Capabilities are granted by policy by default
Path, command, tool, egress, credential, and data-action rules can be versioned. When policy changes, old approvals do not silently continue.
Security / Trust
BeforeWire keeps raw data, secrets, and full artifacts inside the customer boundary by default. External surfaces can receive only policy-approved summaries, hashes, redaction manifests, and Action Receipts.
Path, command, tool, egress, credential, and data-action rules can be versioned. When policy changes, old approvals do not silently continue.
Receipts and artifacts can stay local by default. Enterprise deployments can configure private control planes, encrypted storage, TTLs, and audit exports.
Production credentials, external API mutations, database writes, and customer notifications can be controlled through a broker, approval route, or deny policy.
files=enforced, runtime=enforced, egress=governed, db=brokered, unsupported=blocked. Unsupported surfaces are not presented as recoverable.