Governance

Who can do what, and what proves it

Governance is identity, policy, evidence and audit — who may act, what they may do alone, and what proves it.

Identity

Every administrator and workspace sits behind your own identity provider from first boot — there is no shipped default password to rotate.

Sign in with your own identity provider (OIDC with PKCE); no shipped default administrator password.

Policy, approval and evaluation

A policy decides what an agent may do on its own; an approval is a human decision it waits for; an evaluation is the review a skill passes before it is trusted.

Changes wait for human approval before they run.

Evidence

Every answer shows the evidence behind it, per host: the commands that ran, their exit codes and their output.

Every answer shows the exact commands that ran, their exit codes and output, per host.

Audit

Administrative changes to the fleet are written to an audit log in the control plane.

Administrative actions — such as raising a host's execution policy or moving a host between workspaces — are recorded to an audit log with the actor, the action, the subject and the values before and after the change.

Who can do what, and what proves it

Request a demo