ForgeLayer

Private beta Agent Governance Center

Define what each AI agent may propose, what stays restricted, and where humans must decide.

Agent governance connects AgentOS routing to repository policy, verification, and approval requirements without connecting or executing an agent.

Deterministic previewLive provider connections: falseRepository access: falseGeneric Platform Guidance: Human approval required

Provider governance boundary

Governed agent profiles do not inherit provider connection authority.

Codex, Claude Code, and Cursor are modeled products with recorded previews only. Authentication, ownership, provider health, dispatch, and execution remain unavailable.

Codex

coding agent product

Revocation and provider/workspace/platform/adapter kill switches override approval. Dispatch false · execution false.

Claude Code

coding agent product

Revocation and provider/workspace/platform/adapter kill switches override approval. Dispatch false · execution false.

Cursor

ai coding environment

Revocation and provider/workspace/platform/adapter kill switches override approval. Dispatch false · execution false.

Task-specific authority

Agent recommendation does not equal access.

Every recommended agent is paired with the authoritative task capability package. Packages remain inactive, expiring, revocable previews with dispatch and execution disabled.

previewcapability-package-secure-payment-webhook-v1

Secure the payment webhook

Generic Security Agent

Recommended for this task. No adapter authority or dispatch issued.

Repository scope
acme-payments/payment-webhook-service
Allowed tools
Read-only PR diff inspection, RepoBrain policy preview
Budget
$2.00 USD / 14000 tokens / 40 minutes, demo estimate only
Verification
payment_webhook_security: missing; auth_session_boundary: missing
Approval
owner: missing
Authority issued
false
Execution / dispatch
disabled
Inspect task authority
previewcapability-package-harden-risky-prompt-v1

Harden a risky agent prompt

Generic Prompt Engineer Agent

Recommended for this task. No adapter authority or dispatch issued.

Repository scope
acme-ai-support/refund-assistant-prompts
Allowed tools
PromptForge deterministic analyzer, Read-only policy preview
Budget
$1.25 USD / 7000 tokens / 20 minutes, demo estimate only
Verification
prompt_injection_security_tests: missing
Approval
reviewer: missing
Authority issued
false
Execution / dispatch
disabled
Inspect task authority
previewcapability-package-investigate-failing-tests-v1

Investigate the failing test suite

Codex

Recommended for this task. No adapter authority or dispatch issued.

Repository scope
acme-checkout/checkout-ui
Allowed tools
Read-only test evidence inspection, AgentOS routing preview
Budget
$1.50 USD / 10000 tokens / 30 minutes, demo estimate only
Verification
test_failure_reproduced: missing; test_remediation_verified: missing
Approval
reviewer: missing
Authority issued
false
Execution / dispatch
disabled
Inspect task authority

Operational governance preview

Governed agent registry

Compare deterministic routing fit with explicit capability limits, task restrictions, protected-path rules, verification, and human approval. Local actions never alter AgentOS routing or grant access.

Preview onlyPersisted: falseConnections: falseExecution: false
6Governed agentsDeterministic preview
4Recommendation onlyDeterministic preview
2Mandatory approvalDeterministic preview
20Restricted assignmentsDeterministic preview
29Blocked assignmentsDeterministic preview
3Protected path rulesDeterministic preview
6Verification requiredDeterministic preview
6Policy controlledDeterministic preview
6Needs reviewDeterministic preview
Loading

Loading agent governance preview.

Preparing deterministic registry, policy, verification, and approval context.