The kernel enforces it now
intentd just moved into the kernel. It now runs as the guest kernel inside every Agent Substrate microVM, and every agent gets bound to its declared intent the moment the sandbox boots, through a standard OCI hook. From there, every file, exec, and descriptor call gets checked from inside the kernel itself, not by some sidecar parked next to the agent that a compromised one could just walk around. 787 nanoseconds per hooked call. That’s the whole cost of closing that gap.
The boundary survives suspend, resume, and revoke
The rest of an agent’s life just got the same treatment. Suspend it, resume it in under a second, and its intent gets rechecked against live policy on the way back up, never trusted off the old snapshot. Come back from a stale checkpoint and you don’t get to keep permissions that were pulled while you were parked. Revocation is the same idea for agents that never stopped running: one write pulls authority from every bound task, instantly, no restart, no redeploy. Armed mode keeps it honest. No kernel module, no workload.



