Skip to main content

kailash-pact

PACT governance framework — D/T/R accountability grammar, operating envelopes, knowledge clearance, and verification gradient for AI agent organizations.

Part of the Kailash enterprise AI platform.

Quick Start

from pact.governance import GovernanceEngine

engine = GovernanceEngine.from_yaml("my-org.yaml")
verdict = engine.verify_action("D1-R1-T1-R1", "write_report", {"cost": 50.0})

if verdict.allowed:
    print("Approved:", verdict.reason)
else:
    print("Blocked:", verdict.reason)

Installation

pip install kailash-pact

With Kaizen agent integration:

pip install kailash-pact[kaizen]

Features

  • D/T/R Grammar Engine — Accountability grammar (Department/Team/Role) with positional addressing
  • Three-Layer Envelopes — Role (standing) + Task (ephemeral) = Effective (computed intersection)
  • Knowledge Clearance — Five-level classification independent of authority/seniority
  • 5-Step Access Enforcement — Clearance → Classification → Compartment → Containment → Deny
  • GovernanceEngine — Single facade composing all primitives
  • PactGovernedAgent — Wrap any Kaizen agent with governance enforcement
  • SQLite/PostgreSQL Stores — Persistent governance state
  • REST API — 9 governance endpoints with auth and rate limiting
  • CLIkailash-pact validate org.yaml

MCP Governance — Tenant Isolation (Pre-Pledge v0)

pact.mcp adds deterministic governance to MCP (Model Context Protocol) tool calls and resource reads, including first-class multi-tenant isolation (issue #1843, shipped in 0.16.0). Because kailash-pact is still pre-1.0, this section is an explicit pledge of what the tenant-isolation surface enforces today versus what remains open — read it before relying on McpGovernanceConfig.tenant_grants in a multi-tenant deployment.

  • Enforced today: McpGovernanceConfig.tenant_grants (a dict[str, McpTenantGrant]) scopes both tools/call and resources/read to the caller's tenant through one shared, fail-closed restrictiveness function, evaluated before tool registration (so it applies even under DefaultPolicy.ALLOW). The effective tenant is resolved from the server-verified tenant field (populated server-side at the network boundary, #1878) or a trusted McpCallerIdentity.tenant (resolved by your transport/auth layer and passed to check_tool_call/check_resource_read); the self-asserted metadata["tenant_id"] channel is deprecated and no longer consulted for tenant resolution in any mode (#1919), defeating impersonation. require_caller_identity defaults to True: with no verified/trusted tenant the call fails closed.
  • Deferred: resources/read has ONLY the tenant-isolation check today — no cost, argument, clearance, or rate-limit governance layer exists yet for that surface (that richer contract exists only for tools/call via McpToolPolicy). The server-verified tenant field (#1878) is populated server-side and deliberately excluded from the wire envelope (to_dict/from_dict never emit it — byte-neutral with the Rust SDK's frozen envelope); it is NOT a client-serialized field, and the self-asserted metadata["tenant_id"] channel is no longer consulted for tenant resolution (#1919).
  • Non-promises: tenant_grants being empty is NOT "tenant isolation enabled with an empty allowlist" — it is isolation OFF entirely (every call auto-approved on that axis, byte-identical to pre-0.16.0 behavior). Passing require_caller_identity=False is NOT a recommended production setting — it exists only for the documented #1843 weaker-mode surface. As of #1919 it NO LONGER re-enables a trusted metadata fallback: a caller that relied on the self-asserted metadata["tenant_id"] now receives a DeprecationWarning and the decision fails closed.
  • Verify: pytest packages/kailash-pact/tests/regression/test_issue_1843_mcp_tenant_isolation.py -v exercises the fail-closed defaults, the impersonation-defeat contract, and the resources/read isolation-only surface end-to-end.
  • Status: v0 within a pre-1.0 package (kailash-pact 0.18.0) — the isolation contract above is stable for this release; the deferred items may change shape (not just grow) before a 1.0 cut.

Documentation

Cross-SDK Conformance (PACT N4/N5)

The PACT N6 cross-SDK conformance contract pins byte-for-byte canonical JSON across language SDKs. The Python implementation lives in pact.conformance and drives the same vector files the Rust SDK does.

Run the runner programmatically

from pact.conformance import ConformanceRunner, load_vectors_from_dir

vectors = load_vectors_from_dir(
    "/path/to/kailash-rs/crates/kailash-pact/tests/conformance/vectors"
)
report = ConformanceRunner().run(vectors)
if not report.all_passed:
    raise SystemExit(report.render_failure_report())
print(f"PACT conformance: {report.passed}/{report.total} passed")

Run via pytest

The Tier 1 unit tests at tests/unit/conformance/test_runner.py::test_runner_passes_against_real_cross_sdk_vectors auto-discover the kailash-rs sibling checkout and exercise every vector. The test SKIPS gracefully when the sibling repo is absent, so unit-only CI hosts do not fail.

pytest packages/kailash-pact/tests/unit/conformance/ -v

Vector schema

Each vector is a JSON document at crates/kailash-pact/tests/conformance/vectors/ with:

  • id: unique identifier (sort key)
  • contract: "N4" (TieredAuditEvent canonicalisation) or "N5" (Evidence canonicalisation)
  • input.verdict: {zone, reason, action, role_address, details}
  • input.posture: required for N4 (PseudoAgent, Supervised, SharedPlanning, ContinuousInsight, Delegated)
  • input.fixed_event_id / input.fixed_timestamp: required for determinism
  • expected.canonical_json: the byte-for-byte JSON the SDK MUST emit
  • expected.tier / durable / requires_signature / requires_replication: optional N4 invariants

The runner compares actual vs expected via byte equality (NOT JSON-equal); a single-byte drift surfaces as a FAILED outcome with both SHA-256 fingerprints populated for forensic correlation.

License

Apache 2.0 — Terrene Foundation

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

kailash_pact-0.18.0-py3-none-any.whl (126.6 kB view details)

Uploaded Python 3

File details

Details for the file kailash_pact-0.18.0-py3-none-any.whl.

File metadata

  • Download URL: kailash_pact-0.18.0-py3-none-any.whl
  • Upload date:
  • Size: 126.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for kailash_pact-0.18.0-py3-none-any.whl
Algorithm Hash digest
SHA256 22ce3c4f9ce9e38b53b9761107a70798c3a992139617eef85839c8924ecbe923
MD5 a8432e3861a0a0dc2a10b69e2d40b8e5
BLAKE2b-256 c8dfc27df3d726ee2bfe3e1e7b74b0df60fca3ab9e34780024711ed4ff5a7b8a

See more details on using hashes here.

Provenance

The following attestation bundles were made for kailash_pact-0.18.0-py3-none-any.whl:

Publisher: publish-pypi.yml on terrene-foundation/kailash-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.18.0 This release

1 file

0.17.0

1 file

0.16.1

1 file

0.16.0

1 file

0.15.0

1 file

0.14.3

1 file

0.14.2

1 file

0.14.1

1 file

0.14.0

1 file

0.13.1

1 file

0.13.0

1 file

0.12.1

1 file

0.12.0

1 file

0.11.0

1 file

0.10.0

1 file

0.9.0

1 file

0.8.2

1 file

0.8.1

1 file

0.8.0

1 file

0.7.2

1 file

0.7.1

1 file

0.7.0

1 file

0.6.0

1 file

0.5.0

1 file

0.4.1

1 file

0.4.0

2 files

0.3.0

1 file

0.2.0

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page