ARMORIQ
// Product / Intent Container

Agents now run for hours, not seconds.

Isolate every agent objective at the system layer.

Intent Container binds each agent task to the objective that authorized it, and enforces that authority on files, processes and network calls, from the request path down to the kernel.

See the architecture
// The Problem

Long-running agents drift. Nothing below the app holds them to the plan.

Agents now work for hours across shells, files, APIs and other agents. Their access is granted once, at the start, and stays in place long after the task has moved on. No system today lets you control what an agent does over that whole horizon.

// Without system-level containment
  1. 01 /A task keeps access it no longer needs
  2. 02 /Injected instructions run with the agent's full permissions
  3. 03 /File writes, process launches and local sockets never pass through an API gateway
  4. 04 /Stopping one task means stopping the whole agent
// Capabilities

Hold every task to its objective.

Four controls applied to every task, from the first process it starts to the last.

01// Bind

Bind each task to its objective

Every process the task starts inherits the objective's authority, including child processes and threads.

02// Enforce

Enforce where effects happen

Checks run on file access, program launch, network connections and IPC, not only on API calls.

03// Revoke

Narrow or revoke at any time

Change an objective's authority while the task runs. Anything outside it fails closed from the next check.

04// Trace

Trace every decision

Each allow and deny is tied to the objective and the version of its authority that produced it.

Architecture

Three layers, one objective.

intentd turns an objective into authority. KAP and iVisor enforce it where the agent runs.

intentd

Objective runtime

Tracks each objective, its lineage and the authority it grants, and binds agent workloads to it before they start. Runs today on Google Agent Substrate.

KAP

Kernel enforcement

A Linux kernel subsystem for objective-scoped authority. Intent Lineage Groups are its core object, the kernel's security hooks enforce it, and securityfs is its control plane.

iVisor

No kernel change

A userspace application kernel that applies the same checks where you can't change the kernel. Experimental.

Try it

Try it where you run agents today.

Available

NVIDIA OpenShell

Intent enforcement through OpenShell middleware, with no change to the agent.

Preview

Google Agent Substrate

intentd runs on Substrate and binds each Actor to its objective.

Coming soon

AWS Bedrock

Intent Container for agents on Bedrock.

Preview

Linux

Run KAP in a supported kernel, or iVisor where you can't change the kernel.

Talk to us

Somewhere else

Running agents somewhere else? Talk to us.

Onboarding open

Ready to control what your AI agents actually do?

Join the teams shipping safer, compliant AI agent deployments. White-glove onboarding for the first 50 design partners.

Read Docs →
Live Intent Assurance↗