DESIGN REFERENCE · IMPLEMENTATION UNVERIFIED
Put a policy question
before credential use.
Explore the intended boundary between an agent’s proposed action, a scoped credential decision, and an external service.
- 01
Propose
Describe the intended service, connection, and scope.
- 02
Review
Determine whether the role and requested scope are permitted.
- 03
Exchange
A future integration would need to enforce the decision before credential delivery.
The design question
The reference proposes checking role, connection, and scope before an external credential exchange. That is a useful architecture question, but the marketing description does not prove an implemented integration.
What an implementation would need
- A real identity and credential provider integration.
- A verifiable mapping from the approved action to the credential scope.
- Failure handling, key custody, and evidence retention.
- Tests of the actual exchange and downstream execution boundary.
Evaluate the implemented building block
Use gove-zone if your immediate task is to evaluate a receipt-gated execution boundary. Treat credential-provider integration as separate work.
Explore the execution kernelSOURCE REFERENCES · 2026-09-08Original concept route