Architecture

A control plane agents cannot rewrite.

Waymark separates intent, privileged execution, and operator experience into explicit layers. Module direction and runtime isolation reinforce the same boundary.

Operator experience

Waymark Studio

Native SwiftUI mission control for work, agents, evidence, setup, and approvals.

↓ requests · ↑ safe state
Privileged boundary

Waymark Broker

Owns credentials, git, process execution, network writes, policy gates, persistence, evidence, and recovery.

↓ bounded capabilities · ↑ typed results
Agent-facing foundation

Waymark Core

Pure models for intent, plans, scope, validation, decisions, and Tier-A-safe summaries.

Defense in depth

One boundary, reinforced four ways.

01

Compile-time

Core cannot reference Broker executors, credentials, UI, process APIs, or network clients.

02

Runtime

Agent harnesses launch inside OS-enforced sandboxes with a rebuilt, allowlisted environment.

03

Workspace

Managed worktrees and RepoSeatbelt place active work and recovery on separate capability paths.

04

Evidence

Safe durable records exclude raw prompts, code, diffs, credentials, and command output.

Data boundary

Useful history without a source-code exhaust trail.

Tier A · Durable

Safe operational facts

Identifiers, hashes, scopes, verdicts, counts, timings, policy versions, and bounded summaries.

Tier B · Local

Sensitive working material

Source, diffs, prompts, transcripts, screenshots, command output, credentials, and raw artifacts.

Private preview

Help shape the safer way to ship with agents.

Join the Studio waitlist for product progress, early previews, and launch access.

Join the waitlist