What flux7 does
flux7 sits between AI agents and the tools they call. Every call is checked against a policy before it reaches the tool, recorded in a verifiable trail, and, when the policy asks for it, held until someone or something with the authority to decide has decided.
No code change in the agent: it sees the same tools, through a proxy.
Four products, one core
flux7 is a family of four products. flux7-mesh is the core; the other three are separate products you add when you need them, and two of them are useful without the mesh at all.
| Product | What it is | On its own |
|---|---|---|
flux7-mesh · mesh7 |
the policy proxy: rules, approvals, traces | yes, it is the core; one Go binary, one YAML file |
flux7-memory · mem7 |
persistent, searchable memory for agents | yes, as a memory server for any MCP client; with the mesh, it also keeps human decisions as precedents |
flux7-supervisor · sup7 |
automated evaluation of tool calls | yes, as a decision service (POST /evaluate) for any hook or gateway; with the mesh, it settles the approval queue |
| flux7-console | dashboard and approval UI | no, it is a window onto the mesh, and onto memory and supervisor when present |
Each has its own repository, its own releases and the same licence, Apache 2.0. Nothing is sold separately, and nothing requires the whole family.
The question it answers
An agent with access to files, mail, a database or a cloud API can do something irreversible. Today there are two answers, and neither holds:
- Allow everything, and read the logs afterwards.
- Ask a human every time, until the human approves without reading.
flux7 fills the space between them. Rules settle what is clear-cut. What a human has already approved, repeatedly, stops being asked. What remains goes to an automated evaluator, then to a human if the evaluator is not confident.
What is governed
| Governed | How |
|---|---|
| MCP tools, local (stdio) or hosted (HTTP) | the agent connects to flux7-mesh instead of the server |
| REST APIs described by an OpenAPI spec | each operation becomes a governed tool |
| Command-line binaries | each subcommand becomes a governed tool, flags allowlisted |
| Tools that never transit the proxy, such as an agent harness's built-in shell or file tools | a hook asks the mesh "would you allow this?" before each call and enforces locally |
Any MCP client works: Claude Code, Cursor, Claude Managed Agents, the Agent SDK, LangChain, a plain script over HTTP.
What you get
- A decision per call, per agent, on the arguments. Not only "may this
agent use
send_email", but "may it send to this domain", "may it write outside this directory", "may it setcredit_limitabove 10 000". - Human approval outside the agent. Pending calls wait in a queue, answered from a terminal or a browser, by whoever is on duty.
- Precedents. A read a human approved three times, never refused, is approved on its own the next time. Writes are always asked again.
- An automated evaluator for the calls no rule and no precedent settles. It asks a small model narrow factual questions (does this delete, does it send local data out, does it touch secrets) and decides in code from the answers, with thresholds measured on real traffic.
- A trail that says why. Each call records the rule, the grant or the human approval that allowed it. The trace file is hash-chained, so an edited or deleted line is detected.
- Standard observability. OpenTelemetry export and Prometheus metrics, into the tools you already run.
What it does not do
- It does not govern model output. It governs tool calls: what an agent does, not what it says. Pair it with a guardrail on the model traffic if you need both.
- It does not replace an identity provider or an API gateway. It reads identity from JWTs issued by yours (Keycloak, Auth0, Cloudflare Access), and it runs behind a gateway such as Kong: the gateway checks who calls which tool, flux7 judges the call itself.
- Policy conditions match text. Denying
rm -rfdoes not stopRM -RFor a base64 payload. The automated evaluator exists for what text matching cannot see, and it is measured, not proven. - It is young. One maintainer, versions below 1.0. The features page states the maturity of each part.
How it is deployed
Self-hosted, on a laptop, a VM or in containers: two Go binaries (mesh7, mem7), a Python service (sup7), a Next.js app (console). Nothing leaves your network unless you configure it to: the supervisor's model can be local (Ollama) or remote.
Next: the feature list, how a call flows through the layers, or install it.