SAFETY & OWNERSHIP
Your agents can act. Their authority stays bounded.
Virgo keeps canon and personas owner-controlled, excludes credential values from snapshots, and turns critical rules into mechanisms that refuse loudly when evidence is missing.
CAPABILITY POLICY
Default-allow the recoverable. Confirm or deny the boundary.
One immutable capability stamp drives the visible tools, handler authorization, and launcher allowlist. Startup refuses any projection drift.
LIVE MUTATION
Audit the candidate. Attest the place.
A down, up, or cutover requires a single-operation CLEAR token bound to exact SHA/tree, action, persona, target host, auditor, time, expiry, and operation ID. The execution context is separately attested by hostname, uid, and exact tmux socket.
A chat approval, prose completion claim, or unrelated green test is not execution authority.
SINGLE ACTIVE COPY
Identity is logical. Authority is current.
Registration requires process attestation before lease acquisition. Missing or retired addresses fail before Redis. A consumer that loses its lease refuses work; redelivery keeps the same idempotency and side-effect keys.
PRIVATE BY CONSTRUCTION
Code is generic. Your system stays yours.
- One release SHA covers CLI, daemons, and web assets.
- Machine addresses, people, paths, and workspace names live in private canon/config.
- Snapshots contain tracked persona state, never credential values or ambient machine files.
- The Hub UI is authenticated and never exposes credential values.