EnvoyMesh must protect the owner before it helps the network.
The most important rule is that an Envoy is not allowed to browse the owner's computer. It can only access explicitly approved data and capabilities.
A remote peer may send a malicious message that tries to convince the agent to reveal private information, ignore policy, or call unauthorized tools.
Mitigation:
A bug or compromised agent may try to read private files outside the shared vault.
Mitigation:
An attacker may pretend to be a trusted friend.
Mitigation:
An attacker may create many fake peers to appear trustworthy or overwhelm the node.
Mitigation:
The Envoy may share a raw document when a summary would have been enough.
Mitigation:
The Diplomat is the network-facing component. It handles libp2p connections, message parsing, peer identity, and rate limiting.
It should not have direct access to the private filesystem or model tools.
The Bond Engine makes authorization decisions. It converts a peer identity and request intent into an allow, deny, challenge, or approval-required decision.
It should be deterministic and testable.
The Brain performs local reasoning, summarization, and retrieval-augmented answering.
It should receive only approved context from the vault. It should not be able to make arbitrary outbound network calls.
Envoy Harness runs coding agents on your home node under the same Bond Engine and approval queue as EnvoyAI. Tool calls that exceed policy, touch sensitive paths, or run shell commands enqueue owner approvals on the home node before execution — Social desktop, Terminal, and paired EnvoyGo surface the same pending items. Harness does not bypass vault path safety or grant libp2p keys to external coding runtimes.
The Vault contains owner-approved shared data.
Only data inside the vault can be indexed or shared. Access to the vault should still be mediated by document-level policy.
Each request should be evaluated with:
Example operations:
metadata.readsummary.readsnippet.readfile.readtask.submitstate.syncExample sensitivity levels:
publicfriendstrustedprivateFor the first prototype, use conservative rules:
shared_vault/.Every meaningful exchange should create an audit event:
The audit log helps the owner understand what the Envoy did while they were offline.