DOCUMENTATION

Security & audit

Identity separation, write-path mediation, immutable evidence and release gates.

Docs menu

The security model protects production integrity, availability, data, approval authority, secrets, recovery keys, audit integrity and tenant isolation. It assumes residual risk remains when multiple upstream trust roots are compromised together.

Identity and privilege separation

Agents propose; inspectors analyze read bundles; humans approve sealed plans; policy admins review policy; coordinators request permits; the effect broker writes exact typed payloads; verifiers read independently; audit services append records. No role is meant to both change a policy boundary and execute a broad production effect.

Credentials and complete mediation

The design favors workload identity and temporary scoped credentials. Secrets are referenced by identifier/version and resolved only at runtime, never printed in a plan, audit record, trace or error. REST, CLI and MCP interfaces share the same proposal/decision path; MCP does not expose a generic production command. In Kubernetes, an admission guard verifies target, field, payload and permit, not only a service-account name.

Immutable audit chain

Events are append-only and include proposal, inspection, plan seal, decision, approval, intent, permit, provider receipt, verification, recovery and state-commit records. Hash chaining inside one database is insufficient on its own; the design calls for signed events, WORM-versioned storage and an independent witness for the chain head.

Audit propertyDesign response
Rewrite or deleteAppend corrective annotations; do not alter the original event.
Fork or truncationCompare signed sequence/head with an external witness.
Archive unavailableStop new mutation; preserve pending status and reconcile later.
Sensitive materialKeep minimal/redacted evidence; never record secrets or raw database rows.

Threat control examples

  • Compromised agent: no write credential, typed schema and quotas.
  • Prompt injection: untrusted observed content, no model tools/write and deterministic gates.
  • Stale worker: fencing epoch, narrow broker and admission checks.
  • Cross-tenant replay: tenant/environment binding in payload, approval and permit.
  • Supply-chain change: signed/pinned adapters and artifact digest checks.

Release gates

The design blocks production write when the agent retains a bypass, admission cannot prevent payload substitution, tenant isolation fails, audit witness is not verified, or a worker can both change policy and execute. It does not claim SOC 2, ISO, HIPAA or any other certification.