VIRGO

SAFETY & OWNERSHIP

Your agents can act. Their authority stays bounded.

Virgo keeps canon and personas owner-controlled, excludes credential values from snapshots, and turns critical rules into mechanisms that refuse loudly when evidence is missing.

CAPABILITY POLICY

Default-allow the recoverable. Confirm or deny the boundary.

Allowordinary recoverable workOnly inside stamped workspace, project, persona, and class scope.
Confirmconsequential boundaryCredentials/permissions, irreversible work, publication or deployment beyond delegation.
Denyauthority escapeSecret values, fence/lease material, and unbound cross-scope access.

One immutable capability stamp drives the visible tools, handler authorization, and launcher allowlist. Startup refuses any projection drift.

LIVE MUTATION

Audit the candidate. Attest the place.

A down, up, or cutover requires a single-operation CLEAR token bound to exact SHA/tree, action, persona, target host, auditor, time, expiry, and operation ID. The execution context is separately attested by hostname, uid, and exact tmux socket.

A chat approval, prose completion claim, or unrelated green test is not execution authority.

SINGLE ACTIVE COPY

Identity is logical. Authority is current.

Registered pathcanon-backed admission
Logical consumer group
Instance + fence
Handler succeeds, then ack

Registration requires process attestation before lease acquisition. Missing or retired addresses fail before Redis. A consumer that loses its lease refuses work; redelivery keeps the same idempotency and side-effect keys.

PRIVATE BY CONSTRUCTION

Code is generic. Your system stays yours.

  • One release SHA covers CLI, daemons, and web assets.
  • Machine addresses, people, paths, and workspace names live in private canon/config.
  • Snapshots contain tracked persona state, never credential values or ambient machine files.
  • The Hub UI is authenticated and never exposes credential values.
Read the privacy policy →