Open-source portfolioSany Alam / Independent project / 2026

DAAI Console

A cooperative governance layer for registered Python agent actions.

Before an automation takes a consequential action, ask for permission. Evaluate a deterministic policy, pause for human approval, and record what happened. The developer's application owns the actual execution.

The original hosted beta is discontinued. This page showcases the implementation; it is not a live governance service.

A proposal becomes an action story.

Verified local demo
Verified demo output: an allowed action executes locally, a pending action waits, approval permits execution, rejected and blocked actions do not run, and reused or invalid tokens are refused.
Actual SDK and FastAPI logic. Synthetic invoice data, in-memory persistence, and a simulated executor. No email, payment, or external business action.
  1. 01

    Propose

    The Python SDK submits a registered action and payload before execution.

  2. 02

    Govern

    A deterministic rule allows, blocks, or requests an expiring human decision.

  3. 03

    Execute locally

    The application's executor runs only when the API explicitly permits it.

  4. 04

    Report & record

    Execution results and the governance receipt complete the action story.

Small boundary. Deliberate choices.

Implementation
Deterministic runtime policy
Four explicit policy types. No LLM calls decide whether a runtime action may execute.
Governance and execution are separate
An approval authorizes execution; it does not claim success. Both states remain visible.
Explicit trust boundary
Hashed keys and expiring decision tokens protect access. Applications must cooperate with the gate.
Replay with payload identity
Workspace-scoped idempotency returns the existing run and refuses conflicting payloads.

Built with

Python · FastAPI · PostgreSQL · Supabase Auth · Next.js · Tailwind

DAAI does not intercept arbitrary code or enforce an OS-level sandbox. External side effects and exactly-once execution remain the developer's responsibility. The full dashboard needs a separate Supabase setup; the isolated demo is the verified starting point.

Inspect the work.

Source, schema migrations, regression tests, and a reproducible local walkthrough. MIT-licensed project source, with the original deployment history kept private.