Hover or tab to any cell for the full story. Click a column header to spotlight one tier; click again (or press Escape) to clear.
What this shows
Straza's four enforcement surfaces compared. Tier 1 (harness hooks) gives full local
governance (shell, file, net) plus everything the gateway does; with the managed, root-owned
install its enforcement artifacts are tamper-evident and attestation-gated. Tier 2, the MCP
gateway, is boundary-grade by construction because the PEP is server-side: any MCP client is
governed for MCP traffic, but local actions are invisible. Tier 3, the exec wrapper,
governs every spawned process for hookless agents; honest grading: advisory
on an open machine, boundary-grade only inside the documented sandbox profile. The Python
agentkit plugs into official framework seams (LangChain, OpenAI Agents SDK, Claude
Agent SDK, CrewAI, ADK, Pydantic AI) and delegates every decision to the Go kit; being
in-process it is advisory, strictly weaker than user-mode hooks, and its sessions carry
attestation=advisory at best, which enterprise policy can simply refuse for sensitive
roles. Green and amber here are trust semantics only.