intentd
Objective runtime
Tracks each objective, its lineage and the authority it grants, and binds agent workloads to it before they start. Runs today on Google Agent Substrate.
Agents now run for hours, not seconds.
Intent Container binds each agent task to the objective that authorized it, and enforces that authority on files, processes and network calls, from the request path down to the kernel.
Agents now work for hours across shells, files, APIs and other agents. Their access is granted once, at the start, and stays in place long after the task has moved on. No system today lets you control what an agent does over that whole horizon.
Four controls applied to every task, from the first process it starts to the last.
Every process the task starts inherits the objective's authority, including child processes and threads.
Checks run on file access, program launch, network connections and IPC, not only on API calls.
Change an objective's authority while the task runs. Anything outside it fails closed from the next check.
Each allow and deny is tied to the objective and the version of its authority that produced it.
Architecture
intentd turns an objective into authority. KAP and iVisor enforce it where the agent runs.
Objective runtime
Tracks each objective, its lineage and the authority it grants, and binds agent workloads to it before they start. Runs today on Google Agent Substrate.
Kernel enforcement
A Linux kernel subsystem for objective-scoped authority. Intent Lineage Groups are its core object, the kernel's security hooks enforce it, and securityfs is its control plane.
No kernel change
A userspace application kernel that applies the same checks where you can't change the kernel. Experimental.
Try it
Intent enforcement through OpenShell middleware, with no change to the agent.
intentd runs on Substrate and binds each Actor to its objective.
Intent Container for agents on Bedrock.
Run KAP in a supported kernel, or iVisor where you can't change the kernel.
Running agents somewhere else? Talk to us.
Join the teams shipping safer, compliant AI agent deployments. White-glove onboarding for the first 50 design partners.