cordum-io/cordum
The action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.
What it solves
Cordum provides a deterministic governance layer for autonomous AI agents, addressing the "risk gap" where enterprises struggle to deploy agents because they lack visibility, safety rails, and audit trails for potentially destructive or unauthorized actions.
How it works
It acts as an Agent Control Plane that intercepts agent operations across three stages:
- Before: Evaluates declarative YAML policies via a Safety Kernel to gate or throttle requests before execution.
- During: Provides real-time monitoring, circuit breakers, and human-in-the-loop approvals for active runs.
- Across: Aggregates audit trails and monitors fleet health from a centralized dashboard.
It also includes Cordum Edge, a compliance firewall that hooks into local agent actions (such as Claude Code) to deny risky tools, require approvals for edits, and export redacted evidence bundles.
Who it’s for
Enterprise teams deploying autonomous AI agents who need to enforce safety, compliance, and human oversight without restricting agents to read-only tasks.
Highlights
- Safety Gating: Blocks destructive actions before they occur.
- Human-in-the-Loop: Mandates manual approval for high-risk operations.
- Output Quarantine: Prevents PII leaks and secrets from reaching clients.
- Deterministic Audit: Maintains a full chain-of-thought audit trail for every decision.
- Cordum Edge: A local firewall for agentic tools like Claude Code.
- Policy Simulator: Allows testing of governance rules against historical data.
Related
- Project
- Project
- Project
- Project
- Project