- What does Stoplight actually do?
- Stoplight observes your agent’s tool calls, commands, and file operations via hooks, then suggests specific guardrails you can verify and activate. It’s designed to make “skipping permissions” safer without using crude patterns that constantly require approval.
- Do suggested rules become active automatically?
- No. Suggestions always remain drafts until a user reviews, edits, and activates them progressively. This allows you to review and activate rules and guides as you believe they are necessary, rather than being interrupted constantly.
- How does the free tier work?
- You can create one profile (relevant to a single agent workflow or repo). The free tier supports up to 100 active guardrails so you can fully protect that workflow while still seeing suggestions appear. We intend for Stoplight to soon be available as a self-hosted solution, so you can bring your own LLMs and use your own cloud infrastructure.
- Which agents are supported?
- Claude and OpenCode today. Stoplight is hook-first, and we've designed our application schema to be robust to changing hook shapes as agent runtimes evolve. We will support more agents and integrations as better interfaces become available.
- Can we use this for AI agent SOC 2 compliance?
- While there are no specific SOC 2 requirements released as of yet around AI agent usage, Stoplight is designed in anticipation of emerging requirements around AI guardrail auditability, equipping your security team with legible audit trails and metrics.