Safety by architecture

Agents can be powerful without being privileged.

Waymark’s safety model limits what an agent can reach, makes sensitive actions independently enforceable, and keeps recovery outside the agent’s control.

Core

Agent-facing intent

Plans, scoped context, bounded requests, and safe summaries.

Compile-time boundaryAgents cannot cross it

Broker

Privileged execution

Credentials, git, processes, network writes, evidence, and recovery.

Implemented principles

Security claims tied to product boundaries.

These are the architectural guarantees Waymark is being built and tested around—not generic trust language.

Credentials stay outside the agent

Sensitive git, infrastructure, backup, and delivery operations are executed by native Broker code rather than the coding agent.

The boundary is structural

The agent-facing Core module cannot import the Broker’s credential stores or privileged executors.

Every run is isolated

Agent processes operate inside managed worktrees without access to repository internals, other worktrees, or recovery stores.

Context is treated as untrusted

Repository instructions, prompts, local documents, and artifacts pass provenance and content-bound policy checks before launch.

Durable records stay safe

Evidence stores bounded identities, hashes, verdicts, counts, timings, and summaries. Source, diffs, transcripts, output, and secrets remain local.

Ambiguity fails closed

Stale proof, unsafe scope, credential leakage, uncertain production identity, or failed cleanup stops the workflow.

No prompt can waive the safety floor.

Automatic delivery can remove a routine human pause. It cannot remove immutable artifacts, exact target proof, staging and rollback evidence, scoped commands, health verification, or recovery coordination.

Private preview

Help shape the safer way to ship with agents.

Join the Studio waitlist for product progress, early previews, and launch access.

Join the waitlist