Control / The Operator Surface

See the state.Follow the receipt.Intervene through governance.

Control gives operators one place to review supported execution state, decision outcomes, receipts, and causal lineage. It can initiate supported governed workflows; Runtime alone decides whether an effect is authorized.

The operating picture

Know what happened. Know what to inspect next.

Control organizes the evidence an operator needs to move from visible state to the decision and recorded cause behind it.

01

System state

Review supported execution state, failures, and blocked actions without mistaking the interface for authority.

02

Decisions

Read Runtime outcomes — allowed, denied, or governed review — in the same operator context.

03

Receipts

Move from a decision outcome to its supporting receipt and evidence references.

Receipt to lineage

Follow the evidence back to cause.

Control displays recorded receipt and lineage relationships. It does not infer missing links or turn interface narrative into proof.

  1. 01Runtime + Cortex

    State surfaced

    Supported state appears with its recorded source and status.

  2. 02Runtime

    Decision located

    The decision outcome anchors the operator review.

  3. 03Runtime evidence

    Receipt inspected

    The supporting receipt remains primary over summaries or UI narrative.

  4. 04Cortex

    Lineage followed

    Recorded predecessor and correlation links show how the state evolved.

Governed intervention

Initiate action without creating a side door.

A supported operator workflow begins in Control, crosses the same governed boundary as any other actor, and cannot produce an effect until Runtime authorizes it.

Control initiates. Runtime decides. Receipts remain the record.
  1. 01OperatorInitiates a supported workflow from Control.
  2. 02Governed entryCarries the intent through the MCP Gateway path.
  3. 03RuntimeEvaluates authority before any effect can occur.
  4. 04ControlReturns the outcome and supporting receipt state for review.
Authority boundary

Operational visibility is not execution authority.

Control owns
  • Supported execution-state visibility
  • Decision, denial, failure, and blocked-action review
  • Receipt and evidence inspection
  • Recorded causal-lineage navigation
  • Governed workflow initiation
Control never owns
  • Policy evaluation
  • Decision Receipt issuance
  • Execution authority
  • Canonical truth
  • Direct ledger writes
Inspect the boundary

See the surface. Trace the authority.

The public Control demo is a labeled static preview. Runtime remains the place to inspect how authorization governs effects.