Deploy AI agents with the control you intend.
Loaf compiles your intent into per-task, enforced guardrails: egress policy, sandbox constraints, and evidence that they held. Not a policy document an agent can reason its way around. A boundary it runs inside of.
Intent
review-pr #482, repo: loaf/site
- scope: read pr diff, comment
- egress: github.com only
- fs: repo checkout, read-only
Enforced
- connect api.github.comALLOW
- connect pastebin.exampleDENY
- write /repo/.git/hooksDENY
- read /repo/src/**ALLOW
Illustrative example, not a live product view.
Without Loaf, with Loaf
The same four controls, made concrete. Full detail on the trust page.
- Guardrails
- Without: An agent is told what not to do, and decides for itself how closely to follow that.
- With Loaf: Your intent compiles into an explicit policy before the agent starts. It can't loosen it mid-task.
- Egress policy
- Without: An agent can reach anywhere the network allows, unless someone remembers to block it.
- With Loaf: Network access is default-deny. Only the destinations a task was granted are reachable.
- Sandbox constraints
- Without: A single compromised step can touch anything the process has access to.
- With Loaf: Each run is scoped to its own boundary: filesystem, process, and resource limits, nothing more.
- Evidence they held
- Without: Whether the guardrail held is something you have to take on faith.
- With Loaf: Every run leaves a record you can check: which controls were active, and that they weren't bypassed.
Built to be verified, not just trusted
Read how each control is enforced today, and where we are honest about what is still a work in progress.
Read the trust page