A control layer built for autonomous agents
Know your agents
- Universal Agent Discovery — process, parent/child lineage, install path, hash, publisher, package; no manual registration per agent
- Agent Passport — every agent carries an identity, not an IP address or a binary name
- Known / Observed / Trusted states — new agents get workable default policies instead of instant bans or instant trust
Decide every action in context
- Capability Model with non-transitivity and time-boxed Capability Leases — revocable, task-scoped grants
- Behavior Chain Analyzer + Process Lineage — sequences are judged, not isolated calls
- Sensitive resource classification and a Security Map that never becomes a treasure map for attackers
- Risk tiers Low → Critical, and a User Hard Deny layer no policy or AI can override
Learn — with brakes
- Adaptive Learning with confidence scores, positive+negative evidence, learning quarantine and trust decay
- Shadow policies and policy replay to test rule changes before they touch live traffic
- False-positive and false-negative feedback loops that never let raw feedback edit security rules directly
Survive mistakes and attacks
- Recovery core: pre-action snapshots, undo, and automatic recovery
- Emergency Lock and Away Mode for one-touch and absence protection
- Anti-tamper: the guarded layer cannot turn off its own guardrails
Stay fast and local
- Fast Path / Slow Path split so ordinary reads never pay for heavyweight analysis
- Local Core First: API expiry, cloud outages, or network drops never stop core protection
- Every security decision can be explained in plain language
Feature availability depends on platform and phase — see Supported Agents and Supported OS for the honest matrix.