Skip to main content

Kepil

Accountability layer for AI agents. Give every agent a passport, put every action through one gate, and keep a log that cannot be rewritten afterwards.

53% of organisations have had an AI agent exceed its intended permissions. 48% of agents in production run with no monitoring at all. Only 22% treat an agent as an entity with its own identity. — Cloud Security Alliance and State of AI Agent Security, 2026

Kepil is what the other 78% are missing: identity, mandate, enforcement, evidence — and the part nobody else does, undo.

pip install kepil
python -m kepil.admin        # http://localhost:7317

Русская версия: README.ru.md


What it does

Passport. Every agent version gets an immutable card: who built it, who runs it, what it does, what it will never do, its risk class, its autonomy class, its limits, and when its risks are due for review. A new version is a new card; the old one is kept forever.

Mandate. A machine-readable power of attorney for one job: allowed actions, allowed systems, spending limits, a validity window, and which action types must be confirmed by a human. Anything not explicitly allowed is refused.

Gate. The single point through which an agent touches the outside world. Every action is checked against the mandate before a model is even called. Fail-closed: any error inside the check means refusal, never a pass.

Journal. Append-only JSONL where every record carries the hash of the one before it. Editing or deleting a record is detectable — by anyone, using an independent implementation:

npx @proofbyte/agent-trace verify data/journal.jsonl

Undo. The journal is a graph of actions, and every profession declares its compensating action. Kepil walks that graph backwards and stops honestly at the first step that cannot be undone. Agent platforms record what happened; this one puts it back.

Confirmations on your phone. Irreversible actions arrive in Telegram with two buttons — approve or return — so being accountable does not mean sitting at a laptop.

An agent here is never fully autonomous

AgentPassport refuses to be constructed with the autonomy class where a human can no longer cancel a decision. That is a deliberate architectural limit rather than a missing feature — see ADR-0002. The gate enforces the same rule regardless of what a profession definition claims.

Professions: behaviour as data, not code

An agent's job is a JSON description: ordered steps, boundaries, limits, irreversible action patterns, rollback rules. Adding a new kind of work means adding a file — or filling in a form in the panel. The dangerous parts stay in code and under test.

Five ship with the project: inbound leads, process automation, bookkeeping documents, AI-adoption audit, public-procurement packages.

The panel

python -m kepil.admin opens an operator console: orders, professions, agent passports, a meter (actions, tokens, cost, human time replaced), the compliance generator, the journal with chain verification and anchoring, and settings.

State is plain JSON files under KEPIL_DATA (default ./data). No database: you can open them, read them, and attach them to a dispute.

Compliance packs

Documentation requirements differ by country and change faster than code, so the texts live outside the engine. The neutral pack shipped here follows international practice (ISO/IEC 42001, record-keeping in the spirit of the EU AI Act). Jurisdiction packs — for example Kazakhstan's AI Law No. 230-VIII with order No. 95/НҚ — are dropped into $KEPIL_DATA/packs as files.

Design rules

  • Zero dependencies. The core runs on the Python 3.11+ standard library, and CI fails the build if a third-party import appears. That keeps Kepil installable inside an air-gapped perimeter, and keeps the supply-chain attack surface of a tool that sees every action at zero.
  • Values never enter the journal — only types, counts and hashes.
  • The verifier is a separate implementation in another language. Proof that only its own author can check is not proof.

Related projects

Project Role
agent-trace Independent journal verification and evidence packs (MIT)
AI-Gateway PII and secret masking between your apps and external models
AutoGov Discovery of shadow automations and the credentials they can reach

Status

Alpha, 79 tests. Interfaces may still change. Nothing here is a legal opinion: before relying on generated documents, have them reviewed by a lawyer in your jurisdiction.

License

AGPL-3.0-or-later. Running a network service built on Kepil obliges you to release your own source under the same terms — or to take a commercial licence. See NOTICE.md.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

kepil-0.2.0.tar.gz (83.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

kepil-0.2.0-py3-none-any.whl (86.6 kB view details)

Uploaded Python 3

File details

Details for the file kepil-0.2.0.tar.gz.

File metadata

  • Download URL: kepil-0.2.0.tar.gz
  • Upload date:
  • Size: 83.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.2

File hashes

Hashes for kepil-0.2.0.tar.gz
Algorithm Hash digest
SHA256 236c84933b2f6004ee1bf315cfb40db6cadcd5f309f1d6dc49b5301f41c3ded5
MD5 c687aef390d9aa78f78fd67c8ec249f8
BLAKE2b-256 dbb1912a61cdca19bbe6959748985eb31cd813cf461d6e48cfa10914e07d7b58

See more details on using hashes here.

File details

Details for the file kepil-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: kepil-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 86.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.2

File hashes

Hashes for kepil-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f4934b13e54f8392ef2fe8c6bb243fb3ffe8b90899cb881efce2db40531cba39
MD5 85c9a3937d9102befe7973d1358813c4
BLAKE2b-256 8473fc7c03c01b98f6b5429c3eee0d218c5f75180147a45743e2d15f468ff2fb

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.1

2 files

This release

0.2.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page