix

Know the boundary

Control you
can account for.

Policy you own

Readable rules decide which represented requests may proceed, need approval, or must be denied.

Explore the policy schema

A decision trail

Hash-chained records connect actions and policy decisions. Detecting a complete local rewrite requires evidence retained independently.

Understand audit guarantees

A precise scope

Allowed programs can have effects beyond their represented request. Pair Rampart with appropriate credentials, resource permissions, sandboxing, and egress controls.

Read the architecture and threat model

Your tools. Your authority.

Build with room to move.