← Features

Control & Governance

PartialGovern

Separate the ability to reason from the authority to create real effects.

TL;DR

Primitive already has approvals and authority rechecks for agent writes. Control extends that into leases, permits, boot receipts, gateways, kernels, revocation and escalation for recursive orchestration.

ELI5

An AI can think about many things, but having an idea is not the same as having the key to change something. Primitive keeps the keys separate and records who was allowed to use them.

Synthesis

Governance is enforced at consequential boundaries, not by making every internal step bureaucratic. Existing Workspace approvals are implemented. The more general recursive permit/gateway/kernel model is formalized in Primitive Control and is being integrated as the scalable authority system.

Surfaces
Where you meet it
ApprovalsControlGatewayInbox
Primitives
What it is made from
authoritypermitleaseboot-receiptgatewaykernelrevocation
Technical detail

Implemented approvals

Workspace supports human-approved agent writes with an Approvals UI and authority rechecks.

Permit chain

The HOLARCHY programme defines signed, chained work permits whose scope cannot exceed the parent permit. Scope can include repositories, branches, paths, budgets, expiry and child caps.

Boot and gateway

A child begins locked and proves its context/tool load through a boot receipt. The gateway is intended to check permit validity, boot receipt and path scope before consequential actions.

Revocation and escalation

Parent revocation can fence a subtree. Heartbeats and deadlines provide a basis for detecting stalled work and escalating rather than silently blocking.

Reference / evidence

Where this description comes from

These pointers are the authority behind the status and technical description. If implementation and documentation disagree, the canonical implementation or Control contract wins and this page should be corrected.