Product sheet · v1
The Door
Admission control for untrusted visiting agents.
Fail closed.
No ambient authority.
No free shell.
A visitor knocks, states a job, and either receives a short-lived grant — or is refused.
Natural-language intent is never enough. A shell is never issued. The Door authenticates a principal, compiles a capability set from a structured ticket, and mints a signed session token bound to a future sandbox. Policy is deterministic. No model is required to admit or refuse.
01
The problem
Untrusted agents will ask to “just check production,” “fix everything,” or speak as vendor support. Spoken intent is not identity. Prose is not a permission. A helpful sentence is still unbounded.
02
The door
Knock with identity plus a ticket. Authenticate. Validate. Compile. Mint a SessionGrant — or deny. Every decision is append-only audited. Unknown principals and malformed jobs fail closed.
03
The grant
Success is a capability token: tools, paths, services, network, TTL, tool-call cap. It is short-lived, single-sandbox, non-forgeable, replay-resistant. Visitors cannot mint grants.
Nine rules
- 1Fail closed.
- 2No ambient authority.
- 3No free shell, SSH, or admin mode.
- 4Prose is a label. The ticket authorizes.
- 5Tokens are short-lived and bound.
- 6Every decision is audited.
- 7Unbounded jobs are denied.
- 8Policy works offline.
- 9Host secrets never leave.
Out of scope
- Sandbox execution or tool proxy
- Production writes
- Host filesystem or env dump
- Human contact or secret read
- Offensive scanning
Flow
visitor
→ KNOCK
→ AUTHENTICATE
→ VALIDATE
→ COMPILE
→ MINT grant
→ handoff stub
v1 tools
read_logs
stat_path
read_file
run_healthcheck
propose_diff
list_dir
Not in v1: shell, curl, write_host_file, install_package, send_email.
Try it
Demo tenant acme, key acme-ops-1. Knock a trusted check on billing-api. Then aim a repair at production and watch it refuse.
Open the console