PERSISTENT
HARNESS
Critical Infrastructure for an Agentic Future

MCP Native

MCP-native from day one.

So onboarding is a conversation, not a config file.

Service DomainUser DomainPersistent HarnessTrilateral Handshakesign_token_requesttrustsMCP PROTOCOL LAYERkey lookupkey lookupREST API LAYER/api/* portals/api/* dashboardscallback๐Ÿ‘คUserHuman Principal๐Ÿค–AgentUntrusted Transport๐ŸšชGatewayService AnchorCoordinationNodeTrust Registry๐Ÿ›ก๏ธGuardianIdentity Providerโ˜๏ธServiceAPI / ApplicationMCP Protocol LayerAgent relays signed tokens via MCP tools.MCP protocolKey verificationDelegationCallback
Gateway MCP toolsGuardian MCP toolsAI-assisted onboardingSigned receipts

Protocol native

MCP-native from day one. So onboarding is a conversation, not a config file.

AI-assisted MCP onboarding begins โ€” the system auto-discovers every tool the service exposes, classifies each by risk, and proposes an approval level.

01

Step 6: Connect a Service

Browse the service catalog. Pick GitHub (or Cloudflare, or OpenClaw). AI-assisted MCP onboarding begins โ€” the system auto-discovers every tool the service exposes, classifies each by risk, and proposes an approval level.

02

What the user sees:

A tool review screen showing every capability grouped by risk. "22 tools auto-approve. 8 need your device confirmation. 3 are disabled (too dangerous for autonomous use). 2 are removed entirely."

03

Permission Harness in action

The user can adjust any classification upward (stricter) but not below the service's minimum. This is the Permission Harness in action.

MCP Native

The MCP calls under the hood.

Step 1: Choose Your Guardian

Two options โ€” US and EU data sovereignty. Both run identical protocol, different Cloudflare regions. User picks based on where they want their data to live. This is jurisdiction selection, not a feature difference.

Step 2: Create Your Account

Email, phone number, passkey enrollment. Passkey is biometric-backed (Face ID, Touch ID, Windows Hello). This becomes the primary authentication going forward โ€” no passwords.

Step 3: Verify

Real verification codes sent to real phone/email. First notification the platform sends. Confirms the communication channels that will be used for agent approvals.

Step 4: