What runs close to the host
- Installer CLIs and package entrypoints
- Local MCP registration and host hook wiring
- Runtime request path into MandateOS
- Inspectability through the public repo and packages
Trust boundary
MandateOS is easier to evaluate when the boundary is explicit. The public packages handle local host integration and runtime enforcement. The managed control plane handles shared operator workflows, approvals, workspace administration, and retained evidence.