CTRLRun
CTRLRun is an open-source Python execution-safety layer for AI-agent actions. It sits between an agent's decision to act and the consequential call, applying policy, human approval, reservation, execution, outcome resolution and tamper-evident receipts.
At a Glance
- Developers and engineering teams building AI agents
- Organizations operating consequential AI workflows
- Teams using MCP, LangChain, LangGraph or the OpenAI Agents SDK
- Operators needing policy enforcement, approvals, exactly-once effects and audit evidence
AI Tools by CTRLRun
(1)ctrlrun
AI Agent Action Policy Layer
Discussions
No discussions yet
Be the first to start a discussion about CTRLRun
Latest News
CTRLRun 0.12.2 released with MCP registry manifest and improved operator-tool descriptions
CTRLRun 0.12.1 released with verify-tool fixes; published release grades 22 of 22 applicable guarantees
CTRLRun 0.12.0 released as a hardening milestone with property tests, SBOM generation and architecture fixes
LangChain middleware adapter and its documentation were added to the repository and published-record work was merged
Products & Services
Apache-2.0 Python package (Python 3.11+) providing @protect, policy-driven allow/approve/deny decisions, approval binding, effect-key reservation, explicit AMBIGUOUS outcomes, receipts, authority/delegation, observe mode, verification and operational CLI commands.
A gateway that places the execution boundary in front of an existing MCP server, enforcing policy and approval without requiring changes to the agent; it supports tools behind MCP in any language.
Operator MCP server exposing read and write commands so an approver can inspect pending actions and answer approvals from an MCP client; release 0.12.2 added the official registry manifest, and subsequent source changes added stdio operation.
LangChain middleware adapter that gates tool calls through wrap_tool_call so refused calls do not run and decisions leave receipts.
Market Position
CTRLRun positions itself at the execution boundary rather than as a model guardrail, general agent-oversight dashboard, durable workflow engine or single-API idempotency key. Its differentiators are exact-action approval binding, cross-host effect reservation, explicit treatment of lost/unknown outcomes as AMBIGUOUS, and receipts that record the decision and evidence.
Leadership
Founders
Arpan Ghoshal
Applied AI Engineer and independent consultant; his public profile says he builds production AI systems including LLM pipelines, agents, retrieval and evaluation. Previously Director of AI Innovation at Operating Equity Partners (Vivid Labs Holdings, Inc.), where he led AI product launches and built agent-reasoning, evaluation and observability systems; he also identifies himself as CTRLRun's creator and maintainer.
Executive Team
Arpan Ghoshal
Creator and maintainer
Applied AI Engineer and independent consultant; previously Director of AI Innovation at Operating Equity Partners (Vivid Labs Holdings, Inc.).
Founding Story
The project was started around the observation that an AI agent able to send money, delete infrastructure or email a customer needs more than a good prompt. Its initial vision is to make consequential actions safe to execute by binding approval to the exact action, preventing duplicate effects, treating uncertain outcomes as ambiguous rather than failed, and recording evidence.
Business Model
Revenue Model
The core ctrlrun distribution is open-source under Apache-2.0 and installable from PyPI; the public sources reviewed do not describe a paid plan or a CTRLRun-specific commercial revenue stream.
Target Markets
- Developers and engineering teams building AI agents
- Organizations operating consequential AI workflows
- Teams using MCP, LangChain, LangGraph or the OpenAI Agents SDK
- Operators needing policy enforcement, approvals, exactly-once effects and audit evidence
- Agent-initiated payments, refunds and payouts
- Infrastructure and Kubernetes operations
- Database migrations
- IAM and credential rotation
- CRM and customer-record updates
- Data deletion under retention rules