A home on your desktop.
A desktop companion to manage sandboxes, inspect agent activity, and review approvals without leaving your workflow.
Desktop installers are not released yet.
Select your computer above to see the planned desktop download.
KernallKernall gives every agent run a disposable workspace, scoped identity, controlled network access, and an approval gate before changes reach the real world.
Every run gets a disposable execution cell, scoped identity, private workspace, and atomic promotion path.
Explore the runtimeKernall gives every run a disposable environment, temporary permissions, and a controlled path for approved work to leave.
Inside the sandboxKernall, in your workflow.
On your desktop, in your terminal, or through your AI tools. Three ways into Kernall, currently in development.
Read the documentationA desktop companion to manage sandboxes, inspect agent activity, and review approvals without leaving your workflow.
Desktop installers are not released yet.
Select your computer above to see the planned desktop download.
Launch runs and follow agent activity from your shell. Choose your package manager for a preview of the planned CLI install.
# brew install <kernall-formula>Preview only. These placeholders do not install Kernall. Official commands will appear at release.
Uses Homebrew. The official formula will be linked here when the CLI is released.
Once released, choose one method and paste its official command into your terminal. You will not need all four package managers.
Connect compatible AI tools to Kernall through Model Context Protocol. Request sandbox runs with scoped access and approval checks.
THE KERNALL WORKFLOW PRODUCT VISION
Connect the tools you use and give them one place to work.
Choose what the task can access and what needs approval.
Let the agent make changes and run checks inside its sandbox.
See the activity, files, commands, and checks behind the work.
Ship the result you want. Keep everything else contained.
One policy plane. Every agent surface.
Private overlays, classified paths, atomic promotion
+Command policy, process isolation, syscall evidence
+Semantic egress inspection, scoped destinations
+Per-tool capabilities, argument checks, receipts
+Origin boundaries, session isolation, action trails
+One-task credentials, spend limits, revocation
+Kernall records outside the model's context, so the agent cannot adapt its behavior to the evaluator. Start in observe mode, turn real traces into policy, and graduate high-confidence rules into enforcement.
Record causality without blocking execution.
Pause, deny, or require approval at the boundary.
Infrastructure for teams responsible for what agents do.