ForgeLayer

AgentOS provider-aware routing

Deterministic compatibility, separate from control eligibility.

Modeled fit uses server-owned capabilities. It is not provider performance, assignment, approval, verification, dispatch, or execution.
Deterministic recommendationNot assigned

Claude Code

secure payment webhook

Highest modeled fit
95/100
Recommendation state
deterministic recommendation
Recommendation use
available for human review
Routing analysis
routing-analysis-secure-payment-webhook
Task / repository
controlled-task-secure-payment-webhook / repository-connection-preview-secure-payment-webhook
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z
Recommendation use blockedNot assigned

Claude Code

harden risky prompt

Highest modeled fit
93/100
Recommendation state
recommendation blocked
Recommendation use
blocked by revocation
Routing analysis
routing-analysis-harden-risky-prompt
Task / repository
controlled-task-harden-risky-prompt / repository-connection-preview-harden-risky-prompt
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z
Recommendation use blockedNot assigned

Cursor

investigate failing tests

Highest modeled fit
95/100
Recommendation state
recommendation blocked
Recommendation use
blocked by kill switch
Routing analysis
routing-analysis-investigate-failing-tests
Task / repository
controlled-task-investigate-failing-tests / repository-connection-preview-investigate-failing-tests
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z

Routing-analysis ledger events

Recommendations are recorded without provider assignment or execution.

These deterministic, non-persistent events preserve recommendation provenance while current control state remains separately evaluated.
ledger-demo-payment-verification

Claude Code recorded as the highest modeled fit; no assignment was created.

deterministic_recommendation · persisted: false
ledger-demo-prompt-review

Claude Code recorded as the highest modeled fit; no assignment was created.

recommendation_blocked · persisted: false
ledger-demo-verification-review

Cursor recorded as the highest modeled fit; no assignment was created.

recommendation_blocked · persisted: false

AI Work Ledger v2 foundations · system of record

Every AI software task, decision, review, approval, and outcome — recorded.

AI Software Teams. Controlled.

ForgeLayer connects controlled AI software work into one operational record, keeping recommendations, evidence, approvals, and outcomes visibly distinct.

Demo recordsPersisted: falseExecution disabledGeneric platform guidance: Human approval required

Authenticated integration boundary

Read append-only Ledger events for the active workspace.

The user-context adapter exposes safe event provenance only. Updates, deletes, actor rewrites, workspace moves, and execution side effects remain unavailable.
Integration inactive

Authenticated append-only Ledger

Durable record adapter is inactive and fails closed.

Update / delete: disabled
Workspace boundary

Workspace mode: private_beta. Role: anonymous. Auth required: no. Persistence allowed: limited/demo only. GitHub posting: disabled by default. Agent execution: disabled. Billing: not live.

Approval Authority foundation

Approval is bound to one exact work state.

Authority, approval, revocation, kill switches, verification, and execution transport remain separate control dimensions.

secure payment webhook

Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

blocked platform
Required authority
workspace owner
Principal
Demo workspace owner / demo authority
Exact object
controlled-task-secure-payment-webhook
Repository
repository-identity-secure-payment-webhook
Risk / budget
HIGH / task-budget-secure_payment_webhook-v1
Dispatch authorization
dispatch-authorization-preview-db15b2cd
Verification plan
verification-plan-2458e6d26e940ec0
Evaluated at
2026-08-12T04:25:49.255Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
blocked platform
Approval requirement
Satisfied
Historical grant state
granted
Revocation
not revoked
Kill switch
inactive
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled

Approval requirement satisfied. Repository verification has not run, and execution transport remains disabled.

Immutable bindingsapproval-grant-integrity-a9cdee22ac5c873d5f817dc8policy-snapshot-5cc8bbf1capability-package-secure-payment-webhook-v1verification-plan-2458e6d26e940ec0
Reasoning trail (3)
  • The exact human approval requirement is satisfied.
  • Repository verification is incomplete.
  • Repository runners are not run and execution transport is disabled.
Grant conditions (3)
  • Repository verification remains separate.
  • Execution transport remains disabled.
  • Any immutable binding change requires reevaluation.
Append-only lifecycle (3)
  1. approval authority requested · historical lifecycle event: Exact authority and immutable scope were requested.
  2. approval granted · historical lifecycle event: A deterministic historical approval grant was recorded.
  3. workflow progression blocked · historical lifecycle event: Workflow progression remains blocked; repository execution was not running.

