← All work

Author

Gravel

Guardrails for AI agents: scope validation, human approvals, emergency stop and an audit trail.

Status: Rust workspace with a terminal UI

The problem

An AI agent that can run tools can act on targets it was never meant to touch. It needs enforced limits and a human who can say no, and that control has to sit between the agent and the tool transport.

What I built

Gravel is a terminal app that mediates every tool call: it checks scope, asks the operator to approve, can halt everything instantly, and records what happened.

OutcomeVersion 0.1.0 (February 2026): a five-crate Rust workspace with CI for tests, clippy and rustfmt, and cargo-dist release automation for macOS, Linux and Windows.

What it does

Try it

A working replica of the real interface, running on made-up sample data.

Architecture

How the pieces connect, drawn from the project's own documentation.

Gravel architectureThree rows. First, the gate: the agent proposes a tool call, the scope check extracts targets from the arguments and validates them against allow and block lists (violations are denied and logged), the operator approves or denies in the terminal UI, and approval yields a signed token. Second, execution: the MCP interceptor accepts only requests that carry the token, sends them over a stdio or HTTP transport, and the tool server runs them. Third, always on: an audit log records sessions, requests, approvals, denials, executions and scope violations, and an emergency stop halts new requests and pending work.Gate · before anything runsAgentmodel backend proposes a tool callScope checktargets extracted from arguments;allow and block lists, CIDROperator approvalqueued in the TUI overlay; approve ordenySigned tokenissued on approvalapproved requests onlyExecute · MCP layerMCP interceptorscope, risk and approval awareTransportstdio or HTTPTool serverruns only with a signed tokenAlways onAudit logsession, request, approval, denial,execution, scope violationsEmergency stopstop new requests; cancel or denypending work
Mechanism: a tool call moves from raw request to scoped request to signed token, and only a signed request can reach the tool transport.

Engineering decisions

How it's secured and shipped

Stack

Want this kind of work on your team?