UI route
PrivatePrivate page route behind session auth
This first OS9 shell turns the fleet product contract into a private, typed, governed surface. Governance truth is visible now; registry APIs are published, signed approval evidence is bounded, and broader mutation remains fail-closed.
This shell inherits authenticated page-route posture and is not exposed as a public marketing surface.
Runner registration and connector mutation stay blocked; signed Mission approval issuing, sandbox eval summaries, cost visibility, and operator sandbox interrupts are live.
Published /api/v2/os9 fleets, runners, approvals, and mission contracts use route-level auth and explicit OpenAPI registration; broader OS9 APIs remain closed.
Governed inventory anchored to one workspace.
Hosted and local posture are visible without widening trust.
Blocked actions stay explicit instead of silently enabled.
Preflight contracts bind intent, capabilities, gates, and receipts.
Hash-linked action evidence is visible to operators.
Process Mirror summaries classify what still needs review.
The current product boundary is deliberate: private UI, bounded registry APIs, signed approval evidence, and no silent live mutation.
Private page route behind session auth
Published /api/v2/os9/fleets, /api/v2/os9/runners, /api/v2/os9/approvals, and /api/v2/os9/mission-contracts behind API-key auth
Only signed Mission approval token issuing is live; broader mutation remains blocked
Aweb / command-private
Wave 1 proves visibility across the four product objects that matter first.
Fleet inventory, policy mode, connector reach, and blocked reasons are exposed as typed records.
Hosted, BYOC, and local runners show trust posture and heartbeat truth without pretending write admission already exists.
Approval pressure and Process Mirror narratives are legible, but no live action buttons are exposed yet.
Compiled before execution so Maestro, Trust Runtime, and receipts share the same authority boundary.
Build and run a governed communications and funding-ops agent fleet that can research, triage, draft, update records, pause for approval, and prove every meaningful action.
Sensitive actions default to block; evidence and receipts link back to the contract.
Any Gmail thread or message body read beyond the explicit search result envelope.
Any email, Slack message, or multi-channel communication that leaves draft mode.
Any write to the funding ledger, CRM-like workspace, or durable operator record.
Required fields include contract authority, policy decision, approval, redaction, result, failure, and recovery.
A bounded slice of the governed fleet model the product is built around.
Govern cross-substrate operations with explicit policy and stop authority.
Package internal Aweb substrate into governed customer-facing OS surfaces.
Coordinate monitored commercial interventions without widening spend posture.
The runtime model is visible next to the review queue it still depends on.
Aweb / command-private
Aweb / command-private
Keep /api/v2/os9 publication bounded to read-only fleets, runners, and mission contracts
Admit BYOC write-capable connector reach for Platform Control
Redacted mission narratives classify what happened, what was touched, and what remains blocked.
Route-auth proof is complete: /os9 stays private while /api/v2/os9 is now bounded to read-only fleets, runners, and mission contracts.
Connector reach is visible, but the BYOC runner is still degraded and cannot widen write posture.
Historical revenue-response traces are preserved, but the replay runner is stale and should not be scheduled.