harden risky prompt

Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

revocation active
Required authority
prompt security reviewer
Principal
Demo prompt-security reviewer / demo authority
Exact object
controlled-task-harden-risky-prompt
Repository
repository-identity-harden-risky-prompt
Risk / budget
HIGH / task-budget-harden_risky_prompt-v1
Dispatch authorization
dispatch-authorization-preview-ec038137
Verification plan
verification-plan-d17b2a5528b4be7a
Evaluated at
2026-08-12T04:25:49.255Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
revocation active
Approval requirement
approval revoked
Historical grant state
granted
Revocation
revoked
Kill switch
inactive
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled

A historical approval exists, but current authorization is revoked.

Immutable bindingsapproval-grant-integrity-05dae0fed2dafcfb581b00bapolicy-snapshot-d8a299d8capability-package-harden-risky-prompt-v1verification-plan-d17b2a5528b4be7a
Reasoning trail (2)
  • The exact human approval requirement is satisfied.
  • An effective append-only revocation overrides the historical grant.
Grant conditions (3)
  • Repository verification remains separate.
  • Execution transport remains disabled.
  • Any immutable binding change requires reevaluation.
Append-only lifecycle (4)
  1. approval authority requested · historical lifecycle event: Exact authority and immutable scope were requested.
  2. approval granted · historical lifecycle event: A deterministic historical approval grant was recorded.
  3. approval revoked · historical lifecycle event: Authorization revoked; no external cancellation was performed.
  4. workflow progression blocked · historical lifecycle event: Workflow progression remains blocked; repository execution was not running.
Authorization revokedPrompt digest requires a new prompt-security approval.No external cancellation was performed.

investigate failing tests

Keep workflow progression blocked by the active kill switch. An active kill switch blocks workflow progression. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

kill switch active
Required authority
engineering approver
Principal
Demo engineering approver / demo authority
Exact object
controlled-task-investigate-failing-tests
Repository
repository-identity-investigate-failing-tests
Risk / budget
MEDIUM / task-budget-investigate_failing_tests-v1
Dispatch authorization
dispatch-authorization-preview-683d375f
Verification plan
verification-plan-b860ede3565b9a00
Evaluated at
2026-08-12T04:25:49.255Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
kill switch active
Approval requirement
Satisfied
Historical grant state
granted
Revocation
not revoked
Kill switch
active
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled

An approval exists, but workflow progression is blocked by an active kill switch.

Immutable bindingsapproval-grant-integrity-36095571ec30a139cd54c748policy-snapshot-69ecde00capability-package-investigate-failing-tests-v1verification-plan-b860ede3565b9a00
Reasoning trail (2)
  • The exact human approval requirement is satisfied.
  • controlled_task kill switch blocks workflow progression.
Grant conditions (3)
  • Repository verification remains separate.
  • Execution transport remains disabled.
  • Any immutable binding change requires reevaluation.
Append-only lifecycle (4)
  1. approval authority requested · historical lifecycle event: Exact authority and immutable scope were requested.
  2. approval granted · historical lifecycle event: A deterministic historical approval grant was recorded.
  3. kill switch activated · historical lifecycle event: Kill switch activated; workflow progression blocked.
  4. workflow progression blocked · historical lifecycle event: Workflow progression remains blocked; repository execution was not running.
Kill switch active / controlled taskFailing-test remediation remains unverified.Workflow progression blocked; repository execution was not running.

Repository connection provenance

Current connection state and historical lifecycle previews stay distinct.

The Ledger mirrors deterministic repository lifecycle events for three isolated scenarios. Events are non-persistent and never imply a GitHub request, installation, repository read, PR action, check post, comment post, workflow trigger, merge, or execution.
Repository hosts1
Recorded previews3
Lifecycle events55
GitHub requests0
GitHub writes0
Repository executions0
repository_host_recognized

GitHub repository host recognized.

secure_payment_webhook · external GitHub operation: false
repository_connection_recorded

Deterministic repository preview recorded.

secure_payment_webhook · external GitHub operation: false
repository_workspace_membership_recorded

Workspace membership recorded.

secure_payment_webhook · external GitHub operation: false
github_installation_required

A future reviewed GitHub App installation is required.

secure_payment_webhook · external GitHub operation: false
github_installation_unverified

GitHub installation remains unverified.

secure_payment_webhook · external GitHub operation: false
github_installation_ownership_unverified

Installation ownership remains unverified.

secure_payment_webhook · external GitHub operation: false
repository_ownership_unverified

Repository ownership remains unverified.

secure_payment_webhook · external GitHub operation: false
repository_permissions_modeled

Permissions are modeled but unrequested and unverified.

secure_payment_webhook · external GitHub operation: false
repository_permissions_unverified

No repository permission was requested, granted, or verified.

secure_payment_webhook · external GitHub operation: false
repository_metadata_not_fetched

Repository metadata was not fetched.

secure_payment_webhook · external GitHub operation: false
repository_contents_not_fetched

Repository contents were not fetched.

secure_payment_webhook · external GitHub operation: false
repository_pull_requests_not_fetched

Pull requests were not fetched.

secure_payment_webhook · external GitHub operation: false

Controlled lifecycle

From observed signal to recorded outcome

Each stage retains its meaning. A recommendation is not approval, and simulated evidence is not a production result.
01

Observe

Capture a safe fact or intake signal.

available
02

Assess

Attach policy, risk, and routing context.

available
03

Draft decision

Record a system recommendation without treating it as approval.

available
04

Human approval

Require an explicit human decision for controlled work.

available
05

Verify

Associate test or review evidence with the decision.

simulated or draft
06

Record outcome

Connect the result to its related Work and Review records.

foundation only

Derived demo metrics

Control activity at a glance

Counts below are calculated from deterministic, non-persistent demo records. They are not production analytics.
persisted: false
10Total recordsDerived demo metric
4Awaiting approvalDerived demo metric
2VerifiedDerived demo metric
6Needs reviewDerived demo metric
1BlockedDerived demo metric
9Human decisionsDerived demo metric
28Linked evidenceDerived demo metric

Record model

One control record, multiple sources

Every AI software task, decision, review, approval, and outcome — recorded.
PromptForge

Prompt Review

Prompt quality, rewrite, and security-test evidence.

AgentOS

Agent Routing

Task classification and deterministic agent recommendations.

Agent Work Records

Agent Work Record

Draft record of requested work, risk, evidence, and approvals.

MergeGuard

Merge Decision

Risk, policy, and merge recommendation context.

Review Runs

Review Evidence

Safe review summary and verification evidence.

MergeGuard

Approval

Pending or granted human decisions.

Review Runs

Verification

Test or review evidence state, including needs-review outcomes.

Operational record explorer

Inspect linked AI work records

Search and filter a deterministic record graph, then inspect the evidence, policy context, human decision, and next controlled action.
Demo data only

Showing 10 of 10 simulated, non-persistent records.

System-of-record foundation

Control context that survives the handoff

The foundation links safe summaries without storing raw prompts, diffs, provider errors, tokens, payloads, or secrets.

Connect prompt, routing, review, approval, verification, and outcome records.

Separate observed facts from recommendations, draft decisions, and human approvals.

Link evidence and related records without exposing raw prompts, diffs, secrets, or payloads.

Surface approval and verification state before work is trusted or merged.

Derive safe Review Run and Agent Work Record ledger previews.

Prepare workspace-scoped audit history while production persistence remains blocked.

Existing connections

Derived ledger entries

Agent Work Record ledger entries are derived/foundation-only. They remain non-production until the implemented workspace identity/schema foundation is connected to reviewed production adapters and real RLS behavior is validated. The original Review Run connection remains available beside them.
persisted: false

agent work record

Secure prompt review record

needs_human_review

Review the code review agent prompt for prompt injection, secret leakage, unsafe tool use, and missing approval gates.

Generic Security Agent work record is proposed. Detected work: prompt_engineering, security_review, code_review. Evidence: 2. Risks: 3. Approvals: 0. Human review required: yes. Merge readiness: not_ready.

Control principles

Trust requires explicit boundaries

The Ledger records control state; it does not turn that state into an autonomous action.
01

Observed facts, system recommendations, draft decisions, evidence, and human approvals remain visibly distinct.

02

Human approval is required for controlled work and is never inferred from model output.

03

Demo verification may be simulated or draft and must not be treated as production evidence.

04

No live agent execution, repository access, GitHub posting, or automatic merge is enabled.

05

Production persistence, workspace tenancy, audit retention, and analytics remain future work.