Connect an Agent. Follow its evidence.
Start with one repository, choose an Action transport, and inspect the first recorded or independently checked result. Raw prompts and credentials stay local.
No documentation matches “”. Try an Action transport, capability, or assurance state.
Authorize one repository with one command.
Create a Hosted project, run the command inside the agent repository, and approve once in the browser. Witnora saves a restricted connection, verifies the local path, then guides one real sandbox workflow into the first reviewable run.
Follow the quickstartnpx witnora@latest onboard --project your-project-idOne-time browser authorization
Restricted credential stored outside the repo
Synthetic receipt isolated from CURRENT
First real sandbox run reviewed separately
Move from synthetic evidence to one isolated sandbox action.
Declare one action, keep write and read credentials separate, run the Gateway and customer-operated Probe, then verify the packet against a separately pinned trust root.
Open the design-partner guideRaw prompts and credentials stay local
Single-use grant binds the exact action
Customer-operated read path checks outcome
Offline verifier checks signatures and limits
Answer one assurance question
Declare identity, capabilities, mandates, and controlled boundaries.
Read guide →02Is this release still trusted?Bind scope, run authoritative checks, and detect drift.
Read guide →03Should this action proceed?Evaluate policy, approval, execution grant, and observed outcome.
Read guide →04Who can prove the result?Inspect provenance, signatures, manifests, and evidence strength.
Read guide →Start
Produce the first local evidence, then connect one real action path.
→Hosted workspaceStartCreate a project, connect the CLI, and retain evidence safely.
→Design partner pilotStartReview who the pilot fits, what we verify, and when paid collaboration starts.
→Two-hour design-partner pathStartRun one privacy-preserving covered action path in an isolated sandbox.
→Integrate
Observe, enforce, and verify covered paths without product-specific logic.
→HTTP ActionsIntegrateSend one consequential sandbox Action through an authenticated HTTP endpoint.
→MCP Action integrationIntegrateExpose the same bounded sandbox Action as a local MCP tool.
→Customer-owned collectorIntegrateRun the recorder and gateway inside the customer trust boundary.
→Browser adapterIntegrateMediate browser actions through a credential-isolated customer adapter.
→Customer-operated outcome probeIntegrateObserve target state through a separate read-only customer boundary.
→GitHub ActionsIntegrateGate pull requests, releases, and nightly assurance runs.
→MCP and tool checksIntegrateEvaluate MCP servers and tool behavior with deterministic evidence.
→Private capability discoveryIntegrateDiscover likely Agent capabilities locally without uploading source code.
→Assure
Understand CURRENT, revalidation, suspension, expiry, and scope drift.
→Privacy-preserving action loopAssureKeep raw workflow data local while producing verifiable action evidence.
→Action assurance protocolAssureBind identity, mandate, execution, outcome, and evidence strength.
→Assurance WalletAssureControl sandbox payment authority without storing raw payment credentials.
→Runtime monitoringAssureRecord behavior sequences, policy findings, and incident evidence.
→Evidence schemaAssureValidate portable evidence bundles and artifact manifests.
→Evidence trust chainAssureDistinguish reported, recorded, enforced, and independently reviewed claims.
→Trust
Verify OIDC and SPIFFE principals without storing raw credentials.
→Threat modelTrustReview trust boundaries, attacker capabilities, and non-goals.
→What enforced meansTrustUse precise claims for mediated and non-bypassable action paths.
→Offline trust pinningTrustVerify packets against a root fingerprint obtained through a separate channel.
→Reference
Understand the engines, control plane, and evidence boundaries.
→Event and action envelopeReferenceEmit framework-neutral agent events and action claims.
→Policy specificationReferenceDeclare capability, risk, approval, and outcome requirements.
→Release governanceReferenceVerify provenance, compatibility, canaries, and release artifacts.
→Sandbox certificationReferenceCertify a safe adapter without touching production systems.
→Crash recovery and reconciliationReferenceRecover unknown dispatches through observation instead of repeating the write.
→Design-partner assurance v0.2ReferenceInspect the exact privacy, execution, observation, and review boundaries.
→