GitHub radar

Agent-Safe Pipeline: Auth Boundary for AI Agents

A reference architecture by Decionis that puts an independent authorization checkpoint between what an AI agent proposes and what actually executes — ALLOW, ESCALATE for human review, or BLOCK.

01decionis/agent-safe-pipeline 534TypeScript

Agent-Safe Pipeline is a TypeScript reference implementation built by Decionis that adds an independent authorization layer to AI agents. The agent captures its proposed action as an immutable intent, the Decionis policy service evaluates it and returns ALLOW, ESCALATE, or BLOCK, and a SafeExecutor runs the action only after a valid single-use grant. For escalations, a Presence service collects verified human approval before Decionis re-evaluates. The repo includes runnable examples: refunds, GitHub deploys, procurement, and MCP tool gating.

Why a vibe-coder should care

When you build an AI agent that handles real money, deploys code, or touches production data, you need more than trust — you need a hard boundary that the agent cannot cross without explicit authorization. This gives you that boundary as runnable, documented TypeScript you can adapt today.

Open on GitHub