About Loaf
AI agents now browse, run code, and touch real systems on someone's behalf. Most of the controls around that trust are still written down, not enforced: a policy an agent is told to follow, not a boundary it cannot cross.
Loaf takes the intent behind a task and turns it into controls that hold: what an agent can reach on the network, what it can touch on disk, and what evidence proves the boundary wasn't stepped around. You should be able to check that an agent stayed inside the lines, not just hope it did.
See how the controls work, including where we're honest about what's still in progress.