Users guide
The Door is admission control. A visitor knocks with a structured ticket. You either mint a short-lived grant bound to a future sandbox — or you refuse. This page is how to operate the console.
What this is
The Door sits in front of an untrusted visiting agent. It authenticates a principal, validates a ticket, compiles a capability set, and mints a signed session grant — or it denies, fail-closed.
It does not run the job. It does not open a sandbox. It does not write production. Spoken intent is a label only; authorization uses the ticket plus the compiler.
- No ambient authority — success is a token, not access.
- No free shell, SSH, or admin mode.
- Policy evaluation works offline. No model is consulted.
First knock
- Open the console.
- Choose Trusted check in the left rail (or the chip row on a phone).
- The form fills with a signed Acme ticket against
billing-apiinlogs_only. - Press Knock. The right column should read Allow.
- Inspect the compiled tools, copy the token, then Verify or Revoke.
To see a refusal, run Repair production or Prose only. Unbounded jobs, secrets, and unsigned knocks (while anonymous is off) are also denied.
The ticket
Only canonical JSON is accepted. Extra fields are rejected unless they sit in an ignored extensions map. The stated goal is never a permission.
Required shape
action— check, diagnose, repair, configure, or installtarget.kind— service, path, repo, account, or devicetarget.id— a specific id, max 128 characters. Empty,*, or “everything” is unbounded.target.environment—logs_only,shadow, orreplica. Write-capable jobs may not target production.stated_goal— human label, max 280. “Fix it,” “whatever,” and “repair everything on the network” are denied.constraints— minutes 1–30, network none or allowlist, writes, tool-call cap.may_touch_secretsandmay_contact_humansmust be false in v1.principal— org, agent, key, nonce, and RFC3339issued_at(clock skew max two minutes).
v1 tool catalog
Tools are compiled from the action. Visitors cannot invent tools. run_shell, curl, write_host_file, install_package, and send_email are not in v1 — jobs that need them are denied.
check/diagnose— read_logs, stat_path, read_file, run_healthcheck, list_dir (writes forced off, network none unless policy allows an allowlist)repair— stat_path, run_healthcheck, propose_diff (replica or shadow only)configure— propose_diff, if policy allowsinstall— not compilable in v1
Expand Ticket JSON on the form to see the exact payload that will be signed.
Identity
Display names are not identity. “The agent said it was vendor support” is not a principal.
Signed principal (preferred)
The visitor signs canonical ticket bytes with Ed25519. The Door looks up org_id → key_id in the local trust store. Unknown keys are PRINCIPAL_UNKNOWN. A rogue signature is SIGNATURE_INVALID.
Demo tenant: org acme, key acme-ops-1. The console can also sign with a rogue key to demonstrate refusal.
Anonymous knock
Off by default. Enable it on the Policy tab. Unsigned knocks then may only check, with no writes, no network, at most 10 minutes, in a logs_only sandbox. The ticket must still be valid JSON.
Nonces
Each nonce is bound to the principal. Reuse within twice the TTL is NONCE_REPLAY. The Replay nonce scenario knocks twice with the same nonce to show this.
Reading a decision
Every knock returns allow or deny, reason codes, a short human reason, and — on allow — a grant plus a handoff stub.
- Allow — tools, sandbox class, TTL, writes, network, and the compact token.
- Deny — one or more reason codes. No grant. No tools.
Forbidden capabilities are always listed on a grant: shell, ssh, env_dump, secret_read, outbound_unlisted, production_mutate, human_contact. The Door never places host secrets in the token or in a visitor-facing response.
Grants
A session grant is a signed capability, not a login. It is short-lived, single-sandbox, and bound to the principal, policy hash, expiry, and nonce.
- Copy token — compact Ed25519 token. Verify with The Door’s public key only.
- Verify — signature, expiry, and revoke status.
- As expired — asks verification to treat the clock as past TTL.
- Revoke — immediate burn. The grant is unusable even if the token has not expired.
Open the Grants tab to inspect every mint from this session. Status is active, expired, or revoked.
Ledger & policy
The ledger is append-only. Each line records time, principal, decision, reason codes, policy hash, and a ticket hash — not the full ticket, not signatures, not private keys.
Policy maps (action, target.kind, org_id) to allow or deny, max TTL, network mode, and a tool allowlist. Unknown orgs are denied. Default effect is deny. Evaluation does not need a network and does not consult a model.
Demo policy lists org acme for check/diagnose on services, check on paths, and repair on services inside replica.
Reason codes
| Code | Meaning |
|---|---|
| SCHEMA_INVALID | Ticket is not valid structured JSON. |
| PRINCIPAL_UNKNOWN | Principal is not in the trust store. |
| SIGNATURE_INVALID | Signature does not match the ticket. |
| NONCE_REPLAY | This nonce was already used. |
| TICKET_UNBOUNDED | Job is unbounded or underspecified. |
| ACTION_NOT_COMPILABLE | Action cannot be compiled to v1 tools. |
| PRODUCTION_TARGET_FORBIDDEN | Write-capable jobs cannot target production. |
| SECRETS_REQUESTED | Touching secrets is forbidden. |
| HUMAN_CONTACT_REQUESTED | Contacting humans is forbidden. |
| NETWORK_NOT_ALLOWED | Requested network access is not permitted. |
| TTL_TOO_LONG | Requested TTL exceeds policy. |
| TOOL_NOT_IN_CATALOG | Requested tools are not in the v1 catalog. |
| POLICY_DENY | Policy denies this principal, action, or target. |
| EXPIRED | Grant has expired. |
Sandbox handoff
On allow, The Door returns { next: "sandbox_manager", sandbox_class }. A Sandbox Manager should:
- Verify the token with The Door’s public key only.
- Bind
sandbox_id(minted here, not yet attached to a runtime). - Enforce tools, visible paths and services, network, writes, TTL, and max tool calls.
- Refuse anything in forbidden.
- Treat revoke and expiry as immediate denial.
The Door never executes those tools.
What it does not do
- No sandbox runtime or tool proxy
- No production writes or host filesystem access
- No free shell, SSH, or admin mode
- No host secrets in tokens or visitor responses
- No offensive scanning or autonomous pentest features
Read the sales pamphlet for the short form, then return to the console and knock.