Straza / enforcement tiers

Comparison of Straza enforcement tiers Four columns compare Tier 1 harness hooks, Tier 2 MCP gateway, Tier 3 exec wrapper and the Python agentkit across what they govern, what they see, their trust grade and their identity story. Green means boundary-grade or attested; amber means advisory. GOVERNS SEES TRUST GRADE IDENTITY TIER 1 harness hooks Claude Code · Codex · Gemini3 harnesses TIER 2 MCP gateway any MCP client TIER 3 exec wrapper straza exec -- cmd SDK AGENTS python agentkit straza-agentkit local tools: shell · file · net + MCP via the gateway + knowledge packs at start + conversation capture tools/list + tools/call per-call policy · rps limits credential injection local actions: not governed every spawned process argv → canonical tool.pre deny reason on stderr, exit 2 same PDP, same taxonomy native Python tool calls @guard + framework seams capture: prompts + replies MCP stays a gateway job role catalog only: inventory ∩ exposure ∩ bindings unbound tool = nonexistent deny reasons in-harness same filtered catalog deny-with-reason on calls local commands invisible prompts/replies invisible argv + exit codes decisions + audit trail no prompt/reply seam (no transcript exists) framework tool calls, mapped by adapters yaml prompts/replies in payload unknown tools → "other" managed: attested user-mode: advisory boundary-grade PEP server-side; creds never reach the agent advisory: open machine sandbox: boundary-grade advisory: in-process attestation=advisory at best; weaker than user-mode hooks OIDC device-flow enroll token binds user + device + harness + session · 300 s attestation at checkin session token at the gate minAttestation re-enforced from token claims reached through straza mcp exec-wrapper/<version> lazy checkin per invocation distinct harness identity: policy can gate Tier-3 python-sdk/<fw>@<ver> uses the machine's enrollment headless: NHI client-creds or a registered agent key hooks are one layer, never the only one: the gateway PEP governs MCP for every tier, and policy may require Tier-1 attestation for sensitive roles
Hover or tab to any cell for the full story. Click a column header to spotlight one tier; click again (or press Escape) to clear.
What this shows

Straza's four enforcement surfaces compared. Tier 1 (harness hooks) gives full local governance (shell, file, net) plus everything the gateway does; with the managed, root-owned install its enforcement artifacts are tamper-evident and attestation-gated. Tier 2, the MCP gateway, is boundary-grade by construction because the PEP is server-side: any MCP client is governed for MCP traffic, but local actions are invisible. Tier 3, the exec wrapper, governs every spawned process for hookless agents; honest grading: advisory on an open machine, boundary-grade only inside the documented sandbox profile. The Python agentkit plugs into official framework seams (LangChain, OpenAI Agents SDK, Claude Agent SDK, CrewAI, ADK, Pydantic AI) and delegates every decision to the Go kit; being in-process it is advisory, strictly weaker than user-mode hooks, and its sessions carry attestation=advisory at best, which enterprise policy can simply refuse for sensitive roles. Green and amber here are trust semantics only.