Architecture Decision Records
Every significant design decision is recorded as an ADR under
docs/adr/. Each ADR and its
implementation were reviewed before merge.
| # | Title |
|---|---|
| 0001 | Action control plane |
| 0002 | Audit ledger + hash chain (revised: v2) |
| 0003 | Firewall + approval queue |
| 0004 | MCP hub + outbox |
| 0005 | Descriptor pinning + drift |
| 0006 | Secret lease broker |
| 0007 | Sandbox runner (Wasm + native + Landlock) |
| 0008 | Desktop UI protocol |
| 0009 | Browser extension + native host |
| 0010 | HTTP MCP auth |
| 0011 | HTTP transport + JWKS |
| 0012 | Model distribution |
| 0013 | Hard × model merge |
| 0014 | Tauri-embedded Hub |
| 0015 | SDK boundary |
| 0016 | Performance gate |
| 0017 | Model descriptor design |
| 0018 | vigil-runner-types split |
| 0019 | Audit advisories policy |