Microsoft open-sources RAMPART and Clarity for agent safety

Microsoft has open-sourced two tools for AI agent development: RAMPART, a testing framework for continuous safety checks, and Clarity, a structured app for reviewing design assumptions before coding starts. The company says both tools are meant to make AI safety part of the normal engineering workflow.

Microsoft open-sources RAMPART and Clarity for agent safety

Microsoft has open-sourced two tools aimed at making AI agent development safer: RAMPART, a testing framework for continuous safety checks, and Clarity, a structured tool for reviewing design assumptions before code begins. The company said both are meant to help teams treat AI safety as part of ordinary engineering work rather than a separate review step at the end.

The release reflects a shift in what enterprise AI systems do. Microsoft said the systems shipping inside companies today are no longer limited to answering questions. They can access email, pull records from a CRM, write and run code, and take actions across connected systems on a user’s behalf.

⚡ New to this?

This news matters because AI agents are no longer just chatbots; they can take actions like sending email, pulling data, and running code. That creates new security risks, so teams need ways to test what agents do and to document why a system was built a certain way.

RAMPART is a testing framework for agent behavior, and CI, or continuous integration, is the automated process that runs tests whenever code changes. Clarity is a structured way to capture design decisions and check assumptions before a team builds the wrong thing.

🦞 OpenClaw angle

If you are building self-hosted agents, turn your red-team findings into regression tests instead of leaving them in a report. Add those tests to CI so a prompt-injection fix or tool-access guardrail cannot be removed by a later change.

Before giving an agent access to a new tool, write down the failure cases and the exact side effects you will treat as unsafe. Keep that review in a repo-owned markdown artifact, and make it part of pull requests so design assumptions are visible when the agent changes.

That change, according to Microsoft, alters the safety problem. An agent that can act in the world can also act in ways nobody intended, which means failures can involve real side effects rather than just bad text.

RAMPART is designed to bring red teaming into the development workflow. Microsoft said it is built on top of PyRIT, the company’s open automation framework for red teaming generative AI systems, but aimed at engineers while the system is still being built.

The framework uses pytest-style tests that describe scenarios from a team’s threat model. Each test connects to the agent through a thin adapter, runs an interaction, and checks observable outcomes, including which tools the agent invoked and whether side effects stayed within expected boundaries.

Those tests can be run in CI, or continuous integration, so they can block changes the same way ordinary integration tests do. Microsoft said teams can add a safety test in the same pull request as a new tool or data source.

RAMPART’s current focus is cross-prompt injection attacks, where poisoned content in documents, emails, tickets, or other sources influences an agent indirectly. The company said new threat categories can be added over time, and that the framework uses Python protocols to keep integrations lightweight.

Because AI behavior is probabilistic, RAMPART also supports statistical trials. Microsoft said a test can run multiple times with policies such as requiring a safe action in at least 80 percent of runs, which is meant to better reflect production behavior than a single pass or fail result.

The company said RAMPART is also meant to preserve the results of red team engagements. Findings from an AI red team exercise can be turned into runnable tests, so the same issue is checked on every change instead of living only in a report.

Clarity is aimed at an earlier stage of the process. Microsoft described it as a structured sounding board that helps teams ask whether they are building the right thing before they start implementation. It is meant for questions that experienced architects, product managers, and safety engineers would normally ask but that teams may skip when moving quickly.

Microsoft gave the example of a team adding real-time collaboration to a document editor. Clarity would push the team to ask whether it really needs live cursors and presence indicators, or whether the real requirement is simply that no one loses their work.

Clarity runs as a desktop app, a web UI, or inside a coding agent. Microsoft said it guides teams through structured conversations covering problem clarification, solution exploration, failure analysis, and decision tracking.

The output is written into a .clarity-protocol/ directory as plain markdown files. Those files can be committed to the repository, reviewed in pull requests, and diffed like code.

Microsoft said the failure analysis process uses multiple AI “thinkers” to examine the system from different angles, including security, human factors, adversarial scenarios, and operational concerns. The tool also tracks staleness, so if the problem statement changes, it can flag related documentation that may need to be revisited.

The company said important decisions are recorded with the criteria, options considered, and rationale behind each choice. That gives teams a record they can revisit months later, along with a review packet for stakeholders who want a summary.

Microsoft framed RAMPART and Clarity as part of a broader push toward spec-driven, engineering-native AI safety. The company said Clarity helps capture design intent, while RAMPART provides concrete tests that keep running as agents change.

Both tools are available now as open source projects from Microsoft. The company said it welcomes community feedback and enterprise deployment partnerships at [email protected].

Source: Microsoft Security Blog ↗

More from Security News