Trust ladder and scale¶
Autonomous execution can be viewed along two axes: how humans intervene (the trust axis) and what carries execution (the scale axis).
Post-run review¶
Enforce access boundaries during execution, then review changes and records together.
During execution, file and network policies limit access, and staging retains changes for review. After execution, review the process record and results together, reducing the need to approve each command.
Batch review¶
Process review does not amortize. Every extra step is another decision, and a human must be present throughout—how fast the agent runs depends on how closely you watch. That is today's ceiling.
Deferred review does amortize. Results can be sampled, batched, and machine-checked; once process facts are recorded completely, they can be verified after the fact in one pass instead of being intercepted during execution.
Four levels are a reference; the choice is the last one¶
The four levels describe the timing and degree of human intervention. L0 requires approval before each command; L1 through L3 use post-run review and progressively introduce policy- and evidence-based exemptions. The table lists the usage scenarios for each level.
| Level | How humans intervene (trust axis) | What carries it (scale axis) | Status |
|---|---|---|---|
| L0 | Approve each command before it runs | A single interactive session | Common in agents, now with model-assisted approval |
| L1 | Review each change after the run | Local, individual Jobs | pVisor today |
| L2 | Policy and evidence determine exemptions; humans spot-check | Multiple local Jobs / one pipeline | Next |
| L3 | Audit afterward; humans handle exceptions only | Clustered: cross-node scheduling, centralized evidence | pVisor's scale target |
pVisor focuses on post-run review: enforce access boundaries, stage file changes, then inspect records and results. Use the --ask runtime approval channel when individual operations need approval.
Review process and results together¶
Execution records retain observed file access, denials, and network activity. After the task finishes, review these records alongside the file changes.
Where we are today¶
What ships today is this stage at single-machine scale: individual Jobs on one machine—run unattended, then review changes and evidence afterward, and merge only what you want. L2's exemption decisions and L3's cluster scale are not here yet.
The single-node daemon manages local sandbox lifecycle through an API separate from native Job review. External systems such as Kubernetes and Ray handle cross-node scheduling; pVisor provides execution semantics and checkable records within those systems.
Under construction
The entry criteria and gap list for L2/L3 are not final. See the roadmap for progress, concurrency density for the capacity rationale, and cluster execution for the cluster direction.