Architecture

Headless by design

The platform holds no UI opinions. Surfaces — the agent, the console, your own tools — attach to the same contract. Simulated metrics

Receipts sealed

Proof is a first-class resource

Sample receipts binding grant, execution, evidence, and outcome.

284k +18.6%

Verification at the edge

Targets verify where the action happens

Authority is checked at the point of execution — beside the repo, the payment rail, the deploy target — not in a dashboard after the fact.

GitHub Payments Kubernetes CRM Queues Webhooks

Target adapters

Your systems become refusal-capable

Adapters teach existing tools to check grants and honor refusals — the platform supplies the contract, not another dashboard.

0

pixels of required UI — every capability is an endpoint first

Grants Targets Receipts Autonomy

Autonomy from evidence

Scope is a computed value

An agent's authority envelope is derived from its receipt history — reviewable, reversible, never vibes.

Principles

What the contract guarantees

Four rules the platform holds so surfaces don't have to.

Authority

No grant, no action

Grants are purpose-bound, limited, single-use, and expiring. Standing permission is not a concept the API can express.

Enforcement

Targets refuse, not dashboards

Verification happens at the point of action. A missing, expired, or replayed grant ends in refusal — recorded as evidence.

Evidence

Receipts outlive the run

Every execution seals a receipt binding authority to outcome, verified against the world the action changed.

Learning

Autonomy is earned

Scope widens from verified work and narrows after uncertainty. The envelope is recomputed from receipts, never assumed.