SECURITY BOUNDARY

Assume output is untrusted. Keep authority explicit.

Harnesses and Boxes are asymmetrically isolated with scoped secrets, egress controls, approvals, and attributable sessions.

TRUSTED INTELLIGENCE

Private harness

Selected model + private context

Local credentials, private prompts, and decision policy never enter the Box runtime.

No inbound accessProof-signed requests
signed requestPOLICY
GATE
scoped capability
UNTRUSTED EXECUTION

Isolated Box

Sandboxed tools + sessions

Explicit egress allowlists, scoped secrets, quarantine, one controller lease, and metering.

Output untrustedAudited
Egress allowlistdeny by default
Secret brokerdeny by default
Approval checkpointsdeny by default
Artifact quarantinedeny by default
Principal attributiondeny by default
Hard budget capsdeny by default