Browse the source code, open issues, submit pull requests, and star the project.
admina-org/admina βAsk questions, share your setup, propose features, and talk to the maintainer and community.
Join discussions βFound a bug? Have a feature request? Open an issue β we respond as soon as possible.
Open an issue βHow to set up your dev environment, coding conventions, testing, and submitting PRs.
Read CONTRIBUTING.md βHow to contribute
All contributions are welcome, from bug fixes to new governance domains and plugins. Here are the most impactful ways to help.
Report bugs and edge cases
Run Admina in your environment and share what you find. Real-world edge cases improve governance quality for everyone.
Contribute injection patterns
The Agent Security firewall uses a library of regex patterns with stable ids. Add new patterns for attack vectors you've encountered β each one protects all Admina users β or, since v0.13.0, ship a domain- or language-specific set as a pattern pack.
Write connectors
LangChain, CrewAI, n8n, OpenClaw, and Cheshire Cat connectors ship with every release, alongside seven model-provider adapters and β since v0.11.0 β an OpenAI-compatible governance gateway. New framework integrations are always welcome β see the plugin system's 9 interfaces.
Improve documentation
Clear docs are as important as good code. Fix typos, improve examples, translate content, or write a tutorial.
Share benchmarks
Run the benchmark suite on your hardware and share the results. Performance data from diverse environments strengthens the project.
Star and spread the word
A GitHub star signals to the community that this project matters. Share Admina with your team, write a blog post, or talk about it at a meetup.
Since 0.12.1 the maintainers develop Admina with AI assistance (Claude); commits written
with it carry a Co-Authored-By trailer, and every change is reviewed and tested
by the maintainers before it is merged. Contributions written with an AI assistant are
welcome under the same rules β see "AI-Assisted Contributions" in
CONTRIBUTING.md.
Why "Admina"?
Admina comes from admin β administrative oversight, system governance β shaped into a name with a firm, precise sound, like a trusted system daemon always running quietly in the background.
It also echoes admina as in sysadmin β the person who manages, enforces rules, and keeps systems in order. Exactly what Admina does for AI agents.
Stress on the first syllable: Γ-dmi-na. Think of it like Γ dmin + a, not ad-mΓ-na. Three clean syllables, firm and direct β like the governance it provides.
Wondering how Admina compares to Cordum, Guardrails AI, NeMo, Lakera, and other AI-governance frameworks? See the full comparison β
Changelog
Past releases β what shipped, when, and why. The full release history with per-version details is maintained in the source repository, alongside the code it documents.
Roadmap
Where Admina is going next. Pre-1.0: the public API is feature-complete and production-ready, but the stability commitment is deferred until community validation has confirmed the shape of the public surface. Releases ship when scope is ready β not on a calendar. Full forward plan in ROADMAP.md.
- Egress control on tool calls. A new pipeline stage extracts destinations from tool-call arguments β independently of the HTTP method β and checks them against an operator allowlist (
domains.agent_security.egress.allow: exact hosts,*.suffixwildcards, CIDR ranges). Opt-in:ADMINA_EGRESS_MODEdefaults toobserve, which records and refuses nothing;enforceis default-deny. It runs on five surfaces but only/mcppasses tool-call arguments, so it is an MCP control in practice, andGovernedAgent.call()has none admina egress suggest-allowlistbuilds a candidate allowlist from destinations recorded duringobserve, read back from local forensic records; promoting an entry stays a human decision- Cross-agent coordination detector. A fan-in trigger counts distinct agents writing to one undeclared destination and reports
suspected; withADMINA_EGRESS_FINGERPRINT_KEYset, a keyed content-echo match between agents escalates toconfirmedand quarantines the destination for writes fleet-wide β refused underenforce, recorded underobserve. Everyconfirmed,suspectedordegradedverdict leaves a forensic record, a bus event and anadmina_coordination_verdicts_totalsample;admina egress quarantine list/liftmanage the set. Fed by the MCP proxy only - Wider adapter SDK ceilings β
openai<4andanthropic<2β and the[rust]extra acceptsadmina-core0.12.x, with the engine-bridge ABI unchanged - Fixed:
/metricsrepeated# HELP/# TYPEfor every sample, so a proxy with firewall detections in two or more categories served an exposition Prometheus rejects; metadata is now emitted once per family
- Gateway for embedded deployments. Named upstream routes with API keys (
X-Admina-Upstream), streams passed through unchanged when PII redaction is off, upstream errors and timeouts propagated with their status, request limits, the whole chat completion body in the scan, the governance outcome on every response (X-Admina-Action,X-Admina-Event-Id,X-Admina-Ruleset, β¦), request ids and W3C trace context, and a request plus a completion forensic record per call - Deployment. Secrets from files (
*_FILE),ADMINA_CONFIG,ADMINA_ENABLED_SURFACES, theproxy-minimalextra, an offline mode, a schema check ofadmina.yaml, and signed release images with a-slimvariant - Forensic store. Atomic writes, an HMAC signature on each record, a chain state rebuilt only from verified records, verification from a checkpoint, JSON Lines export (
admina forensic export/verify) and an optional fail-closed mode - Firewall & PII. Linear-time pattern matching, stable pattern ids, pattern packs, an Italian baseline, PII engines from other packages, value-only redaction and an
[OMISSIS]mask style; firewall and PII redaction now reach 32 levels of nesting, with a block past it on/mcpand the gateway - Observability, compliance, testing. Per-surface request metrics, event-loop lag, governance events without request text; EU AI Act classification of Italian, French and German descriptions; an OISG score from external evidence;
admina redteamon external corpora - Upgrade with care: several defaults and failure modes change β read the upgrade guide first. Patch releases 0.12.1 (hardened dashboard sessions) and 0.12.2 (gateway in the counters and on the event bus, dashboard without ClickHouse) shipped the same day
- NIS2 template (incident response, supply-chain obligations)
- ISO/IEC 42001 (AI management system controls)
- SOC 2 (Trust Services Criteria mapping)
- Cross-framework gap analysis (single control β multiple frameworks)
- Report export in PDF and DOCX, signed with the forensic key
- Observability: streaming-request metadata on the OpenTelemetry GenAI semantic conventions (
gen_ai.request.model,gen_ai.usage.*,gen_ai.response.finish_reasons,gen_ai.client.operation.duration); an SLO panel on the Prometheus metrics; a structured error taxonomy; a benchmark regression gate in CI; tracing correlation from the SDK through the proxy to the upstream LLM (the gateway already records W3C trace context) - Multi-tenancy & RBAC: organisation / workspace isolation, per-tenant quotas, RBAC on proxy endpoints (read / write / admin), an OIDC auth provider as a built-in plugin, a shared async pool for data connectors and a decision cache on the firewall fast path, per-tenant forensic namespaces with independent hash chains
- Plugin ABI v1 frozen with contract tests; third-party plugin certification suite
- Official client SDKs: TypeScript, Go
- Deprecation policy formalised; 18-month LTS window for the 1.0 line
- Security advisory process documented; CVE assignment workflow
- Removal of the compatibility shims in
admina/proxy/that keep pre-0.10 imports working