Q on our PH launch: how do you draw the line between actions that run automatically and ones that need a human?
A: policies. Teams set Allow/Deny/Hold per action based on tool, environment, data sensitivity, repo anything. Automate the low-risk stuff, guard what actually matters.
A commenter on our PH launch nailed it:
"Most teams stuff guardrails into the system prompt. Enforcing before the action executes is the only version that holds up in production."
That's the whole thesis behind Kastra.
Most "AI safety" today = a system prompt asking a model to behave.
That stops working the second the input is adversarial.
Kastra enforces policy at runtime before the action executes, not after. That's the whole bet, and PH builders stress-tested it hard this week, see it for yourself.
Kastra launched on Product Hunt and finished #3 Product of the Day.
Best part wasn't the rank, it was builders in the comments trying to poke holes in our architecture. It held.