renker-core-authz
Python · open source

Deterministic authorization for AI agent actions — decided outside the model.

Guardrails built inside an LLM can be talked around. An injected instruction changes what an agent requests — not what it is allowed to do, if the decision lives in a small deterministic function that reads only trusted grants.

View on GitHubRead the README

What it does

Capabilities

Immutable, least-privilege grants: one action verb plus one path scope.

Policy engine

evaluate() returns ALLOW / DENY / REQUIRE_APPROVAL with an explainable reason.

Tamper-evident audit

sha256 hash chain with head anchor, verify() and query().

GuardedFilesystem

Least-privilege file access behind the decision.

Zero runtime deps

Standard library only. Python 3.11+.

Honest limits

Read this first. Audit is tamper-evident, not immutable. The library provides no cryptographic authentication of actors; it decides, it does not identify.

Runnable demo

renker-agent-demo — An MCP server that blocks a prompt-injection exfiltration attempt without the agent's cooperation.