Architecture · current trust boundaries
Architecture and trust boundaries
The product controls a narrow transition from candidate work to accepted project state; it does not turn an AI agent into a trusted authority.
Current verified flow.
Agent/task → bounded project scope → isolated candidate workspace → deterministic validator gate → exact diff → digest-bound local approval → controlled promotion → rollback restoration → hashed evidence.
Current pilot scope is supervised, bounded, non-production Linux using the verified PRODUCT MCP/local CLI surfaces. Clean external-machine E2E and named Claude Code/Codex integrations are not yet claimed as verified.
What the boundary means.
The agent may propose work. Passing declared checks and explicit human acceptance are separate decisions. A model's own confidence is not treated as proof that a change should become accepted project state.