Documentation

Glossary

Alphabetical reference with visual cards.

TURI
The AI agent firewall for macOS — runtime execution governance at the endpoint.
MacFirewall
Internal engineering codename — app, extensions, Swift packages. Customer-facing name is TURI.
DriftCop
Internal name for the policy JSON format and supply-chain broker semantics.
Endpoint Security extension
Sandboxed ES client — AUTH path (not a custom KEXT).
enforcement_mode
Policy key: monitor (log) vs enforce (drop/deny).
Observation mode
App toggle isObservationModeSync — workflow simulate.
ExecGovernor
Primary AUTH_EXEC evaluator from threat matrix + ancestry.
DECIDE
Supply-chain install gate reading local verdict cache.
VerdictCache
mmap macfirewall_verdicts.bin — async scores to sync ES.
decision_hash
SHA-256 audit digest for SIEM replay of install/exec decisions.
CompiledIRPolicy
Graph IR evaluated by IRExecutionEngine.
RuleEvaluator
FSM step-rule engine over AgentEvent streams.
BehavioralVelocityEngine
Host-app actor: ingests AgentEvents, runs rules, flushes VerdictCache.
CausalGraph
In-process DAG linking exec, file, network, and semantic install nodes.
Graph invariant
Structural rule (e.g. orphanExecution) evaluated on the DAG, not a verb sequence.

Running AI agents on Mac at scale? We'll tune policy with you.

Design partners →