A safety floor your
AI agents can't get under.

One policy for Claude Code, Codex, Gemini CLI, Cursor, Windsurf and your MCP servers. Checked before every tool call, judged by what the call will actually run, backstopped by the kernel, recorded in a ledger you can verify.

$pip install provio && provio scan && provio init

Also: brew install writ-agent/provio/provio · scoop install provio · the Claude Code plugin (/plugin marketplace add writ-agent/provio) · gemini extensions install https://github.com/writ-agent/provio

claude-code#88462 replayed: provio denies writing a cleanup script whose trap runs rm -rf $HOME, denies running it by reading the script, and when the delete is obfuscated past every rule the kernel boundary refuses it and the home directory stays intact
claude-code#88462, replayed: refused when written, refused when run, and stopped by the kernel when obfuscated past every rule.
How it works

Three steps, one decision point

Provio wraps agents; it never asks you to adopt a runtime. The same decision point and the same record apply in every interception mode.

01

INTERCEPT

MCP proxy, process wrap, SDK hook — the agent itself is unchanged.

02

DECIDE

One provio.yaml checked before every call: allow, deny, ask, redact. First match wins; unmatched calls fail closed.

03

RECORD

Every call — including denials — lands in a hash-chained ledger, with an OTel GenAI span alongside.

Policy

provio.yaml is the whole surface

Four verdicts, first match wins. The file lives in your repo, so the policy travels with the code and reviews like code. A denial carries the rule id, the human reason and the line that produced it — the agent can correct itself instead of retrying blind.

allow deny ask — a human gates it redact — masked before it re-enters the model
# provio.yaml
version: 1
default: ask                          # fail closed
rules:
  - id: block-destructive-shell
    when: tool == "bash" and command matches "rm -rf|mkfs|dd if="
    verdict: deny
    reason: "Destructive system command. Narrow the path and retry."

  - id: protect-production-db
    when: tool startswith "postgres" and query matches "(?i)(DROP|TRUNCATE)"
    verdict: ask
    irreversible: true                # excluded from automated replay

  - id: egress-allowlist
    when: tool == "http" and not url.host in hosts.allowed
    verdict: deny

  - id: mask-pii
    when: tool startswith "postgres"
    verdict: redact
    patterns: ["[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,}"]
Evidence

The part that survives the session

Logs are what an application chose to write. A ledger is evidence: every call, its verdict, the rule that decided it, who approved it, and the hash of the record before it. Edit one line and provio verify names the record where the chain broke.

provio verify reports a chain intact, then reports a broken chain at record 12 after a ledger line is edited
provio verify — tamper-evident by construction. Nothing is captured beyond metadata and hashes unless you turn content capture on, and there is no telemetry to opt out of.
Surface

Commands

provio scanwhat would provio have caught in your agents' last 30 days (reads transcripts, installs nothing)
provio inita starter policy (the disaster floor + secrets guard) and hooks for every agent found
provio test "rm -rf ~"one call through the policy; nothing runs
provio run -- launch an agent inside the kernel write boundary, hooks wired
provio proxy --mcp --server -- govern every call to an MCP server
provio log · provio show what did my agent actually do last night
provio verifyis this ledger still the one that was written
provio replay --candidate what would this policy have done to last week's run
provio policy testunit-test rules against recorded fixtures
provio doctorwhat is governed, and what is blind
provio report --since 12h --sign key.pemwhat was stopped, what needed you, a timeline, with a receipt anyone can verify
provio mcp pinsMCP tool definitions pinned on first use; a changed one is held until you accept it
Limits

What provio does not do

Provio governs actions, not reasoning. The threat model is public: docs/THREAT_MODEL.md.

  • It does not stop prompt injection. It shrinks the blast radius: least privilege, egress allow-lists, a human gate on irreversible calls.
  • The ledger is tamper-evident, not tamper-proof. Editing a record breaks the chain and is caught; a signed receipt anchored in the Sigstore Rekor log is what makes deleting records after it detectable.
  • Command rules read text. provio also reads the scripts a call runs or writes, but obfuscated commands get past any parser; that is what the kernel boundary under provio run is for.
  • MCP-proxy-only mode is partial coverage. The agent's own shell, file writes and direct HTTP go around it — provio doctor says this out loud.
  • It does not reverse side effects. A denied call never ran; an approved one is yours.