Apache 2.0Pre-1.0 · managed cloud and self-hosted previewsRead the open-source commitment

Decision plane

Control discovery and execution with the same decision.

Hide disallowed capabilities before discovery and enforce the decision again when a caller attempts execution.

Product boundary

The current policy slice filters tool discovery, rechecks execution, and explains deterministic decisions. Authoring and distributed activation are still preview work.

Available now
Behavior backed by the current local vertical slice and automated tests.
Preview
Useful implementation exists, but the complete operating journey is not proven.
Planned
Part of the open MCP-native roadmap, not current product behavior.
Deployment
Managed cloud and self-hosted targets share portable packages; live parity remains an acceptance test.

Capabilities

What policy controls

Status labels distinguish tested behavior from useful previews and the open roadmap.

01Available now

Capability filtering

Shape tools/list for each scoped principal; resources, prompts, and skills remain planned protocol surfaces.

02Available now

Execution enforcement

Re-evaluate policy at invocation so hidden tools cannot be called by guessing a name.

03Preview

Human approval

Pause sensitive actions and bind a pending record to the exact request; independent decision and resume are not shipped.

04Available now

Decision simulation

Test a principal and action before deployment with a trace of every matched rule.

Operating flow

The target journey, with current maturity called out above.

01

Describe

Express subjects, capabilities, conditions, limits, and approval requirements.

02

Simulate

Inspect the allow or deny result and the exact rules that produced it.

03

Enforce

Apply the versioned policy at discovery, routing, and execution boundaries.

Target control surface

Designed for platform and security teams.

These controls define the intended product boundary; the capability labels above are the current implementation record.

  • Role and group bindings
  • Data classification rules
  • Rate and concurrency limits
  • Egress restrictions
  • Time-bound approvals
  • Decision audit trail

Evaluate locally or inspect either deployment target.

The managed cloud and Kubernetes paths are previews of one open codebase, with no intended capability gate or mandatory call-home path.