THE ZORRO PLATFORM
One loop.
It has to close.
Four modules can be drawn. A loop has to close. Here is every link, what is actually behind it, and where it breaks today.
Ownership · Authentication · Delegation
Who is behind the action?
Start with the person or service identity, its owner and the permissions it actually holds.
Platform in development. This interactive map explains the architecture; it does not represent a connected environment. Live capabilities and source coverage are reported in the workspace.
A drawing can skip a link.
A loop cannot.
A module page can describe a capability whose upstream link has no input and whose downstream link has no effector. So each link states its own status.
THE LOOP
We own the middle. Graph, enrich and analyze are built, and the remediation lifecycle is stricter than the category’s: a model may propose, only a person approves, and closure is re-observed rather than declared. We are missing both ends. Nothing is ingested agentlessly today, and execution has exactly one effector. A loop broken at both ends does not close, so this page says where it breaks instead of drawing it shut.
Ingestmissing
Registry, SDK, sealed credentials, sync-run recording, tenant isolation and a fail-closed provider contract are built. The upstream API clients are not.
All ten connector kinds resolve to one stub. Without a credential it reports NOT CONNECTED; with one it reports UNAVAILABLE and makes no upstream call. The GitHub webhook and the edge are the only live inbound paths, and this is the binding constraint on everything downstream.
Graphreal
Event-to-graph projection, batch projector upserts, direct SQL entity reads and path queries over one workforce graph.
Only ever as populated as ingest allows. Today that is GitHub and edge telemetry.
Enrichpartial
Metadata-only classification that reads zero bytes of file content, AI entity classification, entitlement resolution.
Real functions over a thin graph. There is no sensitivity signal from enterprise drives, because none are ingested.
Analyzereal
Exposure scanning for oversharing, public links, external domains, stale shares and AI-reachable assets; identity posture detection; rollout simulation; path queries; time-based detectors on a scheduled sweep.
The engines are genuinely built, and they are answering about an under-fed graph. They say so themselves: the rollout simulator returns insufficient_data rather than safe_to_deploy when the graph is empty.
Profilepartial
Per-entity AI exposure profiles and identity profiles, with reach, principals and MCP surface resolved from the graph.
Profiles exist as contracts and as code. Behavioral baselines and peer comparison do not.
Remediatesplit
Propose, approve, execute, verify. A model may propose; a model subject can never approve. Closure is re-observed against the revocation log and checked for a newer record that re-authorized the session, and it records claimed or unverifiable rather than ever overstating verified.
One effector. Execute revokes a session and nothing else. Marking a data finding for re-observation is not revoking a share, and marking an entitlement recommendation applied is not changing an entitlement. There is no revoke-share, disable-account or kill-token effector, because there is no connector to act through.
THE ASSISTANT LAYER, OVER ALL OF IT
From the big picture
to the detail that matters.
One investigation should keep its context as you move between an agent, a resource and a decision. Each surface names the links it serves and has its own page.
01 / AI & AGENTS
Understand the agent behind the action.
An inventory becomes useful when it explains ownership, available tools and the boundary each agent is allowed to cross.
IN THE LOOP: ANALYZE · PROFILE
AI & agents ↗02 / DATA EXPOSURE
Put sensitive access in context.
A possible exposure and a recorded access are different facts. The interface should make that distinction impossible to miss.
IN THE LOOP: ENRICH · ANALYZE
Data exposure ↗03 / IDENTITY & ACCESS
Make delegated authority visible.
Trace the relationship between the person, the service account, the agent and the policy governing the action. Compare what was granted against what is used.
IN THE LOOP: ENRICH · ANALYZE · PROFILE
Identity & access ↗04 / THREAT CENTER
Give every next step a reason.
Start with a finding, inspect its evidence and decide what happens next. Investigation and authorization stay distinct.
IN THE LOOP: ANALYZE · REMEDIATE
Threat center ↗05 / THE ASSISTANT
Ask in language, read the evidence.
The investigator answers over the sources you are allowed to read and shows the dated path through the graph. A model may propose; a person approves.
IN THE LOOP: OVER ALL OF IT
The assistant ↗The moment that matters
is before the action.
The loop above is the workforce plane, and it runs after the fact. This is the execution plane, and it runs inside the agent loop. Four steps, one property: authority only ever goes down. The cloud is never on the path of a tool call.
Derive the origin sets.
Allowed hosts, packages, paths and commands are read from the repository’s committed HEAD: lockfiles, remotes, scripts. Widening them takes a commit, which is a human act.
Attenuate on ingress.
When untrusted content arrives, whether a PR title, a fetched page or a tool result, the session’s authority is lowered at that moment, not when a model interprets it.
Decide by membership.
Before a tool runs, the action’s parameters are checked against the origin sets. It is a finite membership test with no model, no score and no threshold. p50 decision latency is measured in microseconds.
Sign the answer.
Every allow and every denial emits evidence. A session can be sealed into a signed record of what was authorized, what ran, what it touched and where it went.
BUILT TODAY
- Edge hook for five harnesses
- Monotone authority ledger
- Origin sets derived from HEAD
- Lookalike detection on egress
- MCP proxy with tool-definition pins
- Credential broker (macOS measured)
- Kernel sensor (Linux eBPF)
- Signed session attestation
- Remote revocation / kill switch
- GitHub ingestion by webhook
- Connector framework, no upstream clients
At the edge, what is not built is said just as plainly: the kernel view is Linux only today and the macOS and Windows collectors report UNAVAILABLE rather than guessing, the credential broker is measured on macOS, and no detection rate is claimed before a benchmark run. See the security page.
START WITH ONE QUESTION
Define your first
use case.
Pick a documented incident that matches your
risk and map it to a capability.