ExecBound documentation
ExecBound decides, before dispatch, whether one action on one resource may proceed, and can prove afterwards what it decided and why. These pages are the repository's own documentation, published unchanged.
Start here
What to run first, on one host or in your own cloud account.
Concepts
One page each for the parts a decision is made from.
- Actions and the catalog
- Trusted context
- Policy and rulesets
- Approvals, impact limits and execution
- Providers and the credential boundary
- Evidence and replay
- The external execution checkpoint
- Integrations and the enforcement modes
Reference
The interfaces, the stored shape and the deployment inputs.
- HTTP, MCP, the human pages and the CLI
- Surfaces in detail
- The data model
- The image and its processes
- Retention, backup and recovery
Trust
What ExecBound claims, what it does not, and how each claim is evidenced.
Changelog
Every recorded change, newest first.
API reference
The console API, rendered from the OpenAPI document this repository generates and checks against the running application.