Human authority · observable state

Automation should explain itself—and wait where authority begins.

Our approach separates what a system can observe, propose, authorize, execute, verify, and recover. Access to a tool is never treated as permission to act.

Operation path

Control stays visible from intent to recovery.

  1. 01

    Observe

    Read only the approved scope and show the source, freshness, and limits of the available evidence.

  2. 02

    Propose

    Prepare a bounded interpretation or plan without presenting it as an applied change.

  3. 03

    Authorize

    Verify the operator, target, purpose, capability, limits, and duration before protected work begins.

  4. 04

    Execute

    Let the system that owns the work stage, perform, commit, or safely abort the authorized operation.

  5. 05

    Verify and recover

    Record what changed, what did not, what remains unresolved, and which recovery path is available.

Design commitments

Constraints before claims.

Local-first direction

Useful diagnostic workflows should remain under device-local control by default. Any online integration needs a declared purpose and bounded data flow.

Privacy by default

Collect only what the named operation needs. Optional telemetry, account linkage, and external processing require explicit review and consent.

Fail-closed boundaries

Ambiguity about identity, consent, authority, evidence, signing, or release stops the protected action.

Evidence over assumption

Claims should identify their source, environment, procedure, result, limitations, and accountable decision owner.

Thirteen principles

A system organized around human control.