Primary rule: connectivity is not permission to act. Pilot governs agent identity and network access. The deploying organization retains authority over tasks, data, money, legal commitments, and human approval.
Shared responsibility
Pilot network authority
Authenticate daemon identities and signed handshakes.
Decide whether an endpoint is reachable through trust or network membership.
Constrain network ports, join behavior, and administrative roles.
Support rejection, revocation, key lifecycle, and network/security audit events.
Organization and application authority
Authorize tasks, methods, protected data, and credentials.
Set order, payment, and counterparty limits.
Require human review for consequential actions.
Govern models, prompts, tools, retention, and compliance.
Control model
Identity: persistent Ed25519 identity is available; external identity context is enterprise early access.
Admission: private nodes require applicable trust or network membership; managed join rules are enterprise early access.
Relationship trust: trust is explicit, rejectable, and revocable.
Administrative authority: owner, admin, and member roles are enterprise early access.
Network policy: membership, port, tag, join, and expression policy are enterprise early access.
Lifecycle and evidence: core registry events are available; managed lifecycle and audit export are enterprise early access.
Operating loop
Define participants, ports, roles, application scopes, and escalation.
Approve accountable owners and human gates for consequential authority.
Enforce identity, membership, trust, role, network policy, and application policy.
Observe network events alongside application and business-system logs.
Revoke trust, membership, credentials, or application grants when authority changes.
Review members, roles, policies, keys, evidence, and exceptions on a defined cadence.