constle docs constle docs pre-1.0

Why Constle

A guardrail inside the agent shares the agent's fate. Outside the agent is where enforcement starts, not where it ends.

On this page

Outside the agentLink to this section

A check that runs in the agent's process, or a rule the model reads in its prompt, is exposed to the same injected text that steers the agent. Constle's checks run in a separate host process, at points the agent's traffic must cross: the egress proxy, the MCP gate, the agent-to-agent gate and the supervisor. See Architecture.

Many runtimes now enforce from outside the agent. Constle is built around four further choices.

Four choicesLink to this section

Evidence you can check yourselfLink to this section

With an identity declared, every audit entry is signed and chained to the one before it. constle audit verify runs offline and names the line where an edit, a deletion or a reordering breaks the chain. It also re-checks every signed approval the log records. What an intact chain does and does not prove is in Audit log and verification.

The agent's TLS is never interceptedLink to this section

Constle decides on the destination name and puts no certificate authority inside the sandbox. The cost is stated, not hidden: no per-path rules for allowed hosts, no spend metering of that traffic, and API keys you declare are passed into the sandbox.

Decisions at the tool-call boundaryLink to this section

A named tool call waits for a person. A signed decision must match the exact call it answers, and by default, with no answer, the call is refused and the run stops. Per-run and per-day spend caps on priced tool servers stop the run once a metered charge crosses them. See Human gates and Spend caps.

One contract per run, labelled honestlyLink to this section

Every Agentfile field is marked enforced, validated, declared or informational, and the runtime reads the Agentfile once, when the run starts: nothing changes the policy while the agent runs. A cap with nothing to meter is reported as NOT ENFORCED instead of looking real. See The Agentfile.

What Constle doesn't try to beLink to this section

It is not a fleet platform, not an agent framework and not a filesystem policy engine. It is one CLI that runs agents on the machine it is installed on, with Docker or Firecracker. Read the Known limitations before you rely on it, and What Constle is not for the rest.

QuestionsLink to this section

How is Constle different from other agent-safety platforms?Link to this section

Several platforms now run agents in sandboxes and enforce policy outside the agent's process. Some go further than Constle in places it does not go: they inspect HTTPS traffic to apply per-path API rules and to inject credentials, confine the filesystem, manage fleets of sandboxes on Kubernetes, or add hardware monitoring. If you need those, start there; Constle does not do them.

Constle is narrower, and it makes four choices on purpose:

  1. It never intercepts the agent's TLS. Egress is allowed or refused by destination name. No certificate authority is placed inside the sandbox.
  2. It leaves evidence you can verify yourself. With an identity declared, the audit log is signed and hash-chained. constle audit verify checks it offline and names the line where a change breaks the chain.
  3. It decides at the tool-call boundary. It holds named MCP calls for a human, accepts only signed decisions that match the exact call, and refuses by default when nobody answers. It enforces per-run and per-day spend caps on priced tool servers.
  4. It labels its own contract. Every Agentfile field says whether the runtime enforces it, and validate warns about every control that won't be enforced.

The trade-offs are real. API keys you declare are visible inside the sandbox. There is no filesystem policy. Constle is pre-1.0 and maintained by one person. The Known limitations list where each rule stops.

Does Constle read my agent's traffic?Link to this section

It never intercepts the agent's TLS. For traffic to allowed hosts, the proxy sees where the agent connects (host and port) and how many bytes moved, and nothing of what is said; that is also why such traffic is not metered for spend. MCP tool calls are different by design: the agent sends them to Constle's gate, which reads each call to apply tool allowlists, approvals and metering, and a gated call's arguments go to your approval endpoint.

Can I use Constle together with guardrails inside my agent?Link to this section

Yes. They cover different things. In-agent guardrails judge content: what the model is asked and what it says. Constle governs reach: where the agent can connect, which tools it can call, what it may spend, and what gets recorded. Neither replaces the other. A worked example of the second half: Contain prompt injection.

Where is the source?Link to this section

The documentation is published first. The source, the installers and signed releases are not public yet. Until they are, these docs give no install commands or repository links, because you could not open them. See Project status.