Defined term / workflow

Trust boundary

One of the eight named boundaries (tb-1 to tb-8) across which signed, schema-validated calls flow.

Definition

ADR 0004 names the eight trust boundaries — browser, web plane, agent kernel, compute plane, storage, external providers, share/export, admin plane. Every cross-boundary call is signed and Zod-validated. On-call rotation routes per boundary.

Related doc

Architecture Overview

The shape of the SimPilot platform: one agent kernel, a typed protocol, governed compute, and durable rollout records.

Open doc

Related doc

Security & Trust Boundaries

Eight named trust boundaries, four data classifications, deny-by-default egress, and the declassifier projection contract.

Open doc