AI agents now have access to your shell, credentials and production code.
They shouldn't be responsible for policing themselves.
▮
Agent
⛁ ⌗ ⇅
Tools
Doberman
Objective
Known dangerous behavior
secret exfildestructiveknown attacks
Subjective
What's normal for you
usual commandsusual hostsusual paths
⇧ raise-only
DOBERMAN
An agent action needs your decision
Your agent wants to run a command: git push --force main
This rewrites history on a shared branch — it can permanently erase commits your teammates already pushed.
Auto-denies in 1:58 if you don't answer.
PASSAUTHBLOCK
Doberman
Watches everything, trusts nothing, fails closed.
local-first · fails closed · open source · github.com/DobermanCore/Doberman-Core