Schema-first generator for coding-agent repo policies and compatibility files.
Agent-policy interface contracts — the seam between the Phase 1.5 sovereignty stack and Phase 2 AI agents
Agent policy management with multi-level fallback (repo, local PRPM, cloud workspace)
An ACP-compatible coding agent powered by the Claude Agent SDK (TypeScript)
Open Policy Agent WebAssembly SDK
AgentShield LangChain integration — callback handler for AI agent policy governance
Linux x64 binary for agent-policy
Ollama integration for the Agent Policy Specification (APS)
Linux arm64 binary for agent-policy
CLI tool for QSVA — initialize, visualize, and monitor your AI agent policy enforcement
macOS x64 binary for agent-policy
macOS arm64 (Apple Silicon) binary for agent-policy
Windows x64 binary for agent-policy
OCI NodeJS client for Compute Instance Agent Service
Mastra integration for the Agent Policy Specification (APS)
MCP Server for AI agent policy enforcement - PII detection, guardrails, GDPR/EU AI Act compliance, audit logging, and emergency kill switch
Core TypeScript implementation of the Agent Policy Specification (APS)
Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies
OCI NodeJS client for Management Agent Service
OCI NodeJS client for Generative Ai Agent Service
Vendor-neutral CLI to keep AI coding-agent instruction files in sync and enforce commit attribution.
Vercel AI SDK integration for the Agent Policy Specification (APS)
OCI NodeJS client for Generative Ai Agent Runtime Service
HTTP remote policy adapters for the Agent Policy Specification (APS)
Rails middleware that authorizes incoming requests against a Policy Decision Point, such as an Open Policy Agent server
AgentRuntime provides a reusable control plane for building tool-using LLM agents with explicit state, policy enforcement, and auditability.
Monitor every action, enforce policies, and automatically roll back damage from AI agents.
XCAP (RFC 4825) is a protocol on top of HTTP allowing a client (usually built within a SIP user agent) to manipulate the content of XML documents stored in a server. These documents represent per user buddy list, presence authorization policy, media content (i.e. user avatar) and other kind of features.Ruby XCAPClient library implements the XCAP protocol in client side, allowing the application to get, store, modify and delete XML documents (totally or partially) in the server.
Ruby::Rego provides a pure Ruby parser, compiler, and evaluator for the Open Policy Agent Rego language. It targets a clean, idiomatic Ruby API, deterministic evaluation, and a CLI for validation workflows.
## Overview Privileged Access Manager (PAM) is a Google Cloud native, managed solution to secure, manage and audit privileged access while ensuring operational velocity and developer productivity. PAM enables just-in-time, time-bound, approval-based access elevations, and auditing of privileged access elevations and activity. PAM lets you define the rules of who can request access, what they can request access to, and if they should be granted access with or without approvals based on the sensitivity of the access and emergency of the situation. ## Concepts ### Entitlement An entitlement is an eligibility or license that allows specified users (requesters) to request and obtain access to specified resources subject to a set of conditions such as duration, etc. entitlements can be granted to both human and non-human principals. ### Grant A grant is an instance of active usage against the entitlement. A user can place a request for a grant against an entitlement. The request may be forwarded to an approver for their decision. Once approved, the grant is activated, ultimately giving the user access (roles/permissions) on a resource per the criteria specified in entitlement. ### How does PAM work PAM creates and uses a service agent (Google-managed service account) to perform the required IAM policy changes for granting access at a specific resource/access scope. The service agent requires getIAMPolicy and setIAMPolicy permissions at the appropriate (or higher) access scope - Organization/Folder/Project to make policy changes on the resources listed in PAM entitlements. When enabling PAM for a resource scope, the user/ principal performing that action should have the appropriate permissions at that resource scope (resourcemanager.{projects|folders|organizations}.setIamPolicy, resourcemanager.{projects|folders|organizations}.getIamPolicy, and resourcemanager.{projects|folders|organizations}.get) to list and grant the service agent/account the required access to perform IAM policy changes. Note that google-cloud-privileged_access_manager-v1 is a version-specific client library. For most uses, we recommend installing the main client library google-cloud-privileged_access_manager instead. See the readme for more details.
## Overview Privileged Access Manager (PAM) is a Google Cloud native, managed solution to secure, manage and audit privileged access while ensuring operational velocity and developer productivity. PAM enables just-in-time, time-bound, approval-based access elevations, and auditing of privileged access elevations and activity. PAM lets you define the rules of who can request access, what they can request access to, and if they should be granted access with or without approvals based on the sensitivity of the access and emergency of the situation. ## Concepts ### Entitlement An entitlement is an eligibility or license that allows specified users (requesters) to request and obtain access to specified resources subject to a set of conditions such as duration, etc. entitlements can be granted to both human and non-human principals. ### Grant A grant is an instance of active usage against the entitlement. A user can place a request for a grant against an entitlement. The request may be forwarded to an approver for their decision. Once approved, the grant is activated, ultimately giving the user access (roles/permissions) on a resource per the criteria specified in entitlement. ### How does PAM work PAM creates and uses a service agent (Google-managed service account) to perform the required IAM policy changes for granting access at a specific resource/access scope. The service agent requires getIAMPolicy and setIAMPolicy permissions at the appropriate (or higher) access scope - Organization/Folder/Project to make policy changes on the resources listed in PAM entitlements. When enabling PAM for a resource scope, the user/ principal performing that action should have the appropriate permissions at that resource scope (resourcemanager.{projects|folders|organizations}.setIamPolicy, resourcemanager.{projects|folders|organizations}.getIamPolicy, and resourcemanager.{projects|folders|organizations}.get) to list and grant the service agent/account the required access to perform IAM policy changes.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.