STEP 01
NORMALIZE
Every command becomes a stable canonical fingerprint
▾

What happens

Guardrail turns the command, arguments, working directory, paths, environment policy, execution mode, and workflow settings into a normalized contract.

Paths resolve in the current project context and unordered allowlists are sorted before stable JSON hashing. The result is deterministic for the same normalized contract — not a promise that different machines share absolute paths.

Stable contract serialization
guardrail normalize
# structured request
command: npm
args: ["test", "--silent"]
cwd: ./project

# normalized contract
mode: structured
writablePaths: [/abs/project]

# stable hash for this contract
sha256: a3f9c12e...8b2d
✓ deterministic
STEP 02
CONTRACT FIELDS
The declared execution boundary in structured data
▾
STEP 03
RISK CLASSIFY
Computed, not declared. The engine always wins.
▾
STEP 04
REVIEW & STORE
The acknowledged manifest becomes the reusable contract.
▾
STEP 05
DRIFT DETECTION
Every re-run is compared against the acknowledged manifest.
▾
STEP 06
NEGOTIATION LOOP
Agents self-correct. Humans called only when it matters.
▾
STEP 07
AUDIT TRAIL
Local, structured, and hash-linked.
▾

The guarantees

WHAT GUARDRAIL PROMISES

These are the practical guarantees of the shipped local-first control layer — within the trust boundary documented below.

🔐
Acknowledgement is explicit

Interactive runs require a real TTY acknowledgement; delegated runs remain bounded by operator-owned grants and approval state.

⛔
Drift is always caught

The hash comparison runs on every execution. There is no mode where drift passes silently.

📉
Bound fields stay visible

Commands, arguments, paths, inputs, environment policy, and workflow settings are represented in inspectable contract data.

🧮
Risk is computed

You can declare a risk level. The engine computes independently. Higher computation always wins.

⛓
Audit is verifiable

Hash-linked local JSONL can be queried and verified for broken entry hashes or chain linkage.

🛑
Not a sandbox

Approved processes keep the caller's OS permissions. Use containers, least privilege, and reviewed binaries when containment matters.

READY TO LOCK IT DOWN?

One install. Manifest-backed execution from the first command.

Read the docs Browse recipes → GitHub ↗