{"repo":"decionis/agent-safe-pipeline","free":true,"listed":false,"github":"https://github.com/decionis/agent-safe-pipeline","clone":"git clone https://github.com/decionis/agent-safe-pipeline.git","description":"Reference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.","language":"TypeScript","stars":532,"topics":["agentic-ai","ai-agent-permissions","ai-agents","ai-governance","ai-safety","authorization","decionis","human-in-the-loop","mcp","policy-as-code"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Agent-Safe Pipeline Let agents propose. Let policy decide. Agent-Safe Pipeline is a reference architecture for executing AI-agent actions through an independent authorization boundary. This repository is a library and runnable reference implementation, not a hosted authorization service or a substitute for provider-side identity, least privilege, network isolation, and incident response. Its safety claims apply only when the documented trust boundary is preserved. Agents can reason, plan, and propose actions. They must not determine whether their own actions are authorized, possess downstream privileged credentials, or choose which trusted handler runs. Five-minute demo Requirements: Node.js 22.14 or later and pnpm 9. The demos use an explicitly non-production fixture authority. A production integration uses DecionisGate and DecionisGrantVerifier with server-side credentials. The executor accepts a captured intent and a decision. It does not accept an arbitrary callback from the agent. A sealed ActionRegistry maps action names to trusted handlers and validates parameters before consuming a single-use grant. Repository map - packages/pipeline — IntentCapture , DecionisGate , Presence coordination, and SafeExecutor . - examples/basic-agent — the smallest BLOCK flow. - examples/shopify-refund-agent — amount-based ALLOW / ESCALATE / BLOCK. - examples/github-deploy-agent — environment and force-push controls. - examples/procurement-agent — an in-budget software request held when e","default_branch":null,"files":null,"tree":[],"storefront":"/r/decionis","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/decionis/agent-safe-pipeline/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}