Runtime decisions
Pre-tool decisions with allow, block, ask, warn, redact, structured reasons, and dry-run checks.
Public roadmap
Edictum is centered on open-source runtime enforcement for agent actions. The API/app reference stack supports visibility and approvals, but it is not where enforcement happens.
Direction
The current public product center: OSS runtime enforcement, rulesets, workflow gates, adapters, Gate CLI, audit, and the optional reference stack.
Pre-tool decisions with allow, block, ask, warn, redact, structured reasons, and dry-run checks.
YAML rulesets for pre, post, session, and sandbox rules with templates and schema validation.
Ordered stages, evidence requirements, terminal states, and workflow conformance fixtures.
Python, TypeScript, Go, framework adapters, local checks, assistant hooks, and audit WAL.
Self-hosted API/app for approvals, event ingestion, audit feed, runs, agents, ruleset versions, and hot reload.
The next work is about safer rollout: better previews, clearer reporting, and more complete operational guidance.
Replay past decisions against candidate rulesets and summarize what would have changed before promotion.
Clear event attributes, OpenTelemetry guidance, reporting queries, and SQL sink examples.
Base rulesets, environment overlays, and promotion flows for teams running multiple agent profiles.
More consistent webhook and notification paths around ask decisions, timeouts, and reviewer identity.
OWASP Agentic starter controls, adversarial tests, and common destructive-command and secret-redaction patterns.
Later work extends proof, portability, and team operation without changing the OSS-first center.
Exportable evidence packages for approvals, workflow snapshots, ruleset versions, and decision history.
Runtime summaries that explain what fired, what was blocked, and what policy coverage looked like.
Keep Python, TypeScript, and Go aligned while documenting parity honestly where adapters differ.
Reusable reporting patterns for rule coverage, approval latency, denied actions, and workflow conformance.
These are intentionally out of center for the hub because they pull attention away from runtime enforcement.
The website should not make the app the product center. Enforcement remains local to the runtime path.
Edictum is runtime governance for agent actions, not a general governance suite for every AI risk.
Accuracy, relevance, and answer quality evals are separate tools. Edictum composes with them.
LangGraph, Temporal, CrewAI, and similar systems own orchestration. Edictum enforces action policy before tools run.
The public site should not imply customer deployments without approved public material.
How to engage
The best feedback is specific: which agent, which tools, which approval path, what audit evidence, and what rule change would have reduced operational risk.