Who this document is for
Two readers.
Two readers. An evaluator deciding whether to let AI coding agents run unattended on machines they own — sections 1 through 3 and 11. An administrator or security engineer who needs to know which mechanisms are actually in play, what the defaults are, and what to configure — sections 4 through 10, section 12 (the operational runbook) and section 13 (worked examples).
Section 11, Documented limits, lists what this system does not protect against. It is not an afterthought. A security document without one is marketing.
There is no source code in this document. There are named mechanisms, algorithms, defaults and configuration keys, because those are what you need to evaluate the claims — and section 13 contains worked examples of the ceremonies and enrollment flows, using the real commands, so you can see how the controls are actually operated rather than take our word that they exist.