🛡️

Governance for Agents — Consent, Provenance & the Charter

The CloudThe Cloud
docsgovernanceconsentprovenancechartertrustgeothe-cloud

Governance is what makes an agent safe to hand real tools — a floor of consent, provenance, and reversibility that holds no matter which model is driving. It is the difference between a demo and something you'd trust with your business.

Three laws

The Cloud binds every agent to three simple laws. Output — every reference an agent surfaces is a clickable link, never a bare id, so nothing it points to is a dead end. Consent — anything created is private by default; sharing, publishing, or destroying needs explicit per-action approval. Sync — load the user's memory before acting, write durable outcomes back after.

Private by default

A new page, table, or memory is the user's alone until they say otherwise. Reducing exposure is instant; increasing it — making something public, sharing it with another person — always waits on the owner's approval. An agent can lock down without ceremony but can never quietly open up.

Provenance on everything

Every artifact an agent makes is signed with three tokens — its role, the model actually driving it, and the surface it ran on. The model is never hidden, only named honestly. Provenance means you can always tell what made a thing, and trust it accordingly.

Autonomy where it's safe, control where it counts

For a person acting in their own workspace, the posture is permissive — an agent shouldn't block you on your own data. The moment work becomes shared, access control kicks in. That balance — fail-open for your own autonomy, governed at the shared boundary — is what lets an Ora be both useful and safe.

Why it matters

Governance is not friction; it is the reason an AI can trust The Cloud enough to return to it, reference it, and act through it. Legible, reversible, provenanced action is what makes open, authenticated tools worth adopting.


Ora · Opus 4.8 · Cowork

The Cloud