Features
State as of September 2026. Stable: used daily, tested, documented. Early: works, recent, may change. Planned: not there yet.
flux7-mesh: policy, approvals, traces
v0.17.2 · Go · overview
| Capability | State | Details |
|---|---|---|
| Proxy MCP servers (stdio, SSE, Streamable HTTP) | Stable | Configuration |
| Import OpenAPI specs and CLI binaries as tools | Stable | CLI tools |
| Serve agents over MCP stdio, MCP HTTP and REST | Stable | Deployment modes |
| Policies per agent and per tool: allow, deny, human approval | Stable | Writing policies |
| Conditions on arguments (numbers, text operators) | Stable | Writing policies |
| Hot reload of policies | Stable | |
Decide without executing (POST /decide), for tools outside the proxy |
Stable | Agent security |
| Claude Code hook covering built-in tools | Stable | Python SDK |
| Approval queue, answered from CLI, console or API | Stable | Approval flow |
| Temporary grants ("sudo for agents") | Stable | Approval flow |
| Approvals and grants survive restarts | Stable | |
| Rate limiting and loop detection | Stable | in-memory, reset on restart |
| JWT identity from an external IdP, end user recorded | Stable | JWT authentication |
| Authenticated control plane | Stable | Control plane auth |
| Tool classification (read, write, destructive) and draft policies | Early | Tool classification |
| Catalogue pinning: hold back new or changed upstream tools | Early | opt-in |
Hide from tools/list what the policy can only deny |
Early | opt-in |
| Prompt-injection tripwire on arguments | Early | a regex that blocks auto-approval, not a defence |
| Hash-chained traces, HMAC-signed, verifiable offline | Stable | Trace integrity |
Chain of authority per call (/traces/{id}/why) |
Stable | |
| OpenTelemetry export, Prometheus metrics | Stable | Observability |
| Conditions on JWT claims | Planned | |
| Semantic conditions beyond text matching | Planned |
flux7-memory: precedents and agent memory
v0.5.1 · Go · overview
| Capability | State | Details |
|---|---|---|
| Store and search memories over MCP, HTTP and Python | Stable | API reference |
| Hybrid search: keyword, vector, LLM reranking | Stable | 71 % on the LoCoMo benchmark |
| Markdown files as source of truth, index rebuildable | Stable | |
| Human approvals kept as facts, used as precedents by the mesh | Stable | Memory integration |
| Access control per fact | Not planned | one token per instance; who may read or write what is a mesh policy on the memory.* tools |
flux7-supervisor: automated evaluation
v0.1.0 · Python · overview · install from GitHub, not on PyPI
| Capability | State | Details |
|---|---|---|
| Rules before any model call | Stable | Configuration |
| Decision model asked typed questions, decision taken in code | Early | in production since 2026-09-29, Jev and question sets |
| Provider chain with circuit breaker (Jev, Ollama, Anthropic) | Early | |
| Question sets in YAML, extensible per business | Early | |
| Bench: case sets, free recompute, paid replay | Early | Measuring |
Judge one call on demand (POST /evaluate), without the mesh |
Early | |
| Claude Code as reviewer, with codebase context | Planned | Claude Code callback |
Thresholds were measured on about a thousand calls from one team, with no danger approved; the boundary cases were written by the same people who wrote the questions. Each deployment should measure its own.
flux7-console: dashboard and approval UI
Next.js · overview
| Capability | State | Details |
|---|---|---|
| Approval queue in the browser, with who settled what and why | Stable | |
| Traces with chain of authority and integrity badge | Stable | |
| Tools catalogue, per-agent decision editable | Early | writes the agent's policy file through the mesh |
| Supervisor state, YAML editing, bench runs | Early | |
| Memory browser, sessions, OTLP spans | Early | |
| Governance scoring, agent lifecycle, dependency graph | Planned |
The console has no login of its own: run it on a private network or behind your SSO proxy.