Governed agents4local alpha fleet
Signed permits122 active right now
Policy stateCleanfail-closed default
CAPABILITY AGREEMENTsigned
Agent
Diogenes agent-042
Operator
SuperEgo local-alpha tenant
Subject lock
baron.dev · GPT-5.5
Surfaces
graph.write, graph.read, file.read
Denied
shell.exec, net.outbound, fs.write
Expiry
Session-scoped · revoked on disconnect
7c3f91a…b204e8
Live feed
| Agent | Model | Type | Status | Tier | Agreement | Permits | Uptime |
|---|
Bindings
Capabilities
Permit registry
| Permit | Action | Agent | Scope | Status | Hash |
|---|
CAPABILITY AGREEMENTsigned
Agent
Diogenes agent-042
Operator
SuperEgo local-alpha tenant
Subject lock
baron.dev · GPT-5.5
Surfaces
graph.write, graph.read, file.read
Denied
shell.exec, net.outbound
Expiry
Session-scoped · revoked on disconnect
7c3f91a…b204e8
CAPABILITY AGREEMENTsandbox
Agent
Iris agent-003
Surfaces
file.read
Denied
graph.write, shell.exec, net.outbound, fs.write
d9e4a72…c103f6
Enforcement rules
Fail-closed default
Unlisted actions denied.
ENABLED
Single-use permits
Consumed on first redemption.
ENABLED
Session-scoped expiry
Permits expire on disconnect.
ENABLED
Cross-agent transfer
Cannot forward permits.
DISABLED
Raw tool access
Direct invocation blocked.
BLOCKED
Policy simulator
Run a simulation to check policy coverage.
Governing principles
§1 — Separation. Capability and authority are cryptographically separated.
§2 — Evidence. Every decision produces a hash-committed receipt.
§3 — Boundary. No side effect occurs outside a governed execution boundary.
§4 — Revocation. Authority is always revocable.
Root actions
How a permit moves from proposal to proof
Governed handles
Scenario simulator
AuthorizedGoverned writePermit → execute → prove.
ReviewNetwork requestDeferred; no permit.
ForbiddenRaw shellDenied before execution.
Select a scenario to simulate.
Permit evaluator
Waiting for request.
Decision log
No evaluations yet.
Pending3
Approved8
Denied2
Pending items
Accepted5
Denied2
WorkerPenelope
Commission receipts
| ID | Event | Type | Agent | Status | Time |
|---|
Hash-committed receipts
| Receipt | Hash | Parent | Verified |
|---|
SE HostConnected
CompassConnected
EvidenceClean
Uptime127h 24m
Local alpha proof preview. The governance runtime is real but not a production deployment.
Capability and authority can be cryptographically separated.
Patent pending · 64/073,586
SE Host
v0.1.0-alpha
Compass
v0.1.0-alpha
Console
v2.1-demo
Evidence
SHA-256