Mandatory access control for AI agents. A product of BadCompany.
Agents were built on the newest, tallest stack. More model, more tools, more abstraction. That is playing with fire.
Lilith is the older idea. Its policy engine decides each tool call. Its kernel enforcer makes the decision bind. Two parts. Simple machinery. Highest guarantee.
Properties
Fail closed: enforcer dies, the process is caged.
Stateful: what it already did still counts, so a later deny can depend on an earlier call. ARM locks the session if it keeps eating denials.
Formally verified policies: key properties like consistency are proven before anything goes live.
p50 under 20 microseconds on the decide path.
Just a Linux kernel is needed to run it.
Works with coding agents and custom agents. The policy engine is an interoperable protocol, so Lilith integrates without a vendor plugin.
Rich decision logs which cannot be quietly rewritten. A rewrite is exposed.