One policy for Claude Code, Codex, Gemini CLI, Cursor, Windsurf and your MCP servers. Checked before every tool call, judged by what the call will actually run, backstopped by the kernel, recorded in a ledger you can verify.
Also: brew install writ-agent/provio/provio · scoop install provio · the Claude Code plugin (/plugin marketplace add writ-agent/provio) · gemini extensions install https://github.com/writ-agent/provio
Provio wraps agents; it never asks you to adopt a runtime. The same decision point and the same record apply in every interception mode.
MCP proxy, process wrap, SDK hook — the agent itself is unchanged.
One provio.yaml checked before every call: allow, deny, ask, redact. First match wins; unmatched calls fail closed.
Every call — including denials — lands in a hash-chained ledger, with an OTel GenAI span alongside.
Four verdicts, first match wins. The file lives in your repo, so the policy travels with the code and reviews like code. A denial carries the rule id, the human reason and the line that produced it — the agent can correct itself instead of retrying blind.
# provio.yaml
version: 1
default: ask # fail closed
rules:
- id: block-destructive-shell
when: tool == "bash" and command matches "rm -rf|mkfs|dd if="
verdict: deny
reason: "Destructive system command. Narrow the path and retry."
- id: protect-production-db
when: tool startswith "postgres" and query matches "(?i)(DROP|TRUNCATE)"
verdict: ask
irreversible: true # excluded from automated replay
- id: egress-allowlist
when: tool == "http" and not url.host in hosts.allowed
verdict: deny
- id: mask-pii
when: tool startswith "postgres"
verdict: redact
patterns: ["[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,}"]Logs are what an application chose to write. A ledger is evidence: every call, its verdict, the rule that decided it, who approved it, and the hash of the record before it. Edit one line and provio verify names the record where the chain broke.
provio verify — tamper-evident by construction. Nothing is captured beyond metadata and hashes unless you turn content capture on, and there is no telemetry to opt out of.| provio scan | what would provio have caught in your agents' last 30 days (reads transcripts, installs nothing) |
| provio init | a starter policy (the disaster floor + secrets guard) and hooks for every agent found |
| provio test "rm -rf ~" | one call through the policy; nothing runs |
| provio run -- | launch an agent inside the kernel write boundary, hooks wired |
| provio proxy --mcp --server | govern every call to an MCP server |
| provio log · provio show | what did my agent actually do last night |
| provio verify | is this ledger still the one that was written |
| provio replay | what would this policy have done to last week's run |
| provio policy test | unit-test rules against recorded fixtures |
| provio doctor | what is governed, and what is blind |
| provio report --since 12h --sign key.pem | what was stopped, what needed you, a timeline, with a receipt anyone can verify |
| provio mcp pins | MCP tool definitions pinned on first use; a changed one is held until you accept it |
Provio governs actions, not reasoning. The threat model is public: docs/THREAT_MODEL.md.
provio run is for.provio doctor says this out loud.