Tools
Halofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasure
halofyai/halofy (created 2026-08-22, 300 stars in four days, AGPL-3.0, TypeScript) targets the org-level problem of what agents are allowed to touch, offering access control, RBAC, scoped access, tenant isolation, data provenance, audit logs and signed erasure as a single layer across an organization's agents. Its topic list names pgvector and model-context-protocol, indicating it sits between MCP servers and agent memory rather than inside any one agent runtime. Signed erasure is the unusual piece: a verifiable record that agent-held context was actually destroyed, which is what compliance teams ask for and almost no agent stack currently answers.
Source
↳ Follow the thread