Control Zero とは?
Control Zero は AI エージェント向けのガバナンスレイヤーです。エージェントに許可することを定義すると、Control Zero が実行時にそれを適用します。Claude Code、Gemini CLI、Cursor IDE、Kiro CLI では、拒否(deny)されたツール呼び出しは実行前に停止されます。
英語の原文 -- 翻訳は技術レビュー待ちです
Coverage is declared per event, so the audit trail never implies protection for a call path that was not covered.
Kiro IDE は適用面ではありません。
Hello World
実際に動作する Python の「Hello World」です。サインアップ不要、API キー不要、ネットワーク不要です。
pip install controlzero
# hello_controlzero.py
from controlzero import Client
# Define what your agent is allowed to do.
# Read operations: allowed. Write operations: blocked.
# Note: `database:query` and `database:execute` are legacy action names
# that remain supported. The canonical names are `database:read` and
# `database:write`; both forms match the same calls.
cz = Client(policy={
"rules": [
{"allow": "database:query", "reason": "Reads are fine"},
{"deny": "database:execute", "reason": "No writes from this agent"},
]
})
# Your agent tries to read; allowed.
result = cz.guard("database", method="query", args={"sql": "SELECT id FROM orders"})
print(result.decision) # "allow"
# Your agent tries to write; blocked before it ever runs.
result = cz.guard("database", method="execute", args={"sql": "DROP TABLE orders"})
print(result.decision) # "deny"
print(result.reason) # "No writes from this agent"
実行します。
$ python hello_controlzero.py
allow
deny
No writes from this agent
これがループのすべてです。ポリシーを書き、各ツール呼び出しの前に guard() を呼び出すと、SDK が許可か拒否かを判定しました。拒否された呼び出しは実行されていません。適用のためのコード、認証チェック、許可リストのロジックは一切書いていません。
レガシー名(database:query、database:execute、database:delete)と正規名(database:read、database:write、database:admin)のアクション名は、どちらも同じ呼び出しに一致します。新しいポリシーには正規名を使ってください。レガシー名を使った既存のルールは、変更なしでそのまま動作し続けます。対応表の全体はポリシーを参照してください。
次のステップは、ポリシーをコードから Control Zero ダッシュボードへ移すことです。そうすれば再デプロイせずに変更できます。ダッシュボードを使った 5 分間の手順はクイックスタートを参照してください。
解決する課題: AI エージェントは、ツールを呼び出し、コードを実行し、API を叩き、MCP を通じてサービスにアクセスします。自律性が高まるほど、明確で検証可能な適用の約束事を備えたガードレールが必要になります。Control Zero は、その ガードレールを定義する 1 つの場所を提供し、適用面では拒否された呼び出しを決定論的にブロックし、各イベントのカバレッジを記録します。機能マトリクスは SDK 自身の機能宣言から導出されています。インストール済みの SDK が実際に宣言している内容をエクスポートするには controlzero coverage --json を実行してください(引数なしの controlzero coverage は、ホストごとの短い要約のみを表示します)。
Control Zero を選ぶ理由
-
ゲートウェイプロキシ: コード変更なしで LLM トラフィックを統制する、透過的なドロップインプロキシです。ベース URL を変更するだけで完了です。
-
英語の原文 -- 翻訳は技術レビュー待ちです
Local enforcement: Every action is evaluated against your policies without a per-call network round-trip.
-
ツール呼び出しのインターセプト: すべての tool_use(Anthropic)と function_call(OpenAI)がポリシーに照らして評価されます。拒否された呼び出しは、エージェントに届く前にインラインで置き換えられます。
-
英語の原文 -- 翻訳は技術レビュー待ちです
DLP detection, masking, and blocking: Detect or block sensitive data in prompts. On Claude Code and Gemini CLI, Python SDK hooks can redact matches in place and let the call proceed. On the coding-agent surfaces that cannot accept rewritten tool input -- Cursor, Kiro, Codex CLI, Antigravity -- a mask rule becomes a deny, so the secret never reaches the tool either way. The Gateway can mask, on both the request and the response path, but does neither by default: it detects. See Gateway for the two switches and which one a policy bundle can set.
-
モデルのブロック: ゲートウェイのレベルで、許可されていないモデルへのリクエストを拒否します。
-
コスト上限: 推定トークンコストが予算を超えた場合にリクエストを拒否します。
-
英語の原文 -- 翻訳は技術レビュー待ちです
Secret injection: Store LLM provider keys in an encrypted vault. The SDK and gateway inject them at runtime.
-
英語の原文 -- 翻訳は技術レビュー待ちです
Tamper detection: Policy bundles are encrypted at rest and cryptographically signed. A bundle that fails verification is never loaded, and the event is logged and reported. The SDK re-fetches its signing keys once in case they rotated; if verification still fails, the bundle is refused rather than trusted. During a background refresh the agent keeps enforcing the last known good policy; at startup there is nothing to fall back to, so calls are denied. See tamper detection.
-
英語 の原文 -- 翻訳は技術レビュー待ちです
Fail closed by default: When Control Zero cannot establish coverage, it denies rather than guesses. An unavailable policy bundle blocks traffic instead of silently allowing it.
-
マルチプロバイダー対応: Anthropic、OpenAI、Ollama、DeepSeek、MoonshotAI、HuggingFace TGI、LangChain、CrewAI などに対応しています。
-
公式 SDK: Python と Node.js。インストールして、2 行のコードで AI クライアントをラップできます。
-
MCP サーバー: Claude Code、Cursor、Windsurf などの AI コーディングクライアントから、直接ガバナンスを管理できます。
-
MCP ネイティブ: MCP に対応したあらゆるクライアントにわたり、MCP ツール呼び出しに対する一級のガバナンスを提供します。
-
英語の原文 -- 翻訳は技術レビュー待ちです
Complete audit trails: Every decision is logged with action, resource, result, timestamp, agent identity, and per-event coverage. “Did not run” is distinguishable from “ran and found nothing.”
-
コードから導出される機能マトリクス: 適用面のマトリクスは SDK 自身の機能宣言から導出されます。
controlzero coverage --jsonでお使いの環境向けの宣言をエクスポートでき、このドキュメントと食い違う場合はそちらが正となります。引数なしのcontrolzero coverageは、ホストごとの短い要約のみを表示します。 -
無料プラン: 月 5,000 件のガバナンス 対象アクションを無料で利用できます。クレジットカードは不要です。
重要な考え方: ポリシーはコードではなくダッシュボードにある
これが中核となる設計原則です。
- ポリシーは Control Zero ダッシュボード(または API)で定義します。ポリシーは、どのアクションを許可または拒否するかを記述します。
- コードは SDK クライアントを通じてツールを呼び出します。 特定のポリシーへの参照や、アプリケーションにハードコードされたアクション名はありません。
- 適用は SDK が自動的に行います。 すべての
guard()呼び出しは、ローカルにキャッシュされたポリシーバンドルに照らして評価されます。
ポリシーは、コードに触れることなく、いつでもダッシュボードで変更できます。長時間動作する SDK プロセスは、次回のリフレッシュ時に変更を取り込みます。Python SDK はデフォルトで 60 秒ごと、Node SDK は 300 秒ごとにポーリングします。手動でリフレッシュすれば、すぐに反映されます。