Cursor recorded as the highest modeled fit; no assignment was created.
recommendation_blocked · persisted: false
AI Work Ledger v2 foundations · system of record
Every AI software task, decision, review, approval, and outcome — recorded.
AI Software Teams. Controlled.
ForgeLayer connects controlled AI software work into one operational record, keeping recommendations, evidence, approvals, and outcomes visibly distinct.
Demo recordsPersisted: falseExecution disabledGeneric platform guidance: Human approval required
Authenticated integration boundary
Read append-only Ledger events for the active workspace.
The user-context adapter exposes safe event provenance only. Updates, deletes, actor rewrites, workspace moves, and execution side effects remain unavailable.
Integration inactive
Authenticated append-only Ledger
Durable record adapter is inactive and fails closed.
Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.
revocation active
Required authority
prompt security reviewer
Principal
Demo prompt-security reviewer / demo authority
Exact object
controlled-task-harden-risky-prompt
Repository
repository-identity-harden-risky-prompt
Risk / budget
HIGH / task-budget-harden_risky_prompt-v1
Dispatch authorization
dispatch-authorization-preview-ec038137
Verification plan
verification-plan-d17b2a5528b4be7a
Evaluated at
2026-08-12T04:25:49.255Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
revocation active
Approval requirement
approval revoked
Historical grant state
granted
Revocation
revoked
Kill switch
inactive
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled
A historical approval exists, but current authorization is revoked.
Keep workflow progression blocked by the active kill switch. An active kill switch blocks workflow progression. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.
kill switch active
Required authority
engineering approver
Principal
Demo engineering approver / demo authority
Exact object
controlled-task-investigate-failing-tests
Repository
repository-identity-investigate-failing-tests
Risk / budget
MEDIUM / task-budget-investigate_failing_tests-v1
Dispatch authorization
dispatch-authorization-preview-683d375f
Verification plan
verification-plan-b860ede3565b9a00
Evaluated at
2026-08-12T04:25:49.255Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
kill switch active
Approval requirement
Satisfied
Historical grant state
granted
Revocation
not revoked
Kill switch
active
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled
An approval exists, but workflow progression is blocked by an active kill switch.
Current connection state and historical lifecycle previews stay distinct.
The Ledger mirrors deterministic repository lifecycle events for three isolated scenarios. Events are non-persistent and never imply a GitHub request, installation, repository read, PR action, check post, comment post, workflow trigger, merge, or execution.
Every AI software task, decision, review, approval, and outcome — recorded.
PromptForge
Prompt Review
Prompt quality, rewrite, and security-test evidence.
AgentOS
Agent Routing
Task classification and deterministic agent recommendations.
Agent Work Records
Agent Work Record
Draft record of requested work, risk, evidence, and approvals.
MergeGuard
Merge Decision
Risk, policy, and merge recommendation context.
Review Runs
Review Evidence
Safe review summary and verification evidence.
MergeGuard
Approval
Pending or granted human decisions.
Review Runs
Verification
Test or review evidence state, including needs-review outcomes.
Operational record explorer
Inspect linked AI work records
Search and filter a deterministic record graph, then inspect the evidence, policy context, human decision, and next controlled action.
Demo data only
Showing 10 of 10 simulated, non-persistent records.
System-of-record foundation
Control context that survives the handoff
The foundation links safe summaries without storing raw prompts, diffs, provider errors, tokens, payloads, or secrets.
Connect prompt, routing, review, approval, verification, and outcome records.
Separate observed facts from recommendations, draft decisions, and human approvals.
Link evidence and related records without exposing raw prompts, diffs, secrets, or payloads.
Surface approval and verification state before work is trusted or merged.
Derive safe Review Run and Agent Work Record ledger previews.
Prepare workspace-scoped audit history while production persistence remains blocked.
Existing connections
Derived ledger entries
Agent Work Record ledger entries are derived/foundation-only. They remain non-production until the implemented workspace identity/schema foundation is connected to reviewed production adapters and real RLS behavior is validated. The original Review Run connection remains available beside them.
persisted: false
agent work record
Secure prompt review record
needs_human_review
Review the code review agent prompt for prompt injection, secret leakage, unsafe tool use, and missing approval gates.
Agent
Generic Security Agent
Work status
proposed
Merge readiness
not_ready
Human review
required
Evidence
2
Persisted
false
Generic Security Agent work record is proposed. Detected work: prompt_engineering, security_review, code_review. Evidence: 2. Risks: 3. Approvals: 0. Human review required: yes. Merge readiness: not_ready.
Control principles
Trust requires explicit boundaries
The Ledger records control state; it does not turn that state into an autonomous action.
01
Observed facts, system recommendations, draft decisions, evidence, and human approvals remain visibly distinct.
02
Human approval is required for controlled work and is never inferred from model output.
03
Demo verification may be simulated or draft and must not be treated as production evidence.
04
No live agent execution, repository access, GitHub posting, or automatic merge is enabled.
05
Production persistence, workspace tenancy, audit retention, and analytics remain future work.