ForgeLayer

AI Provider Connection Layer · Part 131

Prepare provider connections without handing an agent authority.

Understand and govern workspace-owned AI provider relationships without authenticating, routing, dispatching, or executing work.

Provider products: 3Recorded previews: 3Verified / authenticated: 0 / 0Dispatch ready: 0Human approval remains separate

Authenticated integration boundary

Record safe provider metadata without contacting a provider.

This isolated path persists allowlisted workspace metadata under the authenticated user and Postgres RLS. Credentials, provider sessions, assignment, dispatch, and execution remain unavailable.
Integration inactive

Provider connection metadata

Isolated persistence is not active. Deterministic preview data remains separate.

External contact: false

Workspace provider inventory

3 provider products recognized

3 deterministic workspace connection previews. Provider account ownership and authentication remain unverified.

3Recorded previews
0Verified
0Authenticated
0Ownership verified
0Live health
0Outputs received
0Dispatch enabled
0Execution enabled
Deterministic previewPersisted production connections: 0Routing decisions: 0Human approval cannot enable dispatch

Workspace-owned provider connections

Detailed connection records from one authoritative workspace projection.

Workspace owns the inventory boundary; provider products and capabilities remain referenced from the Part 131 server-owned registry.

OpenAI

Codex

Recorded preview

coding agent product · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
codex-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-managed
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (14)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • test-execution-proposalregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • command-proposalregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • structured-outputregistry-owned · modeled, not live verified
  • long-running-task-supportregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Anthropic

Claude Code

Recorded preview

coding agent product · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
claude-code-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-managed
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (15)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • test-execution-proposalregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • security-review-assistanceregistry-owned · modeled, not live verified
  • prompt-analysisregistry-owned · modeled, not live verified
  • command-proposalregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • long-running-task-supportregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Cursor

Cursor

Recorded preview

ai coding environment · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
cursor-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-recorded
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (11)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • ide-assisted-workregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Reviewed local or IDE bridge boundary
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Authentication and ownership boundary

A recorded preview is not a provider account connection.

No API key, OAuth token, session cookie, provider identity, or personal account identifier is requested or stored.

Identity and ownership

Workspace-recorded only. Identity and provider account ownership remain unverified.

Unverified

Authentication and secrets

Authentication transport is unavailable. No provider secret is stored.

Unavailable

Health and output

No health probe ran, no provider was contacted, and no provider output was received.

Not observed

Controlled Task compatibility

A recommendation can be compatible in shape and still have zero authority.

Each preview binds the existing recommendation to its policy and capability package. Current packages are inactive, connections are unavailable, and dispatch is globally disabled.
adapter unavailablenot implemented
controlled-task-secure-payment-webhook

Secure a payment webhook

GitHub Copilot · GitHub Copilot

Recommended for this task. No adapter authority or dispatch issued.

Connection source
unavailable
Capability package
capability-package-secure-payment-webhook-v1
Package state
preview
Path count
2
Network / secrets
disabled / none
Can dispatch
false
Prerequisites (8)
  • Trusted workspace identity
  • Authenticated active workspace membership
  • Production persistence and auditable connection ownership
  • Active task-scoped capability package
  • Connected repository with approved scope
  • Complete evidence and independent verification
  • Explicit human approval
  • Provider-specific adapter configuration

Future dispatch package preview — no request sent.

Inspect Controlled Task adapter context
adapter unavailablenot implemented
controlled-task-harden-risky-prompt

Harden a risky prompt

Generic Security Agent · ForgeLayer internal agent profiles

Recommended for this task. No adapter authority or dispatch issued.

Connection source
unavailable
Capability package
capability-package-harden-risky-prompt-v1
Package state
preview
Path count
2
Network / secrets
disabled / none
Can dispatch
false
Prerequisites (8)
  • Trusted workspace identity
  • Authenticated active workspace membership
  • Production persistence and auditable connection ownership
  • Active task-scoped capability package
  • Connected repository with approved scope
  • Complete evidence and independent verification
  • Explicit human approval
  • Provider-specific adapter configuration

Future dispatch package preview — no request sent.

Inspect Controlled Task adapter context
adapter unavailablenot implemented
controlled-task-investigate-failing-tests

Investigate failing tests

GitHub Copilot · GitHub Copilot

Recommended for this task. No adapter authority or dispatch issued.

Connection source
unavailable
Capability package
capability-package-investigate-failing-tests-v1
Package state
preview
Path count
3
Network / secrets
disabled / none
Can dispatch
false
Prerequisites (8)
  • Trusted workspace identity
  • Authenticated active workspace membership
  • Production persistence and auditable connection ownership
  • Active task-scoped capability package
  • Connected repository with approved scope
  • Complete evidence and independent verification
  • Explicit human approval
  • Provider-specific adapter configuration

Future dispatch package preview — no request sent.

Inspect Controlled Task adapter context

Dispatch boundary

Adapter implementation, connection, authority, and transport stay separate.

A compatible adapter does not mean a connection exists, and a connection would not authorize dispatch. The current external transport is disabled.

Adapter implementation

Descriptive contracts exist for Codex, Claude Code, and Cursor with no execution operation.

Foundation

Connection and eligibility

Recorded previews: 3. Verified connections: 0. Dispatch-ready tasks: 0.

Verification required

Dispatch transport

Disabled transport. Zero provider requests and no remote task references.

Transport disabled

Evidence contracts

Provider claims do not become verified evidence.

Output and evidence envelopes keep provider-reported, ForgeLayer-observed, independently verified, and simulated data separate.

Provider reported

A provider may declare output or evidence; ForgeLayer does not trust the claim as verification.

ForgeLayer observed

Safe receipt and lifecycle metadata may be recorded by a future trusted control plane.

Independently verified

Tests, policy checks, repository evidence, and human review must come from trusted systems.

Simulated

Current private-beta adapter records are deterministic, non-persistent previews.