Signed runtime identity
Agent-scoped credentials, exact-body signing, timestamp freshness and replay-resistant nonces.
Verified controlNodra is built to enforce runtime authority, preserve evidence, contain affected agents, and require controlled recovery. This page separates controls we can demonstrate today from assurance we do not yet claim.
These statements are grounded in current implementation and regression tests, not future roadmap language.
Agent-scoped credentials, exact-body signing, timestamp freshness and replay-resistant nonces.
Verified controlExplicit resource:action permissions are enforced before consequential execution.
Verified controlWorkspace-scoped application logic and PostgreSQL row-level security are regression-tested.
Verified controlSecurity events are hash-linked and can be checked with the integrity verifier.
Verified controlIncident blast radius can quarantine the origin while preserving unrelated healthy agents.
Verified controlCustomer-origin credentials are revoked during containment and rotated during recovery.
Verified controlRecovery requires remediation evidence and authorized human approval before safe restart.
Verified controlCI includes SDK, OpenAPI, database, isolation, approval, delegation, containment and authority tests.
Verified controlNodra does not need to replace the customer's model or orchestration framework. The customer places Nodra authorization before the consequential side effect.
Use these documents during architecture and security review.
Nodra should not present the following as completed until independent evidence exists:
Start with one consequential workflow, prove authorization and evidence, then run a controlled containment and recovery exercise.