Guides
Each guide starts from one job, shows the Agentfile that does it, and ends with what Constle enforces for that job and what it leaves to you.
Source release coming soon
The source, the installers and signed releases are not public yet, so there is nothing to install today. The guides document Constle as it behaves now. More in Project status.
Every guide follows the same shape: what you get, the concept in a few lines, the Agentfile, the commands, then a section on where enforcement stops, linked to the Known limitations. Read that section before you rely on a guide.
Start hereLink to this section
- Agentfile in 5 minutes: write a first Agentfile, read what
constle validatetells you, and avoid the fields that parse and do nothing. - Sandbox an AI coding agent: run a CLI coding agent headless in a sandbox with one allowed API host and only the variables you declare.
Network and toolsLink to this section
- Stop an AI agent exfiltrating data: an egress allowlist the agent cannot step around, and the channels it still leaves open.
- Lock down MCP servers: put every remote MCP server behind a gate, with a tool allowlist the agent cannot skip.
- Require human approval for MCP tool calls: hold a named tool call until a person approves it, and refuse it when nobody answers.
- Cap what an AI agent can spend: per-run and per-day caps on priced tool calls, and the spending they do not cover.
Containment and evidenceLink to this section
- Contain prompt injection: assume an injected instruction succeeds, then limit what it can reach, call, spend and how long it runs.
- Give each AI agent a verifiable identity: one
did:keyper agent, a private key that never enters the sandbox, and what it signs. - Verify what an AI agent did: read the signed audit log and check it offline, pinned to the identity you expect.
The concepts behind themLink to this section
The guides link to these pages for the detail: Architecture, Network isolation, Human gates, Spend caps and metering, Audit log and verification, Identity and the Field reference.