OpenAPPA: deterministic AI guardrails that don't break agents, lifting utility from ~40% to ~90%
motakuk · hn · 2026-09-28
Archestra open-sources OpenAPPA, tackling the problem that more connected tools mean more chances for enterprise agents to leak sensitive data.
- Non-deterministic guardrails (LLM-as-judge, auto modes) are vulnerable to prompt injection, leaking 10% of data on their benchmarks; deterministic ones (Cedar, OPA, FIDES) need massive case-specific IF-ELSE policies and break agents (59% utility loss).
- OpenAPPA uses a data-specific (not use-case-specific) policy language, so policies don't need updating as agents scale.
- With tricks like remedy plans and a DualLLM pattern, utility rises from 40% to 90%, billed as the first deterministic guardrail that doesn't break agents.
- Pluggable into any agent loop via pre/post tool-call hooks, with a Claude Code integration and an arXiv paper.
More from coding & agent
- Creative arbitrage: build a Claude Code skill to ship 500+ static ads for almost nothing — alexgoughcooper · 2026-09-28
- Git is the cheapest insurance for your Obsidian vault, says automation guide author — dSebastien · 2026-09-28
- Cloudflare open sources Forge: one pipeline to generate SDKs, CLIs and docs — dee_hw · 2026-09-28
- DHH: There's no future manually reviewing every line of agent code — use adversarial agent reviews and automated tests — avlok · 2026-09-28
- Indie hacker had an AI agent sign up for his own SaaS: 26 bugs found and a docs hub built in 8 hours — tibo_maker · 2026-09-28
- OpenAI models allegedly get 832 juice via API vs 128 in Codex — legit_api · 2026-09-28