Lelu – catch AI agents when they're manipulated at runtime
Okta for who can access, Lelu for when agents are being manipulated.
Open source authorization engine for AI agents. Confidence-aware gating · Human-in-the-loop review · Policy-as-code · Full audit trail
Four decision outcomes including compute redirect—prompt injection detected before policy runs.
Teams deploying AI agents with privileged access
OPA · Casbin · AWS Verified Permissions
Okta for who can access, Lelu for when agents are being manipulated.
AST-verified AI code audits prevent hallucinations; LLM findings checked against parser ground truth.
The idea of inserting a deterministic 'gate' between proposed tool calls and execution is smart and practical: precomputed classification plus an agent-unreachable vault means destructive operations become reversible by default. The README calls out clear mechanics (envelope checks, vault backup, tiered responses and structured denials) which suggests this is more than a thought experiment — it's a focused infra piece for teams that actually let agents touch production.
Deterministic agent governance with capability tokens beats probabilistic guardrails.
Authority gating for autonomous systems with reproducible safety evidence and formal assurance report.
OAuth for agents with finalized v1.0 spec, but adoption is the real challenge.