Skip to main content

Roadmap

From kernel to platform

Mode A public baseline is Quiet Open-Core v1.2.0 (Stage 1 Enforcement Kernel). Stage 2 may be locally implemented. Stage 3 governed autonomy is future/conditional — not the public free-surface baseline. Memory vault and production-qualified multi-tenant SaaS remain Mode B / future.

Stage 1 — Done

Enforcement kernel

Quiet Open-Core v1.2.0: frozen /v1 decision loop, Cedar policy, web/Slack approvals, MCP gateway, Docker sandbox, hash-chained audit. Mode A public package baseline.

Stage 2 — Local

Agent Runtime Control Plane

Operator visibility, policy ops (dry-run), multi-channel webhook approvals, OIDC ops auth, single-tenant hosted path with health probes. Implemented/local engineering — not a higher public maturity label than Quiet Open-Core.

Stage 3 — Future / Conditional

Governed enterprise autonomy

Multi-tenant foundation, fail-closed gVisor isolation, STS credential broker, Object Lock evidence, durable SIEM. Engineering may exist in public artifact trees; not Mode A public baseline and not production-qualified without Mode B.

Vision

Agent OS for governed enterprise AI

Universal infrastructure that secures, audits, and certifies every agent action across the enterprise.

Capability matrix

What ships when

Status flips only when implementation exists and tests pass.

Done · Stage 1 · S1-kernel

Enforcement Kernel

Fail-closed intercept → Cedar + risk + budgets + kill switch → allow / deny / approval_required.

Done · Stage 1 · S1-evidence

Hash-chain audit & local export

Session timelines and evidence packages for self-host review.

Done · Stage 1 · S1-approvals-web-slack

Web + optional Slack approvals

One-use, TTL-bounded human approvals on the self-host surface.

Done · Stage 2 · S2-1

Operator visibility

Session/decision filters, ops metrics rates, kill-switch and budget home on /v1/metrics/usage and /dashboard/metrics.

Done · Stage 2 · S2-2

Policy operations

Bundle upload/activate, dry-run test API, risk-rules GET/PUT and Policy Ops dashboard controls.

Done · Stage 2 · S2-3

Multi-channel approvals

Channel interface with webhook notify + webhook decide path (non-web) completing approve/deny.

Done · Stage 2 · S2-4

Federated identity

OIDC bearer tokens for operator routes when ACTANTOS_OIDC_* is configured; unauthenticated ops deny.

Done · Stage 2 · S2-5

Hosted control plane

Single-tenant Docker Compose path with /health/live and /health/ready; docs/HOSTED.md.

Future · Stage 3 · S3-foundation

Multi-tenant foundation

Tenant-bound OIDC/service principals, RBAC, required tenant selectors, identity schema and RLS migrations. Conditional — not Mode A public baseline.

Future · Stage 3 · S3-isolation

Hardened isolation

Signed isolation contract with fail-closed gVisor/runsc provider. Conditional enterprise path — not Quiet Open-Core free surface.

Future · Stage 3 · S3-credentials

Short-lived credentials

Provider-neutral broker with AWS STS AssumeRole, hashed lease metadata, and tmpfs-only secret material.

Future · Stage 3 · S3-evidence

WORM evidence archives

Signed evidence artifacts archived with S3 Object Lock COMPLIANCE semantics. Not claimed as current Mode A free surface.

Future · Stage 3 · S3-siem

Productized SIEM

Durable webhook and Splunk HEC connectors with outbox delivery. Managed / Stage 3 path — not current public baseline.

Stage 1 non-goals (still deferred)

Not open-core “now” until built and tested as later stages:

  • Enterprise memory vault (audit evidence is not a memory vault)
  • Firecracker microVM runtime (gVisor/runsc is the intended hardened path)
  • Full multi-tenant managed SaaS control plane as a commercial product
  • Artificial open-core seat limits on the free Enforcement Kernel
  • Stage 3 / v1.1.0 as Mode A public maturity baseline
  • Production-qualified multi-tenant platform without Mode B evidence