Policy gateway for AI agents (Cursor, Claude Code, Codex, MCP): every tool call is evaluated against a YAML policy, logged in a tamper-evident ledger, and risky actions can be gated for approval. One-command setup, rollback for file/git ops. MIT license.