Agent
May submit typed proposals and read scoped, redacted evidence. No production write credentials or approval authority.
SECURITY
VISM is designed so that no AI output becomes a production credential, no approval silently expands beyond an exact plan, and no worker receipt is mistaken for proof of a healthy state.
TRUST BOUNDARIES
The product design separates the agent, inspector, policy engine, human approver, effect broker, verifier and audit service. Each receives the smallest authority required for its role.
May submit typed proposals and read scoped, redacted evidence. No production write credentials or approval authority.
May analyze a filtered read bundle. No credentials, arbitrary tools or policy-edit authority.
May attest to a sealed plan according to current role, environment and scope.
May send an exact typed provider payload after validating a one-use permit.
May independently read health/state. It cannot deploy or roll back.
May append and sign history. It cannot execute a production action.
HUMAN AUTHORITY
A valid approval binds a human identity, current role, tenant/environment, plan hash, scope and expiry. Changing a target, payload, threshold, artifact or recovery branch requires a new plan and authority.
RESTRICTED EXECUTION
The execution permit contains the plan hash, step ID, payload hash, resource UIDs, adapter digest, fencing epoch and expiry. A mismatch is denied rather than adjusted silently.
EXECUTION PERMIT
plan_hash · step_id · payload_hash
resource_UIDs · adapter_digest
fencing_epoch · nonce · expires_atOne dispatch. Exact typed payload. Live revalidation at the effect sink.
SECURITY CONTROLS
The security model calls for short-lived scoped credentials, complete mediation of integrated write paths, admission/conditional checks, pinned adapters and an independent audit witness.
Separate agent, human and workload identities; bind tenant and environment at every layer.
Approval attaches to a canonical plan hash and pinned artifacts, not a mutable prose preview.
Append-only signed events and external witness help detect rewriting, truncation or forks.
Freeze new permit issuance, revoke epochs, observe in-flight effects and reconcile before recovery.
FAILURE-SAFE BEHAVIOR
Policy or audit unavailability prevents new mutation. A provider timeout after a write enters reconcile; it does not cause a blind retry. Verification `UNKNOWN` blocks the next stage.
BOUNDARY OF THE GUARANTEE
VISM can only protect integrated, mediated write paths. An agent that still has a direct administrator key, shell path or bypass route is outside that guarantee until the path is closed.
SECURITY IS A PRODUCT CONTRACT