Security & Trust

REVIEWABLE
SCOPE,
CLEAR LIMITS.

Guardrail makes a command's intended scope explicit, records operator acknowledgement, and blocks compared contract drift. It is not a sandbox or a containment boundary.

12
Exit code for contract drift
22
Exit code for a broken audit chain
25
Bundled recipe manifests
0
Hosted Guardrail services
⚠
Important boundary: Guardrail does not isolate processes, restrict syscalls, replace a container, or make an untrusted binary safe. Use operating-system controls for containment.

ARCHITECTURE

The current release is a local-first command and workflow supervision layer.

✓
Normalized execution contracts
Guardrail records the command, arguments, working directory, path scope, environment policy, mode, risk assessment, and workflow settings in deterministic contract data.
≠
Exact reuse comparison
A matching approved manifest can be reused. A compared contract difference returns Exit 12 in non-interactive mode and requires review.
👤
Operator acknowledgement
Interactive guardrail run shows the contract and stores an acknowledgement after the operator types APPROVE. The manifest is not an identity signature.
⌁
Grant-owned delegation
The stdio MCP server exposes only capabilities present in an operator-owned grant. Describe, prepare, and approval stages fail closed when required authority is unavailable.
More info — how execution works

RUNTIME GUARANTEES

These are the useful, implemented boundaries to rely on in Guardrail 1.0.0.

G-1Contract drift is explicit▾
A changed command, argument, working directory, path scope, environment rule, execution mode, or compared workflow field does not silently reuse the old manifest. Non-interactive reuse exits 12.
G-2Risk is computed from the resolved contract▾
Generated or unknown provenance, shell-mode install/destructive commands, system paths, production targets, writes outside the repository, privilege changes, and sensitive environment combinations can escalate a contract to RED and strong confirmation.
G-3Workflow transitions are validated▾
Definitions declare an entry step, transitions, validators, and a positive maxIterations. Invalid references and non-converging workflows are rejected instead of guessed through.
G-4Delegated MCP work is bounded by the active grant▾
Agents inspect grant status and the callable inventory. A denied or missing capability is not permission to invent flags or bypass the grant with a broader raw shell path.
G-5Audit integrity can be verified locally▾
JSONL audit entries include previous, payload, and entry hashes. guardrail audit verify detects a broken local chain and reports audit-chain failure as Exit 22.
G-6Failure states stay machine-readable▾
Approval required, denial, drift, validation failure, update denial, timeout, policy violation, unsupported behavior, protocol failure, internal failure, time-policy failure, concurrency blocking, and audit-chain failure have distinct statuses.
More info — current guarantees and exit codes

DATA & PRIVACY

The shipped product stores its operational state locally. No team cloud or enterprise backend is part of the current codebase.

📄
Approved manifests
Command approval defaults to .guardrail/approved.json. Workflow manifests use their own paths. Manifests may contain absolute project context, so decide deliberately whether to commit or share them.
📚
Audit log
Command and workflow audit events default to the repo-local .guardrail/audit.jsonl.
🔑
Credentials
Recipe and adapter manifests declare environment handshakes and allowlists. Host credential storage and process isolation remain the operator's responsibility.
🌐
Network behavior
Core contract comparison is local. A command, recipe, adapter, or tool can still use the network if its reviewed contract and the host permit it.

AUDIT EVIDENCE

The local JSONL chain is queryable and tamper-evident when verified; it is not an externally anchored ledger.

⛓
Hash-linked entries
Each entry binds its payload and the previous entry hash. Editing an earlier entry breaks verification of the subsequent chain.
🔍
Verify and query
guardrail audit verify --path .guardrail/audit.jsonl
guardrail audit query --trace-id <id>
⇩
Portable export
Use the top-level guardrail export --format json or --format csv command for downstream analysis.
⚠
Retention boundary
A local actor able to delete or replace repository state can also remove the local log. Copy evidence to operator-controlled storage when your threat model requires independent retention.

DEPLOYMENT STATUS

The website previously described commercial tiers that are not present in the current codebase. This page now separates shipped behavior from future possibilities.

CURRENT LOCAL RELEASE

Guardrail 1.0.0. Local CLI, workflows, templates, recipes, lanes, adapters, policies, audit tools, and delegated stdio MCP.

✓
Runs without a hosted Guardrail account
Approval manifests, grants, and audit state are local files.
✓
Bounded automation primitives
Commands, workflow definitions, templates, 25 bundled recipes, resident lanes, adapter profiles, and policy checks.
✕
No sandbox boundary
Pair Guardrail with containers, OS permissions, secret stores, and network controls appropriate to the workload.

TEAM SERVICE

Not shipped in the current repository.

—
No hosted manifest synchronization
Share local artifacts only through infrastructure and review processes you operate.
—
No hosted organization approval service
Current approvals are interactive local acknowledgements, MCP host elicitation, or queued compatibility requests.
—
No hosted telemetry pipeline
Use local query/export and your own log collection if needed.

ENTERPRISE SERVICE

Not shipped in the current repository.

—
No SAML, SCIM, hosted RBAC, or organization backend
Do not treat these as current product capabilities.
—
No VPC or hosted on-prem distribution
The shipped project is a source-distributed Node.js CLI requiring Node.js 20 or later.

PORTABILITY

The current artifacts are inspectable local files and source-controlled recipe definitions.

📄
Manifests are JSON
Inspect, diff, archive, or remove them using your normal repository and filesystem controls.
📊
Audit is JSONL
Verify the chain locally and export JSON or CSV without calling a Guardrail service.
🔧
Recipes are JSON
Validate, pack, inspect, install from explicit sources, or export a self-hosted registry snapshot.

REVIEW THE CURRENT CLI.

Start from the source checkout and inspect the exact contract before approval.