A Reference Monitor for Agents
PPE acts as a reference monitor between an agent and the tools, agents, and data it can access.
PPE is a typed policy runtime for AI middleware. It maps tools, resources, prompts, inference calls, and conventional APIs to routes by entity type and name. PPE combines global defaults, matching groups, and route controls into phases that validate inputs, authorize operations, apply effects, and transform results. The pipeline controls which operations run, what data returns, and where it may flow.
Before policy evaluation, PPE verifies the caller with the IdP and maps subject, role, and permission claims into attributes. The Policy stage evaluates predicates and invokes CEL, Cedar, or OPA where configured. Effects can redact data, request approval, apply session taint, or perform token exchange / delegation for an audience-scoped upstream credential. The session store carries information-flow labels across calls. PPE records the delegation chain and audit history.
data.*http: route selector, precedence, and the catch-all reportPPE acts as a reference monitor between an agent and the tools, agents, and data it can access.
APL (Authorization Policy Layer) defines PPE enforcement pipelines.
SPDX-License-Identifier: Apache-2.0 Copyright (c) 2026 Praxis Contributors –>
PPE ships a Criterion suite that measures the decision hot path: plugin dispatch, a full route decision, per-PDP evaluation, throughput under concurrency, and heap use per decision.
PPE ships a set of plugins, decision points, and a session store, each behind a Cargo feature.
Map typed Common Message Format extensions into the attribute bag that APL policies inspect.
APL evaluates policy against a request in the Common Message Format (CMF).
A PPE configuration is one YAML document. It declares the plugins the process can reach, the cross-cutting wiring, and the policy that decides which of them run for a given operation.
PPE is a Cargo workspace. Most hosts depend on praxis-policy, the facade, and nothing else: it re-exports the runtime and, behind features, the bundled extensions.
PPE is the enforcement point, but where that point sits is your choice.
Alongside the message, every operation carries typed extensions: the contextual state policy reasons about.
Understand how PPE evaluates identity and APL policy for each operation, then applies effects before allowing it to reach a backend.
Adding a preset is data-driven; no new mapper implementation or resolver branch is needed.
Most routes select an operation by name: a tool:, a resource:, a prompt:, an llm:.
PPE resolves the inbound caller and mints the outbound credential on every request.
These production patterns cover APL authoring and rollout.
APL defines policy. The execution pipeline runs its effects. Write pipeline code only to add an effect through a plugin or inspect effect ordering and execution.
Stand up PPE and run the scenario: a get_employee route that authorizes by role and redacts a field by permission.
Test APL by loading a policy, driving operations through the runtime, and asserting each outcome. Most route tests need no live backend.
This threat model defines the assumed adversary, the Reference Monitor boundary, and the coverage of each deployment placement.
Rewrite the keys and forms listed below. Each entry states the old behavior, the replacement, and the load error produced by a missed migration.
Explore end-to-end PPE deployments for AI gateways, identity providers, delegated credentials, and policy enforcement.