Printed matter

A one-sheet for operators who must admit visiting agents without handing them the building.

Product sheet · v1

The Door

Admission control for untrusted visiting agents.

A visitor knocks, states a job, and either receives a short-lived grant — or is refused.

Natural-language intent is never enough. A shell is never issued. The Door authenticates a principal, compiles a capability set from a structured ticket, and mints a signed session token bound to a future sandbox. Policy is deterministic. No model is required to admit or refuse.

01

The problem

Untrusted agents will ask to “just check production,” “fix everything,” or speak as vendor support. Spoken intent is not identity. Prose is not a permission. A helpful sentence is still unbounded.

02

The door

Knock with identity plus a ticket. Authenticate. Validate. Compile. Mint a SessionGrant — or deny. Every decision is append-only audited. Unknown principals and malformed jobs fail closed.

03

The grant

Success is a capability token: tools, paths, services, network, TTL, tool-call cap. It is short-lived, single-sandbox, non-forgeable, replay-resistant. Visitors cannot mint grants.

Nine rules

  1. 1Fail closed.
  2. 2No ambient authority.
  3. 3No free shell, SSH, or admin mode.
  4. 4Prose is a label. The ticket authorizes.
  5. 5Tokens are short-lived and bound.
  6. 6Every decision is audited.
  7. 7Unbounded jobs are denied.
  8. 8Policy works offline.
  9. 9Host secrets never leave.

Out of scope

  • Sandbox execution or tool proxy
  • Production writes
  • Host filesystem or env dump
  • Human contact or secret read
  • Offensive scanning

Flow

visitor
→ KNOCK
→ AUTHENTICATE
→ VALIDATE
→ COMPILE
→ MINT grant
→ handoff stub

v1 tools

read_logs
stat_path
read_file
run_healthcheck
propose_diff
list_dir

Not in v1: shell, curl, write_host_file, install_package, send_email.

Try it

Demo tenant acme, key acme-ops-1. Knock a trusted check on billing-api. Then aim a repair at production and watch it refuse.

Open the console