AI agents can build. AuraBoot makes them safe to run.
Code-generating agents happily write straight to your database — no schema contract, no authorization boundary, no trail. AuraBoot is the runtime underneath: every write, from a person, an automation, or an agent, passes the same two gates and lands in one audit log.
Every write passes the same two gates
Verified mechanics, not aspirations — this is the exact behavior you can reproduce from the getting-started tutorial.
All writes arrive at one endpoint, /api/meta/commands/execute. The endpoint itself requires meta.command.execute — a permission you grant per role. Deny by default: a role without the grant is refused before any business logic runs.
Past the endpoint, the command’s own declaration applies: its permissions, its input whitelist, its state guard. A value the command never agreed to accept is dropped — even when the API answers “success”.
A person clicking Save, an automation, a BPM node, an AI agent calling a tool: four identities, one path, the same two lines. There is no second way in — that is the design.
What a generated app does — with and without a runtime
| Generated app, direct writes | Generated app, on AuraBoot | |
|---|---|---|
| Schema | The model guesses your tables; drift is discovered in production | Declarations create and evolve the schema — columns follow the model file in Git |
| Authorization | Prompt-level at best; any caller with network access writes anything | Two hard gates per write: endpoint permission, then the command’s own role contract |
| Input | Whatever the model emits is trusted | Declared whitelist per command — undeclared fields are silently dropped |
| State | No guards; invalid transitions overwrite real data | State-machine guards and validation run inside the pipeline, per command |
| Trace | Console logs, if you wrapped them | Every accepted execution lands in the audit log — command, phase, duration, payload |
Commands declare risk and intent
Commands carry machine-readable hints for agents: what the command does, which fields it accepts, its risk level, its idempotency. An agent does not have to infer intent from UI scraps — the contract is the declaration.
The audit trail is a property, not a feature
Every execution that gets past the gates is recorded — what the pipeline accepted, how far it got, how long it took. You did not turn it on, and you cannot turn it off for one caller and not another, because there is exactly one caller: the pipeline.
Not a chat box bolted on the side
In-app copilot for natural-language queries, data operations and guided workflows.
Orchestrate agents with skills, tools and memory (enterprise edition).
Ask questions in natural language; get charts and tables back.
Upload PDFs, DOCX, MD, CSV — vector-indexed for retrieval.
OpenAI, Anthropic, Zhipu GLM, MiniMax through one provider interface.
Run the governed path yourself
Ten minutes, in the tutorial: add a field, watch the platform refuse an undeclared write, meet both gates, read the audit trail.