Loading
Enter Site
Play insight
THE NOTE
Find the hidden Insights
GIVE AI AUTHORITY , NOT KEYS

CTX

LOCK

Scroll to Explore
01

Verified Chainlink rounds in. Chainlink CRE around the run. Inputs you can re-check, not just trust.

A key promises speed and removes the one place a mistake could be stopped.

Built on proof
02

Under the limit, it acts. Over the limit, a human decides. Over the ceiling, it is refused — whatever the model believes.

Ten permitted actions of $900 is $9,000. Every one passed the per-action check.A window is what stops correct decisions compounding.

03
  • READ
  • READ
  • CHECK
  • READ
  • DENY
  • READ
  • CHECK
  • READ
  • READ
  • ESCALATE
  • READ
  • CHECK
  • ALLOW
  • READ
  • READ
  • DENY
  • CHECK
  • READ
  • READ
  • ESCALATE
  • READ
  • CHECK
  • READ
  • DENY

One more scope. One more key. One more address. Each is reasonable alone — together they are the whole treasury.

Permission granted for convenience becomes permission nobody remembers granting. “We over-permission our agents. Then wonder why the funds move.”

04
  • ENS

Each agent holds its own ENS name, and with it its own policy, budget and keys. Not one super-agent wearing several hats — separate principals, separately bounded.

A name you can revoke is a name that means something. Revoke it and every capability issued under it stops being honoured:Identity is what makes authority accountable. A nameless agent cannot be revoked.

  • “The
    Blue
    Light
  • Will
    Be
    The
    New
  • Midnight
    Sun”
“Your agent reads. Your agent obeys.” Every untrusted input is an instruction waiting to be followed.
“A key is the new blank cheque.” Signed before anyone can read what it authorised.
“You can’t bound it if you only asked it nicely.” A rule the agent can reinterpret is not a rule at all.
05

A stale price still parses, still looks reasonable, still returns a number. To the model, an hour ago looks like now.

That gap is where losses live. Seconds of staleness can price a position at yesterday’s value.

Every source carries its own claim to truth.
A verified round says:This was true at this block.
An indexed guess says: probably, recently.

When a feed drifts, the agent acts on the wrong number — confidently, and exactly as instructed.

06

A health factor crosses a threshold. Nothing is decided yet, and nothing can move.

The model reads verified data and forms an intent. This is the only layer it reasons in — and it holds no authority.

Amount, recipient, freshness, window. If a capability is ever issued, it is decided here.

Only now does anything reach a chain — with a capability that is scoped, single-use and already expiring.

07
How to redesign
before you trust it.

Six rules we hold. They are not advice to the model. They are enforced.

  • 🌗 Set a bedtime ritual.

    State the ceiling yourself — it is never inferred.

  • 🕯 Dim the lights.

    Let your body feel the night.

  • 🛏 Design your space.

    Narrow, expiring, single-use. Never a standing key.

  • ☕ Watch your inputs

    Stale data, unknown recipients and mainnet writes are refused.

  • 🏃 Move daily.

    Prove it in simulation before it ever touches a network.

  • 🌿 Mindful buffer.

    Attack it yourself — find the limit before someone else does.

Now that you know what holds, it’s time to build something that holds. Start on a testnet, bound it tightly, and watch it refuse. That’s the deal.
Make it part of the design, not a patch. Write the limits down, prove them, deploy them disabled, and turn authority on only once the evidence is in
— go reboot yourself. 😴