Saphan StudioDocs
Concepts

What "shipped" means on this site

The word is used in one sense here, and this page is that sense: present tense means shipped and exercised, and a control that ships opt-in is never described as on.

Present tense on this site means shipped and exercised — not designed, not planned, not on a board. This page is that promise written down, so that every other page can be read against it.

What present tense covers

  • the record and its projections;
  • signed gates and proof-of-done merges;
  • certificate-based machine admission;
  • slots and seats with isolated profiles, locally and over SSH;
  • multi-backend actors, including local models and deterministic tools;
  • capped standing rules;
  • the per-run cost ledger with billing classes, and the pricing registry;
  • five surfaces — the command-line interface, the web console, the client API and gateway, the read-only projection an assistant reads through, and the editor extension — with the owner's inbox among the console's screens;
  • refusals as recorded data;
  • operating-system confinement with kernel read-deny for credentials, including kernel-enforced confinement for runs dispatched over SSH against a measured per-machine capability;
  • a browser first-run wizard that configures a machine with no owner (first run);
  • system packages and a macOS installer that deliver the machine payload — three binaries: the control-plane CLI, the runner-side agent and the console.

Shipped is not the same as exercised everywhere. Which backend has been run on which platform, and what is therefore not proven, is one table: supported agents, runtimes and integrations.

The discipline this page exists to state

A control that ships opt-in is described as shipped and opt-in, never as on. That cuts both ways, and it is the reason a page here will sometimes tell you less than you hoped.

The standing example is egress control. It ships: a run started with saphan run --egress-policy reaches the network only through a per-run proxy that judges every destination against a policy you author, and the confinement walls off every other road. And it is per run — a dispatch that does not ask for a policy is not judged by one. ⇒ Until every dispatch in your fleet asks, egress control at your network boundary remains yours (where this stands today).

Making it the default is an owner's act that nobody has taken, and this site will not describe it as taken.

What this site does not carry

A roadmap. Work that is designed, ordered or in development is not listed here, and a page that named it would be inferring a promise from a design stream. Where a capability exists but has not been exercised, the page that owns it says so in its own row; where one does not exist, the page says that instead.

⇒ If you need to know whether something specific is coming, ask — the answer is a conversation, not a page that ages badly.

On this page