Trust boundary

The open-source trust layer and the managed control plane do different jobs.

MandateOS is easier to evaluate when the boundary is explicit. The public packages handle local host integration and runtime enforcement. The managed control plane handles shared operator workflows, approvals, workspace administration, and retained evidence.

Open-source trust layer

What runs close to the host

  • Installer CLIs and package entrypoints
  • Local MCP registration and host hook wiring
  • Runtime request path into MandateOS
  • Inspectability through the public repo and packages
Managed control plane

What operators use centrally

  • Workspaces and operator access
  • Approval inbox and escalation review
  • Retained audit history and evidence export
  • Shared operations across teams and repos
Evidence boundary

What teams can verify afterward

  • Signed receipts and execution grants
  • Approval events attached to the request path
  • Audit chain verification and retained history
  • Public package surface plus operator-visible outcomes
How the boundary works
Agent host (Codex, Cursor, Claude Code, OpenClaw)
MandateOS runtime checks
Operator review, receipts, and audit evidence