Capability is compounding. Containment is lagging.
Deadbolt is fail-closed execution: leased tools, blast radius, human stop, evidence for a lawyer. It does not shut down GPT. Sidecar down = deny. A bolt-on client is cooperative. mcp-proxy and build-in are enforced.
Why this exists
An agent that can call tools needs a lease, a stop, and a record. Deadbolt is that gate. It does not shut down a vendor model.
Does not shut down GPT
The model keeps running. The next tool call is what gets denied.
Not a lab research swarm
This is your agent. Deadbolt does not contain another lab's agents on the public internet.
Two modes
Build-in is enforced in process. Bolt-on serve and mcp-proxy are enforced at the socket. A client that skips admit is outside the trust boundary.
Crate n11-deadbolt
Depend on the crate and call the gate before the tool body.
serve and mcp-proxy
- deadbolt serve on a Unix socket, or loopback TCP with a token
- deadbolt mcp-proxy admits tools/call before the child runs it
- Clients are cooperative. mcp-proxy and build-in are enforced
- Sidecar down = deny
Operator verbs, not model tools: policy, approve, kill, incident. An irreversible tool is deny needs_human until one approve. The next call is allow once. The one after that is needs_human again. Kill makes the next tool deny killed.
Measured live fire
2026-09-28. One route that emitted tools. Ids as recorded. Not a benchmark. No customer count.
h-59378-18d9acf67c5ecdf8
- write_file → ok
- shell → needs_human
- approve, then shell → ok
- second shell → needs_human
- kill, then read_file → killed
h-60207-18d9ad7dce9803c8
Wrote LIVE-POLICY-B2. That write was allow. Killing P did not block B.
Install
The binary name stays deadbolt. The crate name is n11-deadbolt.