PolicyCtl is a provider-agnostic policy runtime for AI coding agents. It enforces rules deterministically before actions execute, instead of relying on prompt instructions. One `.policyctl.yml` policy works across Claude Code, Cursor, OpenAI Codex, and CI, with sub-12ms local evaluation, pre-execution blocking, secret detection, policy-file protection, and native hook generation.
AI coding agents can write, delete, and execute code faster than you can review every action.
That is exactly why I built PolicyCtl.
PolicyCtl is a deterministic policy runtime that sits between your coding agent and your codebase, enforcing hard rules before actions execute. Define your policies once in `.policyctl.yml` and enforce them across Claude Code, Cursor, Codex, and CI.
Block secrets. Protect critical files. Restrict dangerous commands. Require tests. Let agents move quickly within boundaries you control.
Built for the point where AI agents stop being autocomplete and start becoming autonomous engineers.
What should your coding agent never be allowed to do?
WinScript