What Moonwalker governs
One authority plane for the messy places agents actually work.
Governance that stops at the model boundary governs nothing. Moonwalker sits where autonomous work becomes real — local machines, project vaults, browser sessions, worker agents, scheduled jobs, and the evidence they leave behind.
Local workspace
Files, shells, browsers, and desktop
Read and write access, shell execution, code workers, and browser sessions — each bound to an explicit scope, a backup posture, and policy the customer owns. Governed database access is the next surface on the same contract: scope and evidence over the query, with the data never leaving your systems.
Agent operations
Workers, packets, jobs, and closeouts
Long-running autonomous work becomes reviewable: a task packet, a bounded dispatch, a required artifact, run history, review, and a closeout that says what actually happened.
Human authority
Risk friction where it matters
Routine actions flow without ceremony. Consequential, credential-bearing, outward-facing, or hard-to-reverse actions meet warning, attestation, approval, or a hard stop.
Evidence layer
A flight recorder for autonomous action
Because instructions, task context, and available evidence all cross the control plane, the record preserves what the agent was told and what it knew at the moment it acted — context that otherwise vanishes the instant the action completes.
Crypto posture
Built for the bar you’ll be held to
SHA-384 chain digests and AES-256-GCM at rest — CNSA 2.0-aligned today, with no MD5, BLAKE, or legacy ciphers anywhere in the sealed path. The signature lane is deliberately swappable, so post-quantum ML-DSA is a module change rather than a format migration. Every record states its own module identity and FIPS-validation status instead of assuming it; FIPS-validated signing lands with the first procurement that requires it.