PulseGate's liveness check found it on 13 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 27 Jun 2026. How this is checked
Keel is a policy and audit layer designed for autonomous, tool-using agents, providing persistent safety policies and cryptographic audit trails. It addresses the need for enforceable, reviewable constraints on agent actions, making unsafe or high-risk operations more explicit and subject to structured approval. Keel stores policies on disk rather than in prompts, ensuring that constraints persist through context compaction and session restarts.
The tool operates in three modes: instructions-only, CLI, and cloud. In instructions-only mode, it requires no dependencies and supports tiered risk classification, structured approval flows, a local policy store, write-ahead logging in plain text, blast radius caps, and context compaction survival. The CLI mode, installable via pip, adds cryptographic integrity through a SHA-256 hash-chain write-ahead log, deterministic policy evaluation, chain integrity verification, fidelity self-checks, and structured JSON output. Cloud mode extends functionality to include synchronized policies, a dashboard, multi-agent coordination, and compliance exports, with automatic routing when a cloud API key is set.
Keel enforces a risk-based approval system with four tiers, ranging from read-only actions (T0) to irreversible operations (T3), each with escalating approval requirements. The agent is responsible for classifying each action before execution, and ambiguous cases default to the highest risk tier. Approvals must be explicit and demonstrate understanding; vague confirmations are not accepted. Every action, approval, and policy decision is logged to an append-only, tamper-evident hash chain, making the audit trail resistant to tampering and suitable for compliance and review.
Keel is local-first but offers optional cloud sync for users who require policy synchronization and multi-agent management. It works with any agent capable of executing shell commands, including Claude Code, Codex, and custom agents, by invoking the CLI for policy checks and audit logging. Integration with agent frameworks via MCP server is planned for the future. The tool is developed by Threshold Signalworks Ltd, based in Limerick, Ireland.
Keel is an AI security & guardrails project. It focuses on ensuring persistent, auditable safety and compliance for autonomous agent actions through deterministic policy checks. Keel is an open-source project aimed at AI developers and safety engineers. Keel is open source under the BUSL-1.1 license. It ships for the command line.
It is developed by Threshold Signalworks, and it first shipped in 2026. Key capabilities include policy enforcement, audit trails, and deterministic evaluation. It exposes integrations via an MCP server.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do