How It Works
OpenLatch runs inside every covered AI agent in three layers: the hook in the agent’s lifecycle, the decision the client makes locally, and the verdict the agent receives. Policies are authored on the platform, which also receives the record of what happened.
Architecture Overview
Section titled “Architecture Overview”AI Agent → Hook → Client (resident policy bundle) → Verdict → AI Agent
Platform ── policy bundle ──────────▶ ClientClient ──── events, sent afterwards ─▶ PlatformLayer 1: Hook
Section titled “Layer 1: Hook”The OpenLatch client installs lightweight hooks into your AI agent’s tool call pipeline. When an agent attempts an action — writing a file, running a shell command, making a network request — the hook intercepts it before execution.
What gets intercepted:
- File system operations (create, write, delete)
- Shell command execution
- Network requests
- Environment variable access
What does NOT get intercepted:
- Code generation (text output from the agent)
- Read-only operations (file reads, directory listings)
- Agent-to-user communication
Layer 2: Local Decision
Section titled “Layer 2: Local Decision”The client evaluates each covered action in-process against its resident policy bundle: your organization’s policies, compiled to deterministic rules. The agent never waits on the network, and the verdict never depends on it. Afterwards, the client forwards what it saw to the platform. That payload carries action metadata, not your source code.
Each rule runs in Monitor mode, which records the match and lets the action through, or in Enforce mode, which applies the verdict. When several rules match, the most restrictive verdict wins.
Layer 3: Verdict
Section titled “Layer 3: Verdict”| Verdict | What happens today |
|---|---|
| Allow | The action proceeds |
| Ask | The action proceeds and is flagged for review. The agent is not held waiting for a human |
| Block | The agent receives a native deny that names the rule that produced it |
| Optimize | Measured, not applied. OpenLatch records what the change would have saved and forwards the original request |
A verdict is deterministic because an explicit policy produced it.
Offline Behavior
Section titled “Offline Behavior”The resident policy bundle is the authority, not a cache. It keeps enforcing with the network unplugged, and if a refresh fails, the client keeps the last known good bundle. Syncing policies and sending events need a connection; deciding does not.
Privacy
Section titled “Privacy”OpenLatch sends action metadata to the cloud, not your source code:
- Command strings (e.g.,
rm -rf /) - File paths being written to
- Network destinations
- Session context (agent type, project hash)
File contents, source code, and environment variables are never transmitted.