Features

RADIUS is designed around deterministic enforcement, transparent decisions, and operational safety for agentic workflows.


Core capabilities

Deterministic policy engine

Multi-layer protection

Human-in-the-loop safety

Operational observability

Runtime resilience


CLI workflows

RADIUS ships with practical commands for setup and validation:


Profile model

ProfileIntentDefault actionTypical use
localstrict containmentdenyproduction, credentials, billing systems
standardbalanced protectiondenydevelopment/staging
unboundedobservation modeallowexploration, migration rehearsal

Framework integration

OpenClaw

Generic mode


Security posture summary

RADIUS is strongest when used as:

  1. fail-closed policy (defaultAction: deny)
  2. explicit tool allowlisting
  3. strict filesystem/network constraints
  4. continuous pentest + audit review

Next docs