Five jobs customers actually bring, each as a recipe with four
ingredients: the code the agent writes; the profile, a grant (permission for
a run's code to call listed routes of one API) stored under a name, exactly as the daemon's
grants file spells it; the floor, the weakest isolation tier (how
strong the wall around a run is) the run accepts; and the provider that fits,
the backend that runs the code. Every recipe ends with three calls it must refuse, because
a recipe is defined as much by what it turns away as by its happy path.
01
Pick a job
Each card's profile is in the format PLIMSOLL_GRANTS_FILE loads. The
caller sends only the profile's name; nothing in these files can be changed by a
request. The first recipe is code mode: instead of calling one tool per step,
the agent writes a short program that calls the API, and that program runs in a
sandbox.
02
The same gate for every recipe
The ingredients differ; what has to be proved before launch does not. Check it
against the customer's deployment, not a local demo.