REVIEWABLE
SCOPE,
CLEAR LIMITS.
Guardrail makes a command's intended scope explicit, records operator acknowledgement, and blocks compared contract drift. It is not a sandbox or a containment boundary.
ARCHITECTURE
The current release is a local-first command and workflow supervision layer.
guardrail run shows the contract and stores an acknowledgement after the operator types APPROVE. The manifest is not an identity signature.RUNTIME GUARANTEES
These are the useful, implemented boundaries to rely on in Guardrail 1.0.0.
maxIterations. Invalid references and non-converging workflows are rejected instead of guessed through.guardrail audit verify detects a broken local chain and reports audit-chain failure as Exit 22.DATA & PRIVACY
The shipped product stores its operational state locally. No team cloud or enterprise backend is part of the current codebase.
.guardrail/approved.json. Workflow manifests use their own paths. Manifests may contain absolute project context, so decide deliberately whether to commit or share them..guardrail/audit.jsonl.AUDIT EVIDENCE
The local JSONL chain is queryable and tamper-evident when verified; it is not an externally anchored ledger.
guardrail audit verify --path .guardrail/audit.jsonlguardrail audit query --trace-id <id>guardrail export --format json or --format csv command for downstream analysis.DEPLOYMENT STATUS
The website previously described commercial tiers that are not present in the current codebase. This page now separates shipped behavior from future possibilities.
CURRENT LOCAL RELEASE
Guardrail 1.0.0. Local CLI, workflows, templates, recipes, lanes, adapters, policies, audit tools, and delegated stdio MCP.
TEAM SERVICE
Not shipped in the current repository.
ENTERPRISE SERVICE
Not shipped in the current repository.
PORTABILITY
The current artifacts are inspectable local files and source-controlled recipe definitions.
REVIEW THE CURRENT CLI.
Start from the source checkout and inspect the exact contract before approval.