Python · open source
Deterministic authorization for AI agent actions — decided outside the model.
Guardrails built inside an LLM can be talked around. An injected instruction changes what an agent requests — not what it is allowed to do, if the decision lives in a small deterministic function that reads only trusted grants.
View on GitHubRead the READMEWhat it does
Capabilities
Immutable, least-privilege grants: one action verb plus one path scope.
Policy engine
evaluate() returns ALLOW / DENY / REQUIRE_APPROVAL with an explainable reason.
Tamper-evident audit
sha256 hash chain with head anchor, verify() and query().
GuardedFilesystem
Least-privilege file access behind the decision.
Zero runtime deps
Standard library only. Python 3.11+.
Honest limits
Read this first. Audit is tamper-evident, not immutable. The library provides no cryptographic authentication of actors; it decides, it does not identify.
Runnable demo
renker-agent-demo — An MCP server that blocks a prompt-injection exfiltration attempt without the agent's cooperation.