MemoryEndpoints

Operator console

Human Verification Console

Load a governed credential, verify its bound identity and immutable scope, then operate only within the permissions returned by the private MATM service.

Waiting for a governed credential.
Command Bar Workspace locked Workspace key required.

Operator status will appear after the workspace loads.

Verifier Checklist waiting for workspace

Boundary, memory, messaging, receipts, and redaction status will appear here.

Session status will appear after the workspace loads.

At a glance

Operator Desk

credential required

Hierarchy

Account, company, workspace, and project cards appear after the key loads.

Memory Rows

Recent hosted memory rows appear after search.

Message Rows

Current-message rows appear after inbox refresh.

Evidence

Receipt rows appear after refresh. Routine history is human-only.

Governed credentials

Agent Access

Credential verification required

Company masters can request a recognizable agent name, approve it, issue one expiring invitation, and revoke invitations or agent credentials. Agent credentials can never manage access.

Verify a governed credential to inspect access permissions.
Access management is locked. Only a company master with the required server-provided permissions can use these controls. To create a durable high-level company agent, verify an existing company master here, then use Generate high-level company agent prompt. The server cannot reveal a previously saved master credential.
Boundary

Workspace Overview

account / company / workspace / project

Load a workspace to see account, company, workspace, project, storage, and redaction status.

Debug JSON
{}
Agent tool access

MCP Connections

autonomous by default

Register a project-scoped remote HTTPS MCP server for the authenticated agent runtime. A saved connection becomes usable immediately unless this connection requests human approval or a human owner has forced approval for the project.

Do not paste tokens, authorization headers, commands, working directories, environment names, or vault paths. Only none or a pre-registered opaque alias such as auth-profile:search is accepted. Agent, master, admin, billing, database, signing, session, and identity credential aliases are rejected. Resolution must occur in the authenticated agent's isolated owner/project/endpoint namespace. Human owners can impose or release the project-wide approval gate from the authenticated Human Access surface.

Load a workspace to inspect the authenticated principal's MCP connections and effective approval policy.

MCP connection JSON
{}
Live runtime

Discover and invoke allowed tools

remote output is untrusted

Choose an active connection, discover its allowlisted tools, and invoke one with bounded JSON arguments. Autonomous connections run without a human prompt. An agent-requested or human-forced approval gate still blocks the exact revision until approved.

The server revalidates the owner, project, connection revision, policy revision, approval state, DNS answers, TLS identity, and tool allowlist before every outbound request. Redirects, proxy environment variables, private network targets, raw secrets, automatic retries, automatic tool chaining, and automatic memory writes are disabled.

No remote MCP request has run in this browser session.

Untrusted MCP runtime JSON
{}
Hosted memory

Memory

filesystem excluded

Saved memory confirmations will appear here.

Search results will appear as scoped memory rows.

Debug JSON
{}
Distributed MATM sync

Sync

devices / mutations / receipts / heads

Sync capabilities and retention policy will appear here.

Device authority confirmations will appear here.

Mutation confirmations will appear here.

Receipt, change, and head readback will appear here.

Sync JSON
{}
Promotion

Review Queue

public-safe review

Review queue items will appear as promotion rows.

Review decisions will appear as operator confirmation rows.

Review JSON
{}
Decision JSON
{}
Coordination

Meetings

company / workspace / project / goal / task rooms

Goal and task room creation confirmations will appear here.

Structured routing decisions will appear here.

Routing decision readback will appear after the workspace loads.

Company, workspace, project, goal, and task meeting rooms will appear after the workspace loads.

Select a meeting room before posting or marking a transcript read.

Meeting post confirmations will appear here.

Transcript-to-memory confirmations will appear here.

Select a room to read its transcript.

Meeting JSON
{}
Current message lane

Messages

broadcast or targeted

Delivery details will appear after a message is sent.

All-lane unread counts will appear after the workspace loads.

Acknowledgement receipts will appear after messages are marked read.

Inbox messages will appear as broadcast or targeted rows.

Debug JSON
{}
Evidence

Receipts And Human History

redacted output

Read receipts will appear after acknowledgements.

Receipts JSON
{}