Kernall
Desktop downloads

The agent sandbox for work that matters.

Kernall gives every agent run a disposable workspace, scoped identity, controlled network access, and an approval gate before changes reach the real world.

Give the task authority. Never the agent.

Every run gets a disposable execution cell, scoped identity, private workspace, and atomic promotion path.

Explore the runtime

The agent works in here. Your system stays out there.

Kernall gives every run a disposable environment, temporary permissions, and a controlled path for approved work to leave.

Inside the sandbox

Kernall, in your workflow.

Your tools. Your team. One sandbox.

Fits the way you build.

On your desktop, in your terminal, or through your AI tools. Three ways into Kernall, currently in development.

Read the documentation
DesktopPlanned

A home on your desktop.

A desktop companion to manage sandboxes, inspect agent activity, and review approvals without leaving your workflow.

Desktop installers are not released yet.

Kernall Desktop
KernallChoose macOS or Windows

Select your computer above to see the planned desktop download.

Desktop guide
TerminalPlanned

Stay in your flow.

Launch runs and follow agent activity from your shell. Choose your package manager for a preview of the planned CLI install.

Install KernallCLI · Not released
# brew install <kernall-formula>

Preview only. These placeholders do not install Kernall. Official commands will appear at release.

How to use

Uses Homebrew. The official formula will be linked here when the CLI is released.

Once released, choose one method and paste its official command into your terminal. You will not need all four package managers.

Homebrew documentation

Try the developer console now

Terminal guide
MCPPlanned

Your tools, connected.

Connect compatible AI tools to Kernall through Model Context Protocol. Request sandbox runs with scoped access and approval checks.

MCP connection Planned flow
AI tool
Requests a run
Kernall
Checks policy
Sandbox
Returns the result
MCP guide

THE KERNALL WORKFLOW PRODUCT VISION

Every agent needs
a sandbox you control.

  1. Bring your agent.

    Connect the tools you use and give them one place to work.

  2. Set the boundaries.

    Choose what the task can access and what needs approval.

  3. Work in isolation.

    Let the agent make changes and run checks inside its sandbox.

  4. Inspect the result.

    See the activity, files, commands, and checks behind the work.

  5. Approve what leaves.

    Ship the result you want. Keep everything else contained.

One policy plane. Every agent surface.

Control the action wherever it lands.

File system

Private overlays, classified paths, atomic promotion

Shell

Command policy, process isolation, syscall evidence

Network

Semantic egress inspection, scoped destinations

MCP + tools

Per-tool capabilities, argument checks, receipts

Browser

Origin boundaries, session isolation, action trails

Cloud APIs

One-task credentials, spend limits, revocation

Observe first. Enforce when ready.

Kernall records outside the model's context, so the agent cannot adapt its behavior to the evaluator. Start in observe mode, turn real traces into policy, and graduate high-confidence rules into enforcement.

Observe

Record causality without blocking execution.

Enforce

Pause, deny, or require approval at the boundary.

CAUSAL TRACE / 9B4C00:03.842
00:00.000TASKSession createdPASS
00:00.416IDENTITYCredential lease issuedPASS
00:01.203TOOLcrm.search_accountsPASS
00:02.114NETWORKUnknown destinationPAUSE
00:03.842HUMANEscalation deliveredWAIT
5 EVENTSTRACE INTEGRITY VERIFIED ✓

Infrastructure for teams responsible for what agents do.

One evidence layer across development and deployment.

Evaluate behavior, not just answers.

Capture ground-truth execution traces for capability, alignment, and adversarial evaluations without changing the agent harness.

Ship autonomy with enforceable boundaries.

Give every customer workflow the same portable isolation, policy, approval, and evidence layer.

Turn agent intent into reviewable action.

Observe deployments first, write policy from real behavior, then enforce controls without rebuilding the application.

Research for a world of acting models.

Run agents with proof.

Open the console Request access