{"data":{"slug":"firma-ai-openfirma","name":"openfirma","tagline":"Runtime enforcement boundary for AI agents with local sidecar","github_url":"https://github.com/Firma-AI/openfirma","owner":"Firma-AI","repo":"openfirma","owner_avatar_url":"https://avatars.githubusercontent.com/u/265281226?v=4","primary_language":"Rust","stars":135,"forks":9,"topics":["access-control","agentic-ai","ai-agents","ai-governance","ai-safety","authorization","cedar","cedar-policy","guardrails","policy-engine","runtime-security","rust","sidecar"],"archived":false,"github_pushed_at":"2026-09-11T12:35:48+00:00","maintenance_label":"Very active","stars_delta_30d":29,"url":"https://www.graphcanon.com/tools/firma-ai-openfirma","markdown_url":"https://www.graphcanon.com/tools/firma-ai-openfirma.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/firma-ai-openfirma","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=firma-ai-openfirma","description":"Runtime enforcement boundary for AI agents: a local sidecar that gates every outbound call against Cedar policies you own. Deterministic, call-level, no model on the hot path","homepage_url":"https://firma-ai.github.io/openfirma/","license":"GPL-3.0","open_issues":8,"watchers":1,"ai_summary":"A tool that acts as a policy-enforcing sidecar for outbound calls from AI agents using Cedar policies.","readme_excerpt":"### Install\n\n**Linux / macOS:**\n\n```bash\ncurl -fsSL https://install.openfirma.ai | sh\n```\n\nOn macOS with Homebrew installed, the installer uses `brew install firma-ai/openfirma/firma`\nautomatically. You can also install directly:\n\n```bash\nbrew install firma-ai/openfirma/firma\n```\n\n**Build and install from source** (requires Rust 1.88+ and `protoc`):\n\n```bash\ngit clone https://github.com/Firma-AI/openfirma\ncd openfirma\ncargo install --path crates/firma --locked\n```\n\n---\n\n## License\n\nGPL 3.0. See [LICENSE](LICENSE)","github_created_at":"2026-03-22T02:18:47+00:00","created_at":"2026-07-15T10:43:28.770512+00:00","updated_at":"2026-09-20T04:26:06.142157+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"},{"slug":"evaluation-observability","name":"Evaluation & Observability","url":"https://www.graphcanon.com/categories/evaluation-observability","markdown_url":"https://www.graphcanon.com/categories/evaluation-observability.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/evaluation-observability"}],"tags":[{"slug":"access-control","name":"access-control"},{"slug":"agentic-ai","name":"agentic-ai"},{"slug":"ai-agents","name":"ai-agents"},{"slug":"authorization","name":"authorization"},{"slug":"cedar-policy","name":"cedar-policy"},{"slug":"guardrails","name":"guardrails"},{"slug":"policy-engine","name":"policy-engine"},{"slug":"runtime-security","name":"runtime-security"}],"trust":{"provenance":{"is_fork":false,"github_id":1188390369,"owner_type":"Organization","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-09-12T06:00:34.706Z","maintenance":{"label":"Very active","score":96,"methodology":"github_public_v1","releases_90d":4,"days_since_push":0,"last_release_at":"2026-07-30T16:21:49Z","stars_delta_30d":29,"open_issues_delta_30d":-9},"security_summary":{"status":"no_lockfile","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-15T10:43:30.122Z","medium_count":0,"scan_profile":"none","critical_count":0}},"capability_facts":{"scan":{"source":"repo_scan","observed_at":"2026-09-12T06:00:35.160Z"},"languages":{"value":["rust"],"source":"github.language","observed_at":"2026-09-12T06:00:35.160Z"},"license_spdx":{"value":"GPL-3.0","source":"github.license","observed_at":"2026-09-12T06:00:35.160Z"}},"decision_facts":{"hosting":null,"pricing":null,"requirements":null,"constraints":null,"when_to_use":["When you need deterministic and call-level runtime enforcement that specifically leverages Cedar policies tailored for your needs.","If you are working with locally enforced governance mechanisms for AI agent interactions without model dependencies on the hot path."],"when_not_to_use":["Avoid if you prefer a solution not tightly coupled to Cedar policies, as Openfirma exclusively supports this policy framework.","Do not use if licensing is critical and you need permissive licenses, since Openfirma uses the GPL-3.0 license."],"source":"enrich:decision_facts","observed_at":"2026-07-16T19:29:30.323Z"},"constraint_facets":null,"decision_summary":[{"label":"Adopt for","value":"Openfirma is a policy-enforcing sidecar for AI agents that uses Cedar policies to gate outbound calls, built in Rust under the GPL-3.0 license."}]}}