Select a principal
Identify the agent, extension, or delegated tool making the request.
Explore the permission model for files, commands, network destinations, secrets, tools, and delegation before the native runtime is built.
Identify the agent, extension, or delegated tool making the request.
Bind capability, action, resource, workspace, and expiration.
Record allow, deny, or prompt with a stable reason and policy version.
The runtime target makes agent changes reviewable before applying them.
Network access is designed around explicit destinations rather than ambient egress.
Agents and tools keep distinct principals so authority cannot silently expand.
Use the working product surface now; no future runtime capability is presented as already shipped.