Operator console
From evidence to accountable action.
A proposal is evaluated, authorized, executed, verified, and recorded without giving the agent approval authority.
- Evidence
- Proposed action
- Policy verdict
- Approval
- Receipt
- Rollback
Current proposal
Deterministic policy verdict
- Rule
- Adapter
- Environment
Prepared review
Execution receipt
- Effect
- Verification
- Rollback
Engineering proof
Tool access is not authority.
What this proves: deterministic policy can veto or gate typed synthetic actions and leave inspectable evidence.
What it does not: provide production authorization, tamper-proof audit logs, machine isolation, or truth guarantees.
Operational proof: a private scheduled shadow path passed 10/10 supervised cases. One green follow-on now reads a hash-bound local evidence file through a confined read-only adapter and writes one immutable receipt. The live receipt verified with no approval, matching source and before/after hashes, and an idempotent replay changed no files. Yellow execution remains disabled.
Portable green proof: download the frozen v2 proof packet generated by the actual review and synthetic executor path. Its strict schemas and recomputed digests show internal integrity and deterministic policy binding—not authenticity, production authorization, or an external action.
Human boundary proof: a separate synthetic run required a literal interactive approval after presenting the exact effect and rollback contract. The single-use grant produced one verified sandbox receipt; replay returned the same receipt without a second effect. No external system was connected.
Evidence before authority: inspect the upstream reasoning in the Context Layer Lab.