Skip to content

Overview

OpenLatch is the execution control layer for enterprise AI agents. It runs inside the agent’s own execution path and evaluates every covered action against your policies before it runs: allow, ask, block or optimize.

AI coding agents are powerful, but they operate with broad permissions in your development environment. A compromised prompt, a malicious dependency, or an adversarial injection can turn your helpful assistant into an attack vector.

OpenLatch runs inside the agent, not as a proxy in front of it, so it sees each action while there is still time to change the outcome.

  • Capture — A thin client intercepts agent tool calls before execution
  • Decide — The client evaluates the action locally against its resident policy bundle and returns the verdict in-process
  • Forward — The client sends what it saw to the platform afterwards, so the agent never waits on the network

Each policy runs in Monitor mode, which records what it would have done and lets the action through, or in Enforce mode, which applies the verdict. Today, on a covered agent, Allow and Block reach the agent as native decisions, Ask lets the action through and flags it for review, and Optimize is measured but not yet applied.

OpenLatch works with any AI coding agent that supports tool call hooks:

  • Claude Code
  • Codex CLI
  • Cline
  • Custom agents via the OpenLatch SDK
  • Zero configuration — npx @openlatch/client init is all you need, or the install script for your platform on a machine without Node.js
  • Local-authoritative — The resident policy bundle keeps deciding when the network is down
  • Privacy-first — Your code stays local; only action metadata is analyzed
  • Open source — The client is Apache-2.0-licensed and fully auditable