Captures a complete what-happened run log offline (inputs, actions, artifacts) for later review/export.
Stores/retrieves credentials locally using encryption; provides time-limited secret handles to agents.
Signs payloads (agent packages, receipts, approvals) with a locally held keypair.
Gates high-risk actions behind a hardware-backed user approval and records proof.