Enforcement kernel
Quiet Open-Core v1.2.0: frozen /v1 decision loop, Cedar policy, web/Slack approvals, MCP gateway, Docker sandbox, hash-chained audit. Mode A public package baseline.
Roadmap
Mode A public baseline is Quiet Open-Core v1.2.0 (Stage 1 Enforcement Kernel). Stage 2 may be locally implemented. Stage 3 governed autonomy is future/conditional — not the public free-surface baseline. Memory vault and production-qualified multi-tenant SaaS remain Mode B / future.
Built + tests pass = done. No design-partner or external proof gate. Mode A public baseline remains Quiet Open-Core v1.2.0.
Quiet Open-Core v1.2.0: frozen /v1 decision loop, Cedar policy, web/Slack approvals, MCP gateway, Docker sandbox, hash-chained audit. Mode A public package baseline.
Operator visibility, policy ops (dry-run), multi-channel webhook approvals, OIDC ops auth, single-tenant hosted path with health probes. Implemented/local engineering — not a higher public maturity label than Quiet Open-Core.
Multi-tenant foundation, fail-closed gVisor isolation, STS credential broker, Object Lock evidence, durable SIEM. Engineering may exist in public artifact trees; not Mode A public baseline and not production-qualified without Mode B.
Universal infrastructure that secures, audits, and certifies every agent action across the enterprise.
Capability matrix
Status flips only when implementation exists and tests pass.
Fail-closed intercept → Cedar + risk + budgets + kill switch → allow / deny / approval_required.
Session timelines and evidence packages for self-host review.
One-use, TTL-bounded human approvals on the self-host surface.
Session/decision filters, ops metrics rates, kill-switch and budget home on /v1/metrics/usage and /dashboard/metrics.
Bundle upload/activate, dry-run test API, risk-rules GET/PUT and Policy Ops dashboard controls.
Channel interface with webhook notify + webhook decide path (non-web) completing approve/deny.
OIDC bearer tokens for operator routes when ACTANTOS_OIDC_* is configured; unauthenticated ops deny.
Single-tenant Docker Compose path with /health/live and /health/ready; docs/HOSTED.md.
Tenant-bound OIDC/service principals, RBAC, required tenant selectors, identity schema and RLS migrations. Conditional — not Mode A public baseline.
Signed isolation contract with fail-closed gVisor/runsc provider. Conditional enterprise path — not Quiet Open-Core free surface.
Provider-neutral broker with AWS STS AssumeRole, hashed lease metadata, and tmpfs-only secret material.
Signed evidence artifacts archived with S3 Object Lock COMPLIANCE semantics. Not claimed as current Mode A free surface.
Durable webhook and Splunk HEC connectors with outbox delivery. Managed / Stage 3 path — not current public baseline.
Not open-core “now” until built and tested as later stages: