ForgeLayer

AgentOS provider-aware routing

Deterministic compatibility, separate from control eligibility.

Modeled fit uses server-owned capabilities. It is not provider performance, assignment, approval, verification, dispatch, or execution.
Deterministic recommendationNot assigned

Claude Code

secure payment webhook

Highest modeled fit
95/100
Recommendation state
deterministic recommendation
Recommendation use
available for human review
Routing analysis
routing-analysis-secure-payment-webhook
Task / repository
controlled-task-secure-payment-webhook / repository-connection-preview-secure-payment-webhook
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z
Recommendation use blockedNot assigned

Claude Code

harden risky prompt

Highest modeled fit
93/100
Recommendation state
recommendation blocked
Recommendation use
blocked by revocation
Routing analysis
routing-analysis-harden-risky-prompt
Task / repository
controlled-task-harden-risky-prompt / repository-connection-preview-harden-risky-prompt
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z
Recommendation use blockedNot assigned

Cursor

investigate failing tests

Highest modeled fit
95/100
Recommendation state
recommendation blocked
Recommendation use
blocked by kill switch
Routing analysis
routing-analysis-investigate-failing-tests
Task / repository
controlled-task-investigate-failing-tests / repository-connection-preview-investigate-failing-tests
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z

Private beta workspace · deterministic demo data

Your control center for AI software work.

Launch controlled work, inspect human-attention queues, review evidence, and move between AgentOS, Review Runs, MergeGuard, Ledger, and Analytics from one workspace.

Private-beta demo workspacePersisted: falseExecution disabledProduction telemetry disabledGitHub posting disabledAuthority evaluator-owned

Authenticated integration boundary

Durable workspace state stays separate from demo projections.

When an explicitly isolated Supabase target is configured, this panel resolves the current workspace from a verified session and active membership. Public production remains fail closed.
Fail closed

No authenticated workspace

Authenticated workspace adapter is not active.

Local isolated validation passed. Hosted staging validation is pending; production activation remains blocked.

Workspace provider inventory

3 provider products recognized

3 deterministic workspace connection previews. Provider account ownership and authentication remain unverified.

3Recorded previews
0Verified
0Authenticated
0Ownership verified
0Live health
0Outputs received
0Dispatch enabled
0Execution enabled
Deterministic previewPersisted production connections: 0Routing decisions: 0Human approval cannot enable dispatch

Workspace repository inventory

1 repository host recognized

3 scenario-isolated GitHub repository previews. Installation, ownership, permissions, metadata, and contents remain unverified or unavailable.

Inspect Repository Connections
3Recorded previews
0Verified installations
0Verified repositories
0Metadata read enabled
0Contents read enabled
0Write enabled
0Webhooks configured
0Repository executions
Deterministic previewGitHub requests: 0GitHub writes: 0Provider inventory remains separate

Authoritative workspace inventory

Codex, Claude Code, and Cursor belong to one recorded workspace boundary.

Connection membership is recorded for this deterministic workspace. Provider account ownership, authentication, live health, and provider output remain unverified or unavailable.

OpenAI

Codex

Recorded preview

coding agent product · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
codex-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-managed
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (14)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • test-execution-proposalregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • command-proposalregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • structured-outputregistry-owned · modeled, not live verified
  • long-running-task-supportregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Anthropic

Claude Code

Recorded preview

coding agent product · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
claude-code-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-managed
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (15)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • test-execution-proposalregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • security-review-assistanceregistry-owned · modeled, not live verified
  • prompt-analysisregistry-owned · modeled, not live verified
  • command-proposalregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • long-running-task-supportregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Cursor

Cursor

Recorded preview

ai coding environment · workspace membership recorded, ownership unverified

Workspace
ForgeLayer Guided Beta
Membership
workspace recorded
Adapter
cursor-agent-adapter · provider-adapter-contract-v1
Lifecycle
connected preview
Connection mode
workspace-recorded
Ownership
unverified
Authentication
unavailable
Health
not checked
Provider output
output not received
Revocation / kill switch
not revoked / inactive
Dispatch / execution
disabled / disabled
workspaceIdentityTrustworkspace recordedproviderIdentityTrustidentity unverifiedownershipTrustownership unverifiedauthenticationTrustauthentication unverifiedcapabilityTrustcapability modeledhealthTrusthealth not observedproviderOutputTrustoutput not receivedworkspaceBindingTrustworkspace recordedadapterVersionTrustadapter recordedproductionReadinessproduction not ready
Inspect modeled capabilities (11)
  • code-generationregistry-owned · modeled, not live verified
  • code-editingregistry-owned · modeled, not live verified
  • ide-assisted-workregistry-owned · modeled, not live verified
  • repository-analysisregistry-owned · modeled, not live verified
  • refactoringregistry-owned · modeled, not live verified
  • test-generationregistry-owned · modeled, not live verified
  • code-reviewregistry-owned · modeled, not live verified
  • patch-generationregistry-owned · modeled, not live verified
  • human-in-the-loopregistry-owned · modeled, not live verified
  • evidence-exportregistry-owned · modeled, not live verified
  • work-record-exportregistry-owned · modeled, not live verified
Review future setup requirements
  • Provider-specific authentication
  • Authenticated workspace binding
  • Explicit repository scope
  • Reviewed local or IDE bridge boundary
  • Secure secret storage
  • Provider ownership verification
  • Provider adapter security review
  • Repository connection and installation verification
  • Sandboxed dispatch and execution transport

Workspace readiness

Separate readiness dimensions prevent capability overlap from becoming authority.

Deterministic routing analysis is available. Provider assignment, dispatch, provider execution, and repository execution remain separate unavailable controls.
Available

Deterministic routing analysis

Available: true · approval can enable execution: false

  • 3 deterministic capability-based analyses
  • 3 current recommendations
  • Persistence: false
  • Historical performance used: false
  • Provider assignment: unavailable
blocked platform

provider dispatch

Available: false · approval can enable: false

  • Authenticated workspace identity unavailable
  • Provider ownership unverified
  • Provider authentication unavailable
  • Secure secret storage unavailable
  • Repository not connected
  • Installation ownership unverified
  • Provider adapter not security-reviewed
  • Provider health not observed
  • Provider output not received
  • Durable storage unavailable
  • Verification incomplete
  • Dispatch transport disabled
blocked platform

provider execution

Available: false · approval can enable: false

  • Authenticated workspace identity unavailable
  • Provider ownership unverified
  • Provider authentication unavailable
  • Secure secret storage unavailable
  • Repository not connected
  • Installation ownership unverified
  • Provider adapter not security-reviewed
  • Provider health not observed
  • Provider output not received
  • Durable storage unavailable
  • Verification incomplete
  • Execution transport disabled
blocked platform

repository execution

Available: false · approval can enable: false

  • Authenticated workspace identity unavailable
  • Provider ownership unverified
  • Provider authentication unavailable
  • Secure secret storage unavailable
  • Repository not connected
  • Installation ownership unverified
  • Provider adapter not security-reviewed
  • Provider health not observed
  • Provider output not received
  • Durable storage unavailable
  • Verification incomplete
  • Repository verification and execution transports disabled

Revocation and kill-switch boundary

Approval cannot override workspace or provider controls.

Releasing a control requires complete reevaluation and never authenticates a provider, verifies ownership, or restarts an external session.

Revocation

Platform inactive · workspace inactive · provider 0 · connection 0

Kill switches

Platform inactive · workspace inactive · provider 0 · adapter 0

External effects

Provider request active: false · external provider session cancelled: false · release requires reevaluation: true

Capability inventory

Registry-owned capability coverage, not execution eligibility.

17 normalized capabilities are aggregated from provider definitions. None are live verified, routable, or dispatchable.
code-editingcodex, claude code, cursorcapability modeled · live verified false
code-generationcodex, claude code, cursorcapability modeled · live verified false
code-reviewcodex, claude code, cursorcapability modeled · live verified false
command-proposalcodex, claude codecapability modeled · live verified false
evidence-exportcodex, claude code, cursorcapability modeled · live verified false
human-in-the-loopcodex, claude code, cursorcapability modeled · live verified false
ide-assisted-workcursorcapability modeled · live verified false
long-running-task-supportcodex, claude codecapability modeled · live verified false
patch-generationcodex, claude code, cursorcapability modeled · live verified false
prompt-analysisclaude codecapability modeled · live verified false
refactoringcodex, claude code, cursorcapability modeled · live verified false
repository-analysiscodex, claude code, cursorcapability modeled · live verified false
security-review-assistanceclaude codecapability modeled · live verified false
structured-outputcodexcapability modeled · live verified false
test-execution-proposalcodex, claude codecapability modeled · live verified false
test-generationcodex, claude code, cursorcapability modeled · live verified false
work-record-exportcodex, claude code, cursorcapability modeled · live verified false

Future production requirements

Workspace provider relationships remain blocked from production use.

These are prerequisites, not configuration controls available in this private-beta preview.

Separate repository inventory

GitHub repository previews belong to the workspace without granting repository access.

Provider products and repository hosts remain separate. These three scenario-owned repository records are deterministic, non-persistent previews with no verified installation, ownership, permission, metadata, contents, webhook, write, or execution state.

GitHub · repository host

acme-payments/payment-webhook-service

Recorded preview

Secure Payment Webhook · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • app/api/payments/webhook.ts
  • tests/payment-webhook.test.ts

GitHub · repository host

acme-ai-support/refund-assistant-prompts

Recorded preview

Harden Risky Prompt · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • lib/prompts/refund-assistant.ts
  • prompts/refund-assistant-security.md

GitHub · repository host

acme-checkout/checkout-ui

Recorded preview

Investigate Failing Tests · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Active
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (3)
  • tests/checkout-confirmation.test.ts
  • app/checkout/confirmation.tsx
  • package.json

Task authority

3 deterministic capability packages

Workspace-owned previews only. Active packages: 0; external authority issued: false.

