{"data":{"slug":"cordum-io-cordum","name":"cordum","tagline":"Govern autonomous AI agents with policy enforcement and audit trails.","github_url":"https://github.com/cordum-io/cordum","owner":"cordum-io","repo":"cordum","owner_avatar_url":"https://avatars.githubusercontent.com/u/248097825?v=4","primary_language":"Go","stars":494,"forks":30,"topics":["agent-framework","agentic-ai","ai-agent","ai-governance","ai-orchestration","ai-safety","audit-trail","autonomous-agents","control-plane","devops","governance","human-in-the-loop","llm","llm-agents","mcp","model-context-protocol","nats","policy-engine","safety-kernel","workflow-engine"],"archived":false,"github_pushed_at":"2026-07-31T17:56:28+00:00","maintenance_label":"Very active","url":"https://www.graphcanon.com/tools/cordum-io-cordum","markdown_url":"https://www.graphcanon.com/tools/cordum-io-cordum.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/cordum-io-cordum","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=cordum-io-cordum","description":"The action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.","homepage_url":null,"license":"Other","open_issues":16,"watchers":127,"ai_summary":"Cordum is an open agent control plane that facilitates governance over AI agents through pre-execution policies, approval gates, and comprehensive auditing, supporting frameworks like LangChain, CrewAI, and MCP.","readme_excerpt":"### Option A: Install from source\n\nOne command stands up the full stack — API gateway, scheduler, safety\nkernel, workflow engine, context engine, dashboard, NATS, and\nTLS-secured Redis — with auto-generated secrets, auto-provisioned\ncertificates, and a post-deploy smoke test that exercises a real\napproval workflow:\n\n```bash\ngit clone https://github.com/cordum-io/cordum.git\ncd cordum\n./tools/scripts/quickstart.sh\n```\n\n**Prerequisites:** Docker Desktop v4+ (or Engine v20.10+ with Compose v2,\n≥ 4 GB RAM allocated), Go 1.26.3+ (for first-run cert generation), and\n`curl`. On Windows use MSYS2 / Git Bash / WSL.\n\n**What you get at the end:**\n- Dashboard at http://localhost:8082 — log in as `admin` / `ChangeMe123!`\n  (the default dev password, also saved to `.env` as `CORDUM_ADMIN_PASSWORD`;\n  change it before exposing the stack).\n- Gateway at http://localhost:8081 with a generated `CORDUM_API_KEY` in\n  `.env`.\n- TLS CA, server, and client keypairs under `./certs/`.\n- A working approval-gate workflow proven by the built-in\n  `platform_smoke.sh` run.\n\nFull walkthrough, platform notes, and troubleshooting:\n[docs/quickstart.md](docs/quickstart.md).\n\n---\n\n## License\n\nLicensed under [Business Source License 1.1 (BUSL-1.1)](LICENSE).\n\n- **Self-host and use internally**: Permitted\n- **Modify and contribute back**: Permitted\n- **Offer as a competing hosted service**: Not permitted\n- **Change Date**: January 1, 2029 — automatically converts to Apache License 2.0\n\nSee [LICENSE](LICENSE) for full terms.\n\n---","github_created_at":"2026-01-11T16:56:02+00:00","created_at":"2026-07-11T23:13:41.58787+00:00","updated_at":"2026-08-02T06:00:27.75261+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"},{"slug":"evaluation-observability","name":"Evaluation & Observability","url":"https://www.graphcanon.com/categories/evaluation-observability","markdown_url":"https://www.graphcanon.com/categories/evaluation-observability.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/evaluation-observability"}],"tags":[{"slug":"agent-framework","name":"agent-framework"},{"slug":"agentic-ai","name":"agentic-ai"},{"slug":"ai-governance","name":"ai-governance"},{"slug":"audit-trail","name":"audit-trail"},{"slug":"autonomous-agents","name":"autonomous-agents"},{"slug":"human-in-the-loop","name":"human-in-the-loop"},{"slug":"policy-engine","name":"policy-engine"},{"slug":"safety-kernel","name":"safety-kernel"}],"trust":{"provenance":{"is_fork":false,"github_id":1132275655,"owner_type":"Organization","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-08-02T06:00:26.716Z","maintenance":{"label":"Very active","score":96,"methodology":"github_public_v1","releases_90d":3,"days_since_push":1,"last_release_at":"2026-06-03T14:11:53Z"},"security_summary":{"status":"findings","scanner":"osv@v1","low_count":27,"high_count":0,"last_scan_at":"2026-07-11T23:13:43.803Z","medium_count":0,"scan_profile":"deps","critical_count":0}},"capability_facts":{"mcp":{"source":"repo_scan","observed_at":"2026-08-02T06:00:27.314Z","server_manifest":false},"scan":{"source":"repo_scan","observed_at":"2026-08-02T06:00:27.314Z"},"deploy":{"source":"dockerfile:Dockerfile","self_host":true,"observed_at":"2026-08-02T06:00:27.314Z","managed_saas":false},"languages":{"value":["go","javascript"],"source":"github.language+package.json","observed_at":"2026-08-02T06:00:27.314Z"},"has_docker":{"value":true,"source":"dockerfile:Dockerfile","observed_at":"2026-08-02T06:00:27.314Z"},"license_spdx":{"value":"Other","source":"github.license","observed_at":"2026-08-02T06:00:27.314Z"}},"decision_facts":{"hosting":null,"pricing":null,"requirements":null,"constraints":null,"when_to_use":["When you need comprehensive audit trails for autonomous AI agents","For implementing pre-execution policies in your LangChain or MCP projects"],"when_not_to_use":["If you require a solution hosted as an external service, not self-hosted","In environments where you do not want to enforce policies via approval gates"],"source":"enrich:decision_facts","observed_at":"2026-07-17T11:50:46.164Z"},"constraint_facets":null,"decision_summary":[{"label":"Adopt for","value":"Cordum provides governance over AI agents with policy enforcement and audit trails that work with popular frameworks like LangChain and MCP."}]}}