Skip the visualization

The governed passage for agent work

Give agents reach. Keep control.

One MCP URL per organization. Permissions per call. Credentials in custody. A verifiable record.

Governed channel

Person ◦ Daphnis Team MCP

identity → policy · credential → record

Call: mcp__docs__read

Allowed Recorded

Illustrative example with synthetic data

How it works

One call, five decisions

Every crossing passes the same five gates. The record below is the same one section 3 starts from.

  1. 1 / 5

    Identity

    The passage knows who calls: a person, an automation, or an agent with a key.

    agent:analyst authenticated

  2. 2 / 5

    Policy

    The policy answers one question: may this caller touch this tool, this way?

    read allowed · write denied

  3. 3 / 5

    Credential

    The credential never reaches the agent. The passage holds it and uses it on the caller's behalf.

    credential in custody, never exposed

  4. 4 / 5

    Execution

    The call crosses to the tool. A denied call never leaves the border.

    mcp__docs__read executed

  5. 5 / 5

    Redaction & record

    Arguments stay out of the record. The hash-chained receipt stays in.

    receipt sealed · #a3f9…c21d

See the architecture

Proof of refusal

The boundary has teeth

Pick a scenario. Both leave a record; only one reaches a tool.

Principal
agent:analyst
Tool
mcp__docs__read
Reason
Policy grants read on team docs to agent:analyst.
Record
◆ sealed · #a3f9…c21d
Result
Reached the tool. Response returned redacted.

Illustrative example with synthetic data

Want this boundary around your agents? Join the waitlist

Beyond the endpoint

Automations and Apps use the same passage

Scheduled work and private interfaces cross the same channel, under the same policy.

Automations

Three steps, one graph: gather two sources, merge, notify. Each step crosses as its own call, with its own receipt.

  1. Gather usage ◆ receipt per step
  2. Merge report ◆ receipt per step
  3. Notify team ◆ receipt per step

Each step of the graph returns to the channel.

How Automations cross

An automation is a graph of steps. A step never borrows the next step's permission: each one authenticates, each one is judged by policy, each one leaves a receipt.

Private Apps

A private interface inside the dashboard with one action: approve the weekly report. The action crosses the channel like any call.

Dashboard · private

—

How Apps cross

A private App is an interface with a narrow permission. Pressing the button issues one call through the passage — identity, policy, credential, record — exactly like an agent's call.

Illustrative example with synthetic data

Architecture

Honest architecture

Six parts, no magic. What the passage does not do is written down next to what it does.

  1. 1

    Client

    Agent, automation, or App.

  2. 2

    Edge

    One MCP URL per organization.

  3. 3

    Identity

    Who calls, and with which key.

  4. 4

    Policy

    What this caller may touch.

  5. 5

    Broker

    Credentials in custody, calls placed.

  6. 6

    Upstream

    The tool or API behind the border.

↩ On the way back: redaction, then the sealed record.

Stated limits

  • The record is hash-chained and verifiable. It is not proof against an administrator who controls the host.
  • No intent detection. Policy judges the call, not the motive.
  • No execution isolation. The passage governs the crossing, not the sandbox.

The code link appears here once the public repository is confirmed.

Questions

Frequently asked questions

Is this self-hosted or a hosted service?

The launch is a waitlist for access. Deployment options will be announced to the list before general availability.

How is identity handled?

Each caller — person, automation, or agent with a key — authenticates at the edge. Every decision downstream names that identity.

Do agents ever see credentials?

No. Credentials stay in the broker's custody. The agent asks; the passage presents the credential upstream on its behalf.

What exactly is recorded?

Structure, not content: who called, which tool, the decision, and a hash-chained receipt. Arguments and prompts never cross into the UI or the record.

What are private Apps?

Interfaces inside the dashboard with narrow permissions. Each action they take crosses the same passage as an agent's call.

What does the waitlist get me?

News about Daphnis availability. One email, nothing else required — no name, no phone, no company size.

Still interested? Join the waitlist

Waitlist

Get news about Daphnis availability.

We use your email only to announce availability.