Private command infrastructure

Master Command Broker

A typed, allowlisted command-policy and receipt boundary for future Everything Dashboard operations while preserving each product owner’s authority.

Status: Source-only · in developmentNot available
Not available

Current source scope

What exists now.

  • A registered source-only catalogue and schema define five read-only identities covering broker, task, backup, filesystem findings and transport health.
  • Deterministic preview, confirmation and fixed owner routing are explicit source gates.
  • Idempotency, concurrency, timeout and ambiguity recovery are part of the provider-free source boundary.
  • Receipt and audit verification include rollback-intent proof without activating a live command path.

Explicit limits

Where it stops.

  • Live command execution is not authorised or available.
  • No provider adapter, service, Scheduler task, pipe, credential, production signer or trust, public UI or live owner adapter exists.
  • It never accepts raw shell, script text, executable paths, URLs, environment overrides or unregistered command names.
  • Activation requires later source acceptance and an explicit Master transaction.

No public access.

This entry exists to make current work visible without turning a private or unfinished project into a launch claim.