Can the agent reach the effect directly?
The cell confines agent processes and routes supported effects through a controlled door. Each workflow still needs its own route map and tests.
For security & risk
Cippax is designed so a model’s output is a proposal, not an authorization. A review should follow the action from agent to approval to execution—and test what happens when any required piece fails.
Prototype evidence is not a production certification
A reviewable boundary
For every supported workflow, these checks matter more than a general promise that an agent will behave.
The cell confines agent processes and routes supported effects through a controlled door. Each workflow still needs its own route map and tests.
An enrolled person signs a request with a passkey. The execution path checks the signed request against the action it will perform.
The approved action is consumed once, with a durable precommit before the effect. A changed or repeated request should be refused.
Audit failure blocks an effect. The separate witness withholds new leases when its checks fail; after the current lease expires, the gate closes.
Stated limits
A credible control review includes what the current prototype cannot establish.
Hostile root on the cellis outside the current security claim.
Model identity and weight claimsdo not prove which weights actually executed on the separate model host.
Edge-served approval codeis still part of the trust story; a native approver is planned to narrow that dependency.
Installed workflow coveragemust be demonstrated path by path, not assumed from a passing component test.
Where this stands: The working prototype has conformance tests and signed artifacts. A customer-facing verification report and supported deployment contract are still in development. Regulated workflows also need a review of hosting, data handling, and provider agreements before sensitive data enters scope.
Review a real workflow