Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
OpenLatch is the execution control layer for enterprise AI agents. It turns human intent into Agent Intent Policies across each agent's Autonomy Zone — security, safety, compliance, economics and quality — and makes a deterministic decision on every covered action before it executes: allow, ask, block or optimize.
This repository is its open-source capture-and-enforce adapter: the node that runs inside a coding agent's own execution path, evaluates every covered action against that agent's Autonomy Zone before it runs, and is what gives an agent the control level Enforced.
It plugs into the agent's native lifecycle hooks, decides locally and in-process, and forwards what it saw to the platform afterwards. The agent never waits on the network, and the verdict never depends on it.
Quick start
openlatch status shows what is captured and enforced on this host. The dashboard shows the events and the verdicts. Full walkthrough: Getting started.
The installer runs on Node.js. macOS, Windows and Linux are supported.
How it works
┌─────────────────────────────────────────────────────────────────┐
│ Developer's machine │
│ │
│ ┌──────────┐ hook event ┌──────────────────────────────┐ │
│ │ Coding │──────────────▶│ OpenLatch client │ │
│ │ agent │ │ (127.0.0.1) │ │
│ │ │ │ │ │
│ │ │ │ 1. Wrap in envelope │ │
│ │ │ │ 2. Evaluate resident │ │
│ │ │ │ policy in-process │ │
│ │ │ ◀─ verdict ──│ 3. Redact credentials │ │
│ └──────────┘ │ 4. Write local audit log │ │
│ │ 5. Batch → forward │────┼──▶ OpenLatch platform
│ │ ◀── policy bundle │◀───┼── (policies, analysis,
│ └──────────────────────────────┘ │ dashboard)
└─────────────────────────────────────────────────────────────────┘
- Inside the agent, not a proxy in front of it. The decision point is the agent's own hook lifecycle, so it sees the action rather than the traffic. Model calls additionally pass through a loopback listener, so cost and token usage are measured on the same host.
- Local-authoritative. The resident policy bundle is the authority, not a cache of one. Evaluation reads an in-memory handle and returns.
- Fail-static, not fail-open. A resident bundle keeps enforcing offline, forever. A failed refresh keeps the last known good.
- Privacy-first. Credentials are redacted locally before anything leaves the machine.
What a verdict does
The verdict vocabulary is Allow, Ask, Block or Optimize. What this client can express today is narrower than the vocabulary, and this is the honest map of it. A verdict is deterministic because an explicit policy produced it.
| Verdict | On the wire / in the bundle | What this client does today |
|---|---|---|
| Allow | allow, approve |
The action proceeds. approve is a user-confirmed allow |
| Ask | No wire variant — an allow / approve carrying context |
Rendered to Claude Code as permissionDecision: "ask", the alert as its reason. It allows and flags; it does not hold the agent waiting on a human. It prevents recurrence, not the first occurrence |
| Block | deny — the only action a kind=command rule may take |
Reaches the agent as a native deny at pre_tool_use, naming the rule that produced it |
| Optimize | kind=request rules: prefix_reorder, history_trim, prompt_edit |
Measurement only. Out of the box the boundary observes, reports what a transform would have saved, and forwards the original bytes |
Each rule runs in Monitor (record the match, allow the action) or Enforce (apply the verdict). Most restrictive wins across matching rules.
Supported agents
| Agent | Control level | Notes |
|---|---|---|
| Claude Code | Enforced | macOS, Windows and Linux, across its 12 lifecycle hook events. Verdicts are delivered in the agent's own hook-output shape |
| Cursor · Windsurf · GitHub Copilot · Codex CLI · Gemini CLI · Cline · OpenClaw | Recognised | Their events store and attribute correctly; init cannot install their hooks yet |
Making an agent Enforced is a hook binding plus a verdict translator. Both are contributions we welcome — see Contributing.
Behind a corporate proxy
init finds the route on its own: it probes what is already configured, then walks the OS's own proxy settings (Windows, macOS, GNOME), and only asks if none of them reach the platform. Kerberos/Negotiate uses the logged-on identity; a TLS-inspecting proxy needs only its root CA in ca_bundle. Proxy credentials go to the OS keychain, never to a file.
The hosts to open, every [proxy] key and every OL-122x code: docs/egress.md.
Configuration
openlatch init writes ~/.openlatch/config.toml, and every key has an OPENLATCH_* environment variable that overrides it. Precedence is CLI flags → environment → config.toml → defaults. The full list is in docs/configuration.md.
Documentation
| Where | What |
|---|---|
| openlatch.ai/docs | Installation, getting started, how it works, FAQ, privacy |
| docs/configuration.md | Environment variables, config.toml, what the daemon writes into the agent's config |
| docs/egress.md | Proxies, the hosts to open, Kerberos, troubleshooting codes |
| docs/cli.md | Command reference, health reports, exit codes |
| docs/evaluate-protocol.md | Evaluation process frames, caller-owned session state, errors and diagnostics |
| CHANGELOG.md | What changed in each release |
Contributing
&&
Never run a development build against your own install: openlatch init rewires every live agent session on the host. The Contributing Guide covers the sandbox that prevents it, the checks CI runs, Conventional Commits and the PR process; AGENTS.md states what the client does and what it deliberately does not.
Pick a good first issue, or join us on Slack.
Security
- Report vulnerabilities to security@openlatch.ai; private vulnerability reporting is enabled on this repository
- Releases are built with SLSA provenance via GitHub Actions
- Full policy: SECURITY.md
License
This client is licensed under Apache-2.0. The OpenLatch platform — policy authoring, analysis and the dashboard — is a commercial product; see openlatch.ai.