Specify Work

Grant only the access the task needs.

Every agent uses a revocable identity, an explicit scope, and a complete audit trail.

Create workspace
Publishing gate ·Customer proofrunning
Codex · launch agentWorking on the launch narrative
Draft launch storycomplete
Verify customer quoterunning
Publish customer proofwaiting
Update launch checklistwaiting
Decision gatepublish.execute · heldexecution paused here
Decision packetPreparing impact preview
Assembling the boundaryEvidence and dependent runs remain inspectable.

Codex reaches a consequential action outside its current grant.

Trace identity → grant → policy → action.

CHAPTER 01

Identity before access

Human and agent clients act through attributable, revocable identities.

Claude CodeAgent identity · activeattributable
  • SourceWorkspace administrator
  • ActorClaude Code / agent
  • ScopeLaunch narrative · read
  • ConsequenceEvery request is tied to one revocable client

Inspect current state and evidence for each control.

Identity

People and agents act through attributable, revocable identities.

Current state
client-04 · active
Owner
Workspace administrator
Evidence
Available in audit history
Set up workspace access
Evidence modelActor · policy · source · timeControl pathIdentity → grant → policy → audit

Know what crossed the boundary.

Every delivery stays tied to an identity, a grant, a policy decision, and an audit event.

Review the trust model

Open the access history.

Start with the agent identity. Follow the grant, policy result, action, and audit event.

  1. 01Identity
  2. 02Grant
  3. 03Policy
  4. 04Audit