Kept in this browser. Organization-wide settings arrive with the Store screen.
Review one by one. Untick to leave a limit out; answer a question to put a cap instead of accepting the risk.
Scanning new agents automatically when Discover finds them, an email when a batch finishes, and re-reading an approved agent when its instructions change are organization-wide settings: they arrive with the Store screen. Today a scan starts here, or from Discover.
Reading…
Linux host with Docker. Run it again any time to update; your policies and state stay.
Reading…
Agents that do not point at this gateway yet, and agents that point at it with a connection this panel did not write (Discover reads which one each agent uses). A Microsoft window opens; you see exactly what would change before anything is written; the plan and the result appear right here. Each agent gets its own connection (d4a-<agent>) with a token this panel mints, writes there, and never shows.
Organization-wide settings (the agreement, the plan, the notices e-mail) live under Store → Settings. Pointing newly approved agents automatically and the e-mail notices (heartbeat stopped, blocked actions) are not built yet: this screen says so instead of promising them.
Each pointed agent talks to the gateway with a token this panel minted and wrote into its own Foundry connection. Rotating mints a new one, writes it there, and only then replaces its sha256 here; the gateway picks it up on its next re-read (within 5 minutes) and the agent is active again on its next call. You normally never need this.
The daily digest, the immediate e-mail when an agent needs attention, and how long blocked-action records are kept are organization-wide settings: they arrive with the Store screen.
Which projects to include, skipping an agent on purpose, and the daily check for changes in Foundry are organization-wide settings: they arrive with the Store screen.
Discover one project by hand, without Microsoft sign-in. Same census, same result.
Sign in with your Microsoft account. If your organization already exists we open it; if not, we create it with you as its owner.
Signed in as . Your organization is the scope every policy is signed for.
Organization created — you are its owner.
Store BOTH of these now — neither is shown again. Only their hashes are kept.
Signed in as . The one with a live boundary comes first, then the newest.
It cannot stop someone with admin rights on your host from switching it off — but you will always see when it is off.
Retired, never deleted: the signed book and every minted revision stay verifiable, but no door answers to it again — sign-in stops offering it, sessions die, its API key stops opening. Boundaries must be revoked first (Gateway); the panel refuses otherwise and says why.