agent-action-policy
Declarative action policies for AI agents — approve, deny, or escalate any tool call before execution.
Install
pip install agent-action-policy
pip install agent-action-policy[yaml] # for YAML policy files
Quick Start
from action_policy import PolicyEngine, Action
engine = PolicyEngine.from_dict({
"policies": [{
"name": "no-force-push",
"match": {"tool": "bash", "args_pattern": "git push --force"},
"action": "deny",
"reason": "Force push requires human approval",
}]
})
decision = engine.evaluate(tool="bash", args={"command": "git push --force origin main"})
print(decision.denied) # True
print(decision.reason) # "Force push requires human approval"
Sandboxing vs Policy
| Sandboxing (containers) | Policy (this library) | |
|---|---|---|
| Controls | Where code runs | What the agent can do |
| Granularity | Process-level | Per-tool-call |
| Configuration | Infrastructure | YAML/Python |
| Use with | Any runtime | Any agent framework |
Sandboxing and policies are complementary. Use both.
Policy Definition (YAML)
policies:
- name: no-destructive-git
match:
tool: bash
args_pattern: "git (push --force|reset --hard|branch -D)"
action: deny
reason: "Destructive git operations require human approval"
- name: escalate-system-files
match:
tool: "~(file_write|write_file)"
path_patterns:
- "/etc/*"
- "/usr/*"
action: escalate
reason: "System file modification needs confirmation"
- name: approve-reads
match:
tool: "~(read|search|grep)"
action: approve
priority: 10 # lower = higher priority
Built-in Templates
engine = PolicyEngine.from_template("safe_coding")
| Template | What it protects |
|---|---|
safe_coding |
Blocks force-push, rm -rf, system file writes, credential access, hook skipping |
safe_browsing |
Blocks internal URLs, file:// protocol, escalates downloads |
safe_database |
Blocks DDL (DROP/TRUNCATE), escalates DELETE and WHERE-less UPDATE |
strict |
Whitelist mode — only read operations allowed, everything else denied |
Python API
# From YAML file
engine = PolicyEngine.from_yaml("policies.yaml")
# From dict
engine = PolicyEngine.from_dict({"policies": [...]})
# From template
engine = PolicyEngine.from_template("safe_coding")
# Evaluate
decision = engine.evaluate(tool="bash", args={"command": "rm -rf /"})
decision.action # Action.DENY
decision.denied # True
decision.reason # "..."
decision.policy_name # "no-rm-rf"
# Fail-closed mode (deny by default)
engine = PolicyEngine.from_template("strict", default_action=Action.DENY)
# Decorator
@engine.guard
def execute_tool(tool: str, args: dict = None):
... # raises PolicyDenied or PolicyEscalated
Pattern Matching
| Pattern type | Syntax | Example |
|---|---|---|
| Exact match | tool_name |
"bash" |
| Glob | *, ?, [...] |
"file_*" |
| Regex | ~pattern |
"~(bash|shell|exec)" |
| Args regex | any regex | "git\\s+push\\s+--force" |
| Path glob | glob or ~regex |
"/etc/*", "~\\.env$" |
License
MIT
Release files for agent-action-policy 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agent_action_policy-0.1.1.tar.gz | 14.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agent_action_policy-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 26.0 kB
Release files / agent_action_policy-0.1.1.tar.gz
| Download URL | agent_action_policy-0.1.1.tar.gz |
|---|---|
| Size | 14.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6b5d5ca6ddab1148c5613cc3e041e23223d6dd566b2d58bb7efbc11a918fdfdc
|
|
BLAKE2b-256 checksum How to use checksums |
a7f9f0597e9b1c24a2f2a08ada02c3b93cd8d1b545f1b05dfc0ffd6754e3b184
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 25, 2026.
Transparency logRelease files / agent_action_policy-0.1.1-py3-none-any.whl
| Download URL | agent_action_policy-0.1.1-py3-none-any.whl |
|---|---|
| Size | 11.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
670fc60abb0e122509270344fe04c30fdffcb7fb4edec1144e9afed1fc14c2d8
|
|
BLAKE2b-256 checksum How to use checksums |
20252e3b4cbd8e70e753ad408ed799daea8cbdaa1ff23524602f2ac81ff35d45
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 25, 2026.
Transparency log