Inspiration
AI agents are becoming autonomous workforce members—reading files, sending emails, merging PRs, querying databases. But there's been nothing stopping them from making destructive calls. We built AgentGuard because autonomous agents need autonomous security: policy-as-code guardrails that enforce RBAC, rate limits, time windows, and PII redaction before any tool executes.
What it does
AgentGuard sits between your agent and its tools, evaluating every tool call before execution. Denied calls never run; allowed calls can have sensitive data redacted on the fly. Every decision is written to a SHA-256 hash-chained audit log and streamed live to a real-time dashboard for compliance and incident response.
Key capabilities:
Policy enforcement: allow, deny, or redact based on YAML rules RBAC: guest, reader, developer, admin roles with different tool access Rate limiting & time windows: per-agent quotas and business-hours-only access PII redaction: SSN, credit card, email masking before data touches disk Tamper-evident audit chain: verifiable SHA-256 hash chain for compliance Automatic tool selection: LLMs only see tools their role permits, saving tokens Multi-tenant isolation: per-tenant policy and audit databases MCP server mode: run AgentGuard as a read-only tool for Claude Desktop
How I built it
AgentGuard is a multi-package TypeScript monorepo built on the Volcano ADK. -Core (@agentguard/core): wrapMCP() interceptor that sends every tool call to the sidecar before execution -Sidecar: Fastify-based policy engine with SQLite audit store (node:sqlite), WebSocket live feed, Slack alerting, and OpenTelemetry traces/metrics -Dashboard: React 18 + Vite + TailwindCSS UI showing live decisions, KPIs, agent status, and policy viewer -CLI: init, serve, validate, audit-verify, doctor, export-audit, mcp commands for scaffolding and compliance workflows -Policy language: plain YAML with hot-reload, no custom DSL—rules support RBAC, rate limits, time windows, and regex-based data classification -The system is containerized as multi-arch Docker images (amd64 + arm64), hardened with CSP/HSTS, SSRF guards, per-IP rate limits, and PII log scrubbing.
Challenges I ran into
-Zero-trust without breaking agents: designing a default-deny policy model that still lets legitimate workflows run smoothly required careful rule design and the failClosed option for resilience. -Tamper-evident logging: implementing a correct SHA-256 hash chain in SQLite that can be verified end-to-end without native dependencies. -Tool filtering for LLMs: ensuring listTools() only returns permitted tools to the LLM while keeping the wrapper transparent to agent code. -Production hardening: adding CSP, HSTS, body-size caps, SSRF guards, and PII scrubbing without complicating the developer experience.
Accomplishments that I am proud of
-End-to-end policy enforcement: every tool call evaluated pre-execution with allow/deny/redact decisions and live dashboard visibility. -Verifiable audit chain: deterministic, hash-chained logs that can be cryptographically verified for compliance audits. -Multi-agent crew support: full Volcano SDK orchestration (.then(), .parallel(), .branch(), .forEach()) with per-agent role enforcement. -Zero native dependencies: using Node's built-in node:sqlite means no compilation headaches across platforms. -Hot-reloadable policies: policy changes apply instantly via /policies/reload with zero downtime.
What I learned
-Policy-as-code works: plain YAML rules are easier for teams to adopt than custom DSLs, and hot-reload makes iteration fast. -LLM tool filtering saves tokens: hiding disallowed tools from the model prevents wasted attempts and reduces prompt complexity. -Security must be transparent: wrapping MCP handles means existing agent code works unchanged while gaining guardrails. -Compliance needs verifiability: hash-chained audit logs provide cryptographic proof that logs haven't been altered.
What's next for AgentGuard
-Expanded data classifiers: more PII patterns (global IDs, phone numbers, addresses) and custom regex libraries. -Policy templates: industry-specific packs (GDPR, HIPAA, SOC2) with pre-built rules and exportable compliance reports. -Advanced orchestration: deeper integration with agent workflows, conditional branching based on policy outcomes, and automated remediation. -MCP ecosystem: broader MCP server integrations (Slack, GitHub, Jira, databases) with role-aware tool exposure. -Enterprise features: SSO/SAML, fine-grained audit retention policies, and multi-region audit replication.
Built With
- cli
- docker
- fastify
- hot-reload
- mcp
- monorepo
- multi-tenant
- node.js
- otel
- pii
- policy-as-code
- protection
- rbac
- react
- sha-256
- sqlite
- ssrf
- tailwindcss
- typescript
- vite
- volcanoadk
- websocket
- zero-trust
Log in or sign up for Devpost to join the conversation.