OpenBot enforces audit logging before any bot action executes, not after
OpenBot, an open-source agent framework described as a template rather than a finished product, routes every bot action through a single gateway that evaluates policy and writes an audit record before the action is carried out. The system uses CEL-based rules to inspect tool names, file paths, shell commands, and other parameters, and is designed to fail closed — a missing or broken policy blocks rather than permits. Sensitive data such as secrets are partially obscured in logs, recording only that a request was made and the length of the value, not its contents. Human takeovers during bot sessions — such as handling login walls or two-factor prompts — are also logged, and bot actions are refused rather than queued while a person is in control. The project is currently in alpha, has no hosted version, and is explicitly intended as a starting point for teams to adapt with their own configuration.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in