Vibe Coding Discover

AI Agents

agent-safe-pipeline

View on GitHub

Reference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.

★ 58958 forksTypeScriptApache-2.0decionis

TypeScript reference architecture enforcing an authorization boundary for AI agents: agents propose immutable intents, an independent policy engine returns ALLOW/ESCALATE/BLOCK, verified human approval issues a single-use execution grant, and a SafeExecutor runs only granted actions with verifiable audit dossiers.

Use Cases

Gate agent-proposed actions behind an independent authorization boundaryRequire verified human approval for high-risk agent actions (wire transfers, refunds, deploys)Enforce policy-as-code verdicts of ALLOW, ESCALATE or BLOCK before tool executionIssue and consume single-use intent-bound execution grantsPrevent grant replay, parameter tampering and fabricated approvalsGate MCP tool calls through the same authorization boundaryGenerate signed Decision Dossiers and offline-verifiable audit evidenceRun shadow mode to compare local and hosted policy verdicts without changing behavior

Built With

Language
TypeScript
Frameworks
Node.js · TypeScript · pnpm · MCP · Hono · Vitest · ESLint · Prettier · Docker · GitHub Actions

Tags

ai-agents · agent-permissions · agent-safety · authorization · human-in-the-loop · policy-as-code · execution-authority · audit-trail · mcp · zero-trust · intent-binding · single-use-grant · verifiable-evidence · reference-architecture · typescript