AI can propose. RBEK decides what can execute.
An AI agent proposes three refunds:
EUR 12,500 ........ DENY executed: NO
EUR 2,000 ......... ALLOW executed: YES
EUR 50,000 ........ DENY executed: NO
The EUR 50,000 case includes a manipulative prompt attempting to override the policy. The prompt can propose an action; it does not grant execution authority.
curl -fsSL https://raw.githubusercontent.com/rbekplatform/rbek/main/examples/refund-governance/demo.sh | bashNo API key. No prior RBEK installation. No payment processor.
The demo installs and validates the public RBEK CLI when needed and applies a deterministic EUR 5,000 refund limit.
AI / agent proposal
|
v
deterministic refund policy
|
+----+----+
| |
DENY ALLOW
| |
executed RBEK governed
NO local execution
|
v
executed YES
+ evidence
What the terminal proves:
EUR 12,500 refund ............... DENIED
Denied refund executed .......... NO
EUR 2,000 refund ................ ALLOWED
Governed execution .............. YES
Execution evidence .............. VERIFIED
EUR 50,000 manipulative prompt .. DENIED
Prompt granted authority ........ NO
Denied refund executed .......... NO
Network action .................. NO
Database action ................. NO
External API action ............. NO
Payment processor ............... NO
RBEK_REFUND_GOVERNANCE_DEMO=PASS
The allowed case uses the bounded customer-transform / local.transform target.
Positive execution is accepted only when RBEK reports execution, receipt, certification and allowlist evidence.
The demo does not move money, contact Stripe, or contact a payment processor.
Read the refund governance example →
The repository also includes a governed-agent example with real model inference and a real Open-Meteo external action:
cd examples/real-governed-agent
export OPENAI_API_KEY="your-key"
./demo.sh --liveAI agents can decide what they want to do. Production systems still need a controlled boundary for what is actually allowed to execute.
RBEK puts that boundary between application logic and real external actions:
agent / workflow
↓
execution request
↓
RBEK policy admission
↙ ↘
DENY ALLOW
↓
execute
↓
evidence
This keeps execution governance separate from the agent framework, model provider or workflow engine.
curl -fsSL https://releases.rbekplatform.com/cli/stable/install.sh | bashVerify:
rbek-cli --versionCurrent public stable:
RBEK 0.2.1
Create and run a minimal local RBEK project:
rbek-cli init ./rbek-demo
rbek-cli run ./rbek-demoOr run the repository example:
bash examples/5-minute-quickstart/run.shThe goal of the first five minutes is simple: install RBEK, create a governed local project and execute it through the RBEK CLI.
See QUICKSTART.md for the complete first-run walkthrough.
After the zero-key proof, you can run the real agent path:
cd examples/real-governed-agent
export OPENAI_API_KEY="your-key"
./demo.sh --liveIn live mode:
OpenAI agent
↓
weather.current
↓
RBEK policy admission
↓
controlled external execution
↓
Open-Meteo
↓
receipt + certification
The agent does not call Open-Meteo directly. The external action goes through the RBEK governed execution boundary.
See examples/real-governed-agent/README.md for details.
Developer is the public CLI entry point for local development, evaluation and integration.
It does not require a paid commercial entitlement.
Team and Enterprise commercial access are handled separately.
This repository contains Developer documentation, examples and installation guidance.
The RBEK runtime is distributed through the official release host:
https://releases.rbekplatform.com
The complete runtime source is not published in this repository.
https://rbekplatform.com
See SECURITY.md.
An AI agent may propose a refund. RBEK determines whether the proposal may cross the execution boundary.
The runnable example covers three cases:
- EUR 12,500 ->
DENY-> no controlled execution. - EUR 2,000 ->
ALLOW-> eligible for RBEK governed local execution. - Manipulative EUR 50,000 prompt ->
DENY-> no controlled execution.
Policy-only:
python3 examples/refund-governance/run.pyExplicit governed local execution for the allowed case:
python3 examples/refund-governance/run.py --executeThe example uses a bounded local customer-transform / local.transform
execution target. It does not contact Stripe, move money, or claim real
financial settlement.
AI can propose. RBEK decides what can execute.