<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>information-flow-control on tomrochette.com</title>
    <link>https://tomrochette.com/tags/information-flow-control/</link>
    <description>Recent content in information-flow-control on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Wed, 07 Oct 2026 06:38:49 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/information-flow-control/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>OpenAPPA</title>
      <link>https://tomrochette.com/agents/control-planes/openappa/</link>
      <pubDate>Wed, 07 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/control-planes/openappa/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=glm-5.3-flash</category><category>control-planes</category><category>information-flow-control</category><category>policy-enforcement</category><category>prompt-injection</category><category>rust</category>
      <description>&lt;p&gt;OpenAPPA (archestra-ai/OpenAPPA) is an MIT-licensed Rust policy engine, built on the APPA information-flow algebra, that labels everything an agent reads with an audience and trust level and checks every tool call against declarative TOML policy before it runs.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Its argument is that you cannot prompt-inject an algebra: instead of classifying intents or matching blocked patterns, the engine tracks where data came from and derives each decision from the trajectory&amp;rsquo;s label, so the same event log always yields the same verdict.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Policy is one &lt;code&gt;appa.toml&lt;/code&gt; describing data sources, audiences, trust levels, and authorities; every trajectory carries a security label (audience × trust) that only narrows as the agent reads.&#xA;The engine runs in-process or as a sidecar, decides from the event log alone with no network or file calls, and answers a block with a machine-readable remedy plan: sanitizers that redact a payload so it can flow to a wider audience, one-action authorities, or a disposable child branch that absorbs untrusted reads without poisoning the parent trajectory.&#xA;A Claude Code plugin (&lt;code&gt;appa plugin install claude-code&lt;/code&gt;) is the fastest integration, and the sponsor&amp;rsquo;s Archestra LLM proxy implements the same enforcement for any agent that talks to a model through it, including Claude Code, Claude Desktop, Cursor, Codex, OpenCode, Copilot CLI, and n8n.&#xA;&lt;code&gt;appa describe --check&lt;/code&gt; and &lt;code&gt;appa replay&lt;/code&gt; validate policy coverage in CI, so a team can block merges that leave tool paths uncovered.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Active and fast-growing for its age: 1,476 stars and 63 forks as of 2026-10-07 since creation on 2026-08-18, pushed 2026-10-06, latest release v0.31.1, positioned as a preview and an RFC where config and wire surfaces may break without shims.&lt;/p&gt;&#xA;&lt;picture&gt;&#xA;  &lt;source media=&#34;(prefers-color-scheme: dark)&#34; srcset=&#34;https://api.star-history.com/chart?repos=archestra-ai/OpenAPPA&amp;type=date&amp;theme=dark&amp;legend=top-left&#34; /&gt;&#xA;  &lt;source media=&#34;(prefers-color-scheme: light)&#34; srcset=&#34;https://api.star-history.com/chart?repos=archestra-ai/OpenAPPA&amp;type=date&amp;legend=top-left&#34; /&gt;&#xA;  &lt;img alt=&#34;Star History Chart&#34; src=&#34;https://api.star-history.com/chart?repos=archestra-ai/OpenAPPA&amp;type=date&amp;legend=top-left&#34; /&gt;&#xA;&lt;/picture&gt;&#xA;&lt;p&gt;&lt;strong&gt;The formal claim has an actual paper behind it: APPA (arXiv 2607.24625, revised 2026-08-26) proves no-laundering and recovery-containment invariants and reports 6,600 benchmark episodes, and the work was accepted to the NeurIPS 2026 Workshop on Agents in the Wild.&lt;/strong&gt;&#xA;The community footprint is still thin (a 2-point, zero-comment HN thread on 2026-10-01), and every benchmark number is self-reported, though the suites (Bench-Corp, AgentThreatBench, Tau) are public and the baselines are named.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Deterministic decisions computed from the event log alone are auditable in a way classifier-based auto-modes cannot be, since the same log always produces the same verdict.&lt;/li&gt;&#xA;&lt;li&gt;The remedy-plan design is the interesting part: blocks come with legal continuations (sanitizers, authorities, subagent isolation), which is how guarded runs complete 88 to 90 percent of tasks while recording zero successful attacks across 1,320 evaluations.&lt;/li&gt;&#xA;&lt;li&gt;Token overhead is measured rather than asserted: 4.22 percent over stock on Tau Bench.&lt;/li&gt;&#xA;&lt;li&gt;Policy coverage is checkable in CI, so completeness is provable before merge instead of asserted after an incident.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Preview and RFC: config and wire surfaces may break without shims, so pin deliberately and read the changelog before upgrading.&lt;/li&gt;&#xA;&lt;li&gt;Development is sponsored by Archestra, whose proxy is the flagship integration; vendor neutrality is a design stance, and the benchmark baselines (Microsoft FIDES, Claude auto mode) are configured by the sponsor.