OpenAPPA is an open-source guardrail system that sits between an AI agent and its tools and decides whether data may be sent to a destination before each action runs. Its underlying APPA (Agentic Permissions Policy Algebra) tracks the sensitivity and trust of data read by an agent, then evaluates tool calls against declarative TOML policies. Unlike probabilistic classifiers and PII detectors, the engine is deterministic: it makes the same decision for the same event log, uses no network or file calls during evaluation, and can run in-process or as a sidecar. The project measures both security and usefulness on Bench-Corp, which contains 20 multi-step enterprise workflows, and AgentThreatBench, based on the OWASP Top 10 for Agentic Applications, using standard and adversarial prompts. OpenAPPA reports that no scored attack succeeded across 1,320 evaluations while task completion remained at 88–90%. In the displayed comparison, OpenAPPA Claude Auto mode completed 89% of tasks with 0% successful attacks, compared with 90% and 10% for Claude Code auto mode and 41% and 31% for Microsoft FIDES, respectively. The repository offers a Claude Code playground and allows developers to embed the APPA runtime in agents written in any language or connect agents through hooks. Archestra's 1.4 release candidate is described as supporting OpenAPPA through an LLM proxy for Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, n8n, and other compatible agents. The CLI can validate configurations and replay scripted tool calls, including in CI before merges. OpenAPPA is currently marked as a preview and RFC, so its configuration and wire interfaces may change. Its formal algebra and recovery guarantees are presented in a paper accepted to the NeurIPS 2026 Workshop on Agents in the Wild.
