Trust & policy plane
Identity, trust roots, signed policy distribution, and attestation remain above the session so the agent cannot rewrite its own governance.
Primary product
Signed governance loads at start or resume. Local hooks enforce the installed policy outside the model. Signed observations and service receipts make the result inspectable.
Alpha access is free and no payment method is collected. Pricing will be introduced before general availability, with advance notice and an explicit choice.
Two ways to run an agent
Both keep an agent inside limits. They differ in where the check happens and how many chances there are to slip past it. The first is often called supervision, the second governance. mistwire's alpha installs hooks, which is the first; setting up the session first is next.
The cycle in five moves
Every arrow from the service carries something signed by a key your machine pinned. Every arrow from your machine carries something signed by a key the service enrolled. Neither side acts on an unsigned claim from the other. Click a numbered step or play the sequence.
Trust and signed policy originate outside the agent-controlled session. Verification and request enforcement happen locally. Installed-state attestation remains a separate evidence lane.
What happens to a request
Choose a behavior covered by the current signed alpha bundle. Follow its local outcome, then inspect the separate evidence path for installed governance state.
Choose a current alpha behavior. The path lights up from local request to a bounded, legible outcome.
Bounded safe-read rule matches. Host proceeds within the signed boundary.
Tool request
The host exposes the requested operation and path to the installed local permit hook before deciding whether to proceed.
Plainly: the action is named before any auto-approval.
Attestation verifies installed governance state. It does not claim to be a per-action log or proof of what this individual request did.
What the receipt catches
Set the state of each governed file and read the verdict. The service compares the report against the policy it signed, and signs the answer with a key your machine does not hold.
what arrived from your machinepolicy/governance.tomlhooks/mw-permit.shskills/commit-ritual/SKILL.mddocs/ENFORCEMENT.mdan unlisted file in the governance foldera second, independent witnessEvery governed file matches the signed policy.
Mirrors the service's adjudicator: policy, hooks and skills are graded; docs are not. Unknown means the report named a policy the service does not know, so it cannot judge. No report yet and Reports disagree are planned verdicts, drawn here so the layout has room for them. A signed receipt binds an enrolled key, observation, bundle, time, and service verdict. It attests installed governance state; it is not a per-action activity log or proof that a customer-controlled machine reported truthfully.
Identity, trust roots, signed policy distribution, and attestation remain above the session so the agent cannot rewrite its own governance.
Installed hooks evaluate covered requests before execution. A safe read may proceed, a signed hazard is denied, and uncertain requests remain with the host and human.
The policy is distributed from outside the session and enforced locally in the request path. Attestation remains separate from individual action outcomes.