Start Control Flow

Route a deterministic task through recommendation, review, approval, and Ledger preview.

Explore AgentOS

Inspect agent fit, routing, workflows, Work Records, and comparison.

Review Work

Inspect simulated Review Runs, evidence, policy context, and approval state.

Open Ledger

Explore linked deterministic work, review, decision, and approval records.

View Analytics

Review derived demo metrics without production telemetry.

3Open Review RunsDeterministic demo summary
0Evaluator pending requirementsDeterministic demo summary
3Blocked / needs reviewDeterministic demo summary
10Recent Ledger recordsDeterministic demo summary
53Linked evidenceDeterministic demo summary
92%Human interventionDeterministic demo summary
75%Lifecycle completeDeterministic demo summary

Current canonical routing and control flow

Secure a payment webhook

The provider recommendation comes from the canonical Part 134 routing analysis. No provider was assigned or contacted, no task was dispatched, and no repository access was granted.
Journey statusHuman Approval / Human control

Complete the explicit human approval gate

Canonical recommended providerClaude Code

Recommendation only · no external agent call

Alternative provider candidatesCodex, Cursor

Capability support, not delegated execution

Recommendation statedeterministic recommendation

available for human review

Canonical routing referencerouting-analysis-secure-payment-webhook

Evaluated 2026-07-31T00:00:00.000Z

MergeGuard postureHIGH · merge after changes

A human chooses approve, request changes, or block before the flow can conclude.

Taskcomplete
Capabilitycomplete
Agentcomplete
Work Recordcomplete
Reviewcomplete
MergeGuardcomplete
Verificationcomplete
Approvalcurrent
Ledgerwaiting

Product readiness

Private-beta demo-ready

Demo-ready foundations remain separate from production workspace capabilities.

Available now

  • Deterministic routing
  • Review previews
  • Approval simulation
  • Agent Work Records
  • Ledger previews
  • Analytics previews

Not live

  • Workspace persistence
  • Production identity
  • GitHub write actions
  • Autonomous execution
  • Agent API calls
  • Production analytics
11 ready/demo-ready5 foundation-only4 not live

Workspace Attention Center

Human decisions, ordered by control urgency

Review deterministic evidence, control state, approval, and verification before a person chooses the next local preview action. Generic Platform Guidance: Human approval required by policy is evaluated separately from these browser-local request fixtures.

8 demo itemsLocal state onlyNot final authority
3ImmediateDerived demo count
3High urgencyDerived demo count
1Local approval request fixturesDerived demo count
2Verification issuesDerived demo count
2BlockedDerived demo count
1Evidence gapsDerived demo count
0In reviewDerived demo count
0AcknowledgedDerived demo count
Attention queue

Loading attention preview

Preparing deterministic attention items locally. No network request is made.

Recent Review Runs

Review, verification, and approval

Recent Ledger activity

Derived control records

Analytics snapshot

Derived control signals

Fixed demo data, not production telemetry.
Human intervention92%
Derived preview
Lifecycle completion75%
Derived preview
Evidence density88%
Derived preview

Recent workspace activity

Connected module events

  1. 01
    Secure a payment webhook

    Active deterministic demo task selected for controlled routing.

    Control Flow · active · persisted: false
    Open
  2. 02
    Legacy profile preview: GitHub Copilot

    Legacy deterministic profile preview; non-canonical and not an assignment.

    AgentOS · legacy non canonical · persisted: false
    Open
  3. 03
    Secure payment webhook replay handling

    Payment webhook changes are scoped to the webhook implementation and its matching test. Repository verification has not run; the approval requirement is satisfied.

    Review Runs · needs manual review · persisted: false
    Open
  4. 04
    Recorded browser-local payment approval request

    Historical/local request input only. Current authority is evaluated separately by the server-owned Approval Authority.

    Approval Center · browser local request · persisted: false
    Open
  5. 05
    Refund assistant prompt security review

    PromptForge identified injection and tool-boundary gaps and produced a safer draft rewrite.

    AI Work Ledger · needs review · persisted: false
    Open

Workspace capabilities

Your control center for AI software work.

Launch the guided private-beta Control Flow from a single operational workspace.

Surface AI work requiring approval, changes, verification, or blocking decisions.

Inspect recent safe Review Run summaries and derived Ledger activity.

Show deterministic AgentOS routing and supporting-agent context.

Summarize control risk, approvals, evidence, and lifecycle analytics.

Keep product readiness and production boundaries visible beside the work.

Control principles

A workspace that keeps its boundaries visible

01

All workspace data is deterministic demo data, derived preview, and non-persistent.

02

Generic Platform Guidance: Human approval remains required before AI software work is trusted, merged, or used.

03

No live agents, external calls, repo access, repository writes, GitHub posting, or automatic merge occurs.

04

Analytics is a fixed demo projection, not production telemetry or real customer usage.

05

Production identity, organizations, tenancy, billing, migrations, and workspace persistence are not live.