Skip to main content
ControlFrame

Five role views · swipe to explore

For security, identity, cloud, and platform operators

Collect proof inside the boundary you already trust.

Approved legacy collection paths can keep target credentials and collection activity inside the configured runtime. The separately released Runner v2 handshake is verify-only: it proves bounded appliance contact and package identity, but grants no browser, target, credential, artifact, or evidence authority.

Your operating lane

Make evidence collection an observable systems path.

The operator lane begins with an approved target and a bounded job. The runner receives only the authority required for that collection, records its operating events, and returns an artifact that can be reviewed without exposing the target credential to the evidence portal.

  1. 01

    Enroll

    Bind an execution-capable collector to the approved environment

    For an approved legacy collection path, establish the runtime, identity, credential source, target allowlist, and artifact destination before collection is admitted.

    Record carried forward: runner identity and environment binding

  2. 02

    Admit

    Accept only declared work on an activated path

    An execution-capable collector job names the project, control, target, procedure, deadline, and expected artifact contract; missing or invalid authority is refused instead of silently downgraded.

    Record carried forward: signed scope and evidence contract

  3. 03

    Execute

    Run only through an approved execution protocol

    Where an approved legacy path is activated, collection uses the configured organization credential and network path while operating state remains observable. Runner v2 verification does not execute this step.

    Record carried forward: job events and source-bound artifact

  4. 04

    Promote

    Return proof, not runtime authority

    The governed artifact carries its version, checksum, source context, sensitivity posture, and custody trail into review; the target credential does not travel with it.

    Record carried forward: artifact custody and explicit outcome

Agent contribution

Automate preparation, never accountability.

  • Select the framework-specific procedure and expected artifact contract for a declared target.
  • Operate only through approved tools and refuse work outside the signed scope or target policy.
  • Record source observations, structured checks, and artifact metadata for downstream review.
  • Explain collection failure as a named unavailable state instead of substituting unrelated data.

Named human authority

Keep the consequential decisions attributable.

  • Approve environments, target allowlists, credential custody, egress, retention, and escalation paths.
  • Issue, rotate, revoke, and retire organization credentials and runner appliance tokens through authorized roles.
  • Decide whether the collected artifact is sufficient, sensitive, stale, or eligible for release.
  • Activate execution only after the configured deployment passes its agreed security and acceptance gates.

Role-specific proof surfaces

Inspect the implemented surface behind each part of the role.

Each link opens a distinct, labeled public reference surface. The surfaces do not share browser state or represent one continuous tenant run. Together they demonstrate implemented record shapes and review logic; none is an activated customer environment, an auditor opinion, or a certification.

  1. 01 · Boundary

    Review private execution

    Inspect identity, target, secret, network, and artifact-custody boundaries.

    Open runner trust
  2. 02 · System

    Inspect the architecture

    Trace how the control plane, customer runtime, repository, and release gate interact.

    Open architecture
  3. 03 · Run

    Replay a synthetic collection

    Follow the declared plan, browser observations, checks, and captured artifact.

    Open run theater
  4. 04 · Proof

    Inspect the governed output

    See how source context, integrity metadata, decisions, and release eligibility remain attached.

    Open the package

Design the collection path before granting it authority.

Bring the target class, network constraints, credential owner, evidence contract, and retention requirement. We will map the private-runner boundary and its activation evidence.

Request a role-based walkthrough
Private evidence collection for operators | ControlFrame