About this project
OpenAPPA is a policy enforcement layer placed between an AI agent and its tools. Before each action, it answers whether the data involved is allowed to go to the requested destination. The runtime tracks sensitivity and trust for information the agent reads and applies that history to subsequent tool calls, with the goal of preventing sensitive data from reaching unauthorized tools.
The system uses APPA, Agentic Permissions Policy Algebra, and policies are written in declarative TOML. According to the README, decisions are produced from the event log alone, and the engine makes no network or file calls during evaluation, so the same log should produce the same decision repeatedly. It can be embedded in-process or run as a sidecar that inspects calls before they execute.
Integration paths include a Claude Code plugin for experimentation, an embeddable runtime for custom agents, agent hooks, and proxy-level use through Archestra. The README states that Archestra's release candidate supports Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and agents communicating through an LLM proxy.
For policy development, the APPA CLI provides `appa describe --check` for configuration validation and `appa replay` for checking scripted tool calls against expected decisions. These checks can be run locally or added to CI.
The project reports evaluations on Bench-Corp and AgentThreatBench, including standard and adversarial prompts. Its published results claim no scored attack succeeded in 1,320 evaluations while task completion was 88–90%; comparisons with Microsoft FIDES and Claude Code auto mode are also presented. These are project-reported benchmark results rather than independently verified conclusions here.
OpenAPPA is labeled a preview and RFC. The README warns that configuration and wire interfaces may change without compatibility shims. The formal algebra and recovery guarantees are described in a paper accepted to a NeurIPS 2026 workshop. The repository is MIT licensed.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.