ActionProxy Community
Run the approval boundary locally or self-host it, inspect the policy and lifecycle, and keep real-tool credentials in infrastructure you control.
Open-source execution governance
ActionProxy evaluates a proposed action, allows bounded calls, denies prohibited calls, queues selected calls for human review, and controls the transition into execution.
Choose the operating path
Run the approval boundary locally or self-host it, inspect the policy and lifecycle, and keep real-tool credentials in infrastructure you control.
The narrow boundary
Return allow, deny, or require approval from explicit rules over a normalized tool call and trusted context.
Connect the reviewer’s decision to the payload, policy, eligibility requirements, nonce, and expiry.
Follow the proposal through decision, review, dispatch attempt, and reported outcome without overstating what logs prove.
Start here
Learn where an AI agent approval gateway belongs, what it should bind and record, and when human review helps more than blanket approval.
Read guide →Learn where to place human approval in an MCP tool call, what the reviewer should see, and how to bind an approved request to one controlled execution.
Read guide →Design an AI agent email approval flow that reviews the actual message, binds the decision to one send, and records the downstream outcome.
Read guide →Current project boundary
ActionProxy Community v0.1 is a developer preview for local and self-hosted evaluation, not a complete production authorization boundary or hosted SaaS control plane. Real business-tool effects use an external runner or downstream MCP server; the built-in registry is a deterministic demo surface.