Supervisor
NOT RUNExpected: access to its own pinned memory.
ENTERPRISE AGENTS / EARNED AUTHORITY
TENURE replaces day-zero credentials and permanent approvals with narrow authority earned from verified work—and revoked safely when evidence breaks.
Containment is deterministic. Investigation belongs to the Supervisor.
Complete a case first. This changes sandbox records and does not touch real payments.
No events yet. Every completed action will link to a receipt and a decision.
Policy grants authority. The Supervisor investigates failures and proposes bounded recovery. It cannot promote itself—or anyone else.
Test the distinction ↗PROOF LAB / CHALLENGE THE BOUNDARY
Inspect the experiment. See the inputs. Download every decision.
Two fixed evidence profiles have identical outcome accuracy. One cites the controlling policy. The other gets the answer right for the wrong reason.
Deterministic fixture · zero model calls · not the held-out corpus
Same outcome. Different permission.
Run the comparison to see why.
| Control strategy | Safe autonomy | Unsafe authorized | Awaiting human | Errors |
|---|
The Supervisor and Invoice runtime each attempt the same read-only memory lookup using their own credentials. No model call, impersonation or permission change.
Checking proof configuration…
Expected: access to its own pinned memory.
Expected: a verified permission denial.
Expectations are not results. Authentication failures, missing resources and timeouts do not count as a successful denial.
Run a case, inject a failure, and inspect containment, demotion, compensation and receipts.
Open fleet room ↗Loading recorded probe…
A real wall-clock wake after process loss is still pending. A sleeping request or browser timer will not be presented as durable execution.
PLATFORM / TRACEABLE COMPOSITION
Configuration is not execution evidence. This page keeps them separate.
Read-only configuration from this running service. No credentials or access tokens.
Loading…
SCOPE / WHAT THIS BUILD ACTUALLY PROVES
A working sandbox with real control boundaries—not a claim of production completeness.
The cloud Supervisor uses Gemini and constrained ADK tools. Local recovery uses deterministic fixtures. Vendor, Invoice and Treasury currently execute fixture-driven workflows; their native runtime identities do not mean each case invokes three models.
Vendor, invoice and payment records really change in the sandbox. No money moves. The irreversible bank-export escalation is a synthetic fixture, not a real bank integration. Recovery enumerates the current case, not every historical case across the tenant.
TENURE enforces capability authority at the mutation boundary. Native Google Agent Gateway is not deployed. Tenant-keyed records are not a substitute for authenticated multi-tenant authorization. Cloud access remains IAM-protected.
Cloud authority and sandbox records persist in Firestore. This local fleet uses shared memory. Business mutations and audit receipts are separate commits. Crashed owners require reconciliation; automatic crash recovery is not claimed.
Twenty parameterized synthetic families test policy and control behavior. They do not establish Gemini reliability, real-world attack prevalence, human time savings, or production financial risk. The human baseline is modeled.
Interactive durable wake and native identity controls, automatic incident-memory learning, measured model tokens and costs, deployed UI verification and a cold-reader walkthrough remain. No prize outcome is guaranteed.