Honua safe-agent flagship

Agents propose. Policy validates. You approve. Honua executes.

Model output is untrusted input—not permission. Every effect is typed, bounded, context-bound, and receipted.

mode deterministic fixture state proposed source reads 0 live lane skipped
1 Proposal2 Validation3 Approval4 Execution5 Receipt

01 · Untrusted input

Agent proposal

Requested effect
Important
Loading this proposal performs no read, write, subscription, or app effect.

Proposed tool calls

    02 · Side-effect free

    Typed plan & bindings

    Waiting for policy validation

    03 · Human control

    Explicit approval

    No approval grant exists

    Approval binds the exact plan digest, reviewer, effect, context, maximum rows, and maximum bytes. Inspect the request/row/byte estimate, fidelity, cache policy, and provenance in the dry-run plan before granting it. Narrowing cannot widen the proposal.

    Policy lab

    Prove refusal paths

    effects disabled

    These proposals are intentionally invalid. Each must fail before any source call.

    04 · Approved effect

    Bounded result

    0 rows
    Rows returned by the approved read
    IDParcelZoneBuiltValue

    05 · Verifiable outcome

    Tamper-evident receipt

    No execution receipt

    Integrity check: not-run. The receipt binds plan, approval, result, source/schema versions, scope, and time.

    
            

    Optional lane

    Host-mediated model & live data

    no browser secrets

    Model providers and data credentials belong behind same-origin host endpoints. Missing configuration records a structured skip; it never masquerades fixture output as live.

    Proposal loaded. No source or tool effect has run.