&lt;/li&gt;&#xA;&lt;li&gt;The Claude Code plugin is described by the project itself as a playground, not the product, so production enforcement today means the Archestra proxy or an embedded runtime.&lt;/li&gt;&#xA;&lt;li&gt;Utility collapses without the recovery machinery: one Bench-Corp ablation falls from 88 percent completion to 35 percent without guided recovery, so evaluate with recovery enabled or expect stalls.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;MIT licensed and free.&#xA;The sponsor&amp;rsquo;s Archestra platform is a separate open-source project with its own commercial offering; no OpenAPPA-specific prices exist.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/veto/&#34; &gt;Veto&lt;/a&gt;: both are local-first gates, but Veto matches actions against YAML rules while OpenAPPA tracks data flows and labels; choose Veto for rules about specific actions, OpenAPPA when the threat is exfiltration of anything the agent read.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/microsoft-agent-governance-toolkit/&#34; &gt;Microsoft Agent Governance Toolkit&lt;/a&gt;: the toolkit wraps calls with policy, identity, sandboxing, and audit across five languages; OpenAPPA is single-purpose and deeper on the data-flow axis.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/crowdstrike-falcon-guardian/&#34; &gt;CrowdStrike Falcon Guardian&lt;/a&gt;: the endpoint-commercial answer to the same exfiltration problem; OpenAPPA runs in your process instead of your sensor estate.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended for teams whose dominant risk is sensitive data reaching unauthorized destinations, who can live with a preview engine and want deterministic, CI-checkable policy.&lt;/strong&gt;&#xA;Not for teams that need budgets, org models, or fleet approvals, because OpenAPPA deliberately governs data flows, not agent organizations, and not for anyone who requires a stable 1.0.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-10-07 - Created from the entrant scan (an HN surfacing cross-checked against the awesome-ai-governance list), profiling the APPA information-flow engine.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/control-planes-feature-matrix/&#34; &gt;Control Planes Feature Matrix&lt;/a&gt; - the category comparison this note joins&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/veto/&#34; &gt;Veto&lt;/a&gt; - the action-rule kernel this complements on the data-flow axis&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/microsoft-agent-governance-toolkit/&#34; &gt;Microsoft Agent Governance Toolkit&lt;/a&gt; - the broad multi-language policy alternative&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../../../an-agent-is-only-as-safe-as-its-worst-tool-call/index.md&#34; &gt;An Agent Is Only as Safe as Its Worst Tool Call&lt;/a&gt; - the corpus argument for gating the call&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/archestra-ai/OpenAPPA&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://github.com/archestra-ai/OpenAPPA&lt;/a&gt; - README: the algebra, remedy plans, integrations, benchmarks summary, license&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://api.github.com/repos/archestra-ai/OpenAPPA&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=api.github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://api.github.com/repos/archestra-ai/OpenAPPA&lt;/a&gt; - stars, forks, creation and push dates as of 2026-10-07&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openappa.com/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openappa.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openappa.com/&lt;/a&gt; - the flow-tracking argument, the label model, remedy plans&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openappa.com/evaluation&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openappa.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openappa.com/evaluation&lt;/a&gt; - the 1,320-episode results, the FIDES and auto-mode comparisons, token overhead, ablations&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openappa.com/archestra&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openappa.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openappa.com/archestra&lt;/a&gt; - the sponsorship statement and the proxy-level integration&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://arxiv.org/abs/2607.24625&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=arxiv.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://arxiv.org/abs/2607.24625&lt;/a&gt; - the APPA paper: invariants, recovery containment, 6,600 episodes, NeurIPS workshop acceptance&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://api.github.com/repos/archestra-ai/OpenAPPA/releases&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=api.github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://api.github.com/repos/archestra-ai/OpenAPPA/releases&lt;/a&gt; - v0.31.1, the latest release&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=49918330&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=news.ycombinator.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://news.ycombinator.com/item?id=49918330&lt;/a&gt; - the 2-point, zero-comment thread, the thin community signal&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
