Ticket

Knock

Natural language is never enough. Authorization uses this ticket plus the compiled capability set.

Ticket JSON
{
  "ticket_version": "1",
  "action": "check",
  "target": {
    "kind": "service",
    "id": "billing-api",
    "environment": "logs_only"
  },
  "stated_goal": "Confirm billing-api is healthy from logs.",
  "success_criteria": [
    {
      "type": "service_healthy",
      "spec": "billing-api:ready"
    }
  ],
  "constraints": {
    "max_minutes": 10,
    "network": "none",
    "allowlist_hosts": [],
    "writes": false,
    "may_contact_humans": false,
    "may_touch_secrets": false,
    "max_tool_calls": 40
  },
  "principal": {
    "org_id": "acme",
    "agent_id": "ops-bot-1",
    "key_id": "acme-ops-1",
    "nonce": "n-pending-nonce",
    "issued_at": "1970-01-01T00:00:00.000Z"
  }
}

No knocks yet. The ledger is append-only.