agent-safe-pipeline
View on GitHubReference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.
TypeScript reference architecture enforcing an authorization boundary for AI agents: agents propose immutable intents, an independent policy engine returns ALLOW/ESCALATE/BLOCK, verified human approval issues a single-use execution grant, and a SafeExecutor runs only granted actions with verifiable audit dossiers.
Use Cases
Built With
- Language
- TypeScript
- Frameworks
- Node.js · TypeScript · pnpm · MCP · Hono · Vitest · ESLint · Prettier · Docker · GitHub Actions
Tags
ai-agents · agent-permissions · agent-safety · authorization · human-in-the-loop · policy-as-code · execution-authority · audit-trail · mcp · zero-trust · intent-binding · single-use-grant · verifiable-evidence · reference-architecture · typescript