A rule the agent must remember
CLAUDE.md says to confirm destructive actions. The production-debug credential still owns the database.
Harnexis starts with represented GitHub pull-request, review, and CI evidence. It gives leaders and operating teams one accountable next decision, the exact proof behind it, and a signed artifact they can hand to an auditor or customer. Unknown AI use and missing release lineage stay visible.
A named integration is not a shipping claim. Open any card for its current scope and boundary. Available now means deployed in a provisioned workspace; planned means help shape it, not depend on it yet.
GitHub is the current evidence path. Every other named provider is explicitly classified beside it.
Loading current integration boundaries.
Coding assistants now invoke subagents, open pull requests, diagnose failures, and recommend production changes. Usage dashboards show activity. Prompt files describe intent. Neither tells an operating team what to do next or proves what its decisions changed.
See selected GitHub work by repository, observed identity, runtime declaration, and action class without turning a pull request into an unsupported authorship claim.
Turn observed evidence into a scoped action with a named owner, expected effect, safety boundary, and measurement window.
Keep expected impact separate from observed results, including verified quality, evidence gaps, demotions, and protection outcomes.
The first screen is deliberately plain. Underneath it, Harnexis preserves the append-only records, policy versions, provenance, verified outcomes, and authority observations technical teams need to trust the conclusion.
Import read-only GitHub pull-request, review, and CI evidence. No new approval inbox is required to see the first posture.
Show where AI work appears, what evidence is missing, and which scoped action a named operating team should consider next.
Define an exact repository, branch, path, exclusion, and size boundary. Harnexis verifies which changes match from exact file evidence before any separate policy decision.
Compare the expected effect with observed post-decision evidence. Every simplified statement resolves to technical records.
Instructions tell an agent what it should do. They do not remove what its credential can do. Harnexis makes that gap visible, helps prepare a customer-owned least-privilege correction, and records how and when the resulting boundary was observed.
CLAUDE.md says to confirm destructive actions. The production-debug credential still owns the database.
The accepted design has the customer apply least privilege, then Harnexis independently read effective authority. That provider path is planned, not deployed today.
Scoped assurance, never magic: every claim names the agent identity, action class, environment, enforcement points, observation time, expiry, maximum drift-detection interval, and evidence strength. Point-in-time evidence does not claim continuous or execution-time protection. Unknown credentials or bypass paths produce a critical finding — never a green badge.
Technical teams can inspect the underlying tier, policy threshold, action class, blast radius, verification record, demotion trigger, and authority boundary. Executives do not need to learn those objects to understand the decision.
The default for every new agent and action class. Humans see and approve each proposal; every verdict feeds the ledger.
The agent acts; humans review a policy-defined sample. Verified outcomes keep the trust score honest between checks.
Destination state: unsupervised inside an explicit blast radius, with a verified failure triggering coordinated demotion. Automatic enforcement and demotion are planned.
See where enrolled AI work appears, what material evidence gaps remain, which operating team owns the next decision, and what prior decisions changed.
Move from a noisy estate to a concrete action with scope, expected effect, safety boundary, measurement window, and technical evidence.
Prompt rules receive no security credit. Inspect which destructive capabilities remain available, how strong the latest evidence is, when it expires, and what identities are uncovered.
Follow a simplified statement back to the action, human verdict, policy version, provenance, verified outcome, and authority observation that support it.
Claude Code, Codex, OpenCode, service identities, and subagents create one operating problem even when durable child identity is unavailable.
A circuit breaker protects the next action. It cannot restore a deleted database; destructive authority must be removed at the enforcement point before an incident.
A decision should name its owner and expected effect, then return with observed quality, rework, protection outcome, and an honest evidence boundary.
Choose the review you are preparing for across internal oversight, NIST AI governance, secure AI development, EU AI Act, or EU Cyber Resilience Act evidence packs. See what current evidence supports, what remains, and the next action—then share the exact result as PDF, HTML, or JSON.
The report reuses repository scope, ownership, human decisions, outcomes, coverage gaps, retention policy, retrieval manifests, and canonical references already represented in Harnexis.
No hidden compliance score. Every unanswered question names what remains and the next evidence action an accountable team can take.
Give a reviewer a deterministic PDF, use standalone HTML for searchable inspection, or send versioned JSON into a GRC workflow. When integrity matters, create a signed HTML/JSON package they can return and verify.
Confirm the customer-approved minimum period, inspect represented coverage, and run a bounded retrieval check. Versioned readiness packs reuse that proof without turning it into a legal conclusion.
Need SOC 2, ISO/IEC 42001 or 27001, DORA, NIS2, FedRAMP 20x, or another review? Request a maintained mapping; availability, licensing, scope, and price are confirmed before commitment. Package verification proves signer and file integrity, not evidence truth or completeness. Harnexis does not certify compliance, provide legal advice, determine framework applicability, or replace an auditor.
Trust, computed — not vibes.
Connect a bounded scope, see what Harnexis can support with evidence, and expand only when continuous observation or stronger controls are useful. There are no separate charges for transient agents, subagents, tokens, evidence records, or viewers.
A unique contributor who committed to a connected private repository during the preceding 90 days. It measures the engineering scope Harnexis observes; it is not a login seat. Repository bands keep ingestion predictable.
See your first evidence-backed operating brief before committing to continuous observation.
Continuous visibility and prioritized action for one operating team.
A contracted rollout for multi-team decisions, safeguards, and measured follow-through.
Organization-scale evidence, deployment, retention, compliance, and support.
Current customer access is provisioned. Published prices are packaging anchors, not maturity claims. Assessment and Team use the current GitHub-centered path. Business, Enterprise, and proof engagements identify included canonical maturity entries and any separately accepted planned work in the statement of work.
The read-only import shows what selected GitHub evidence represents, which review and CI outcomes exist, and where the strongest gaps remain. One GitHub Actions-to-Fly release-lineage path, its offline release package, and its bounded in-toto interoperability proof are Early access; human-credential provenance and enforcement remain explicit planned proof paths.
Prospect and design-partner inquiries · [email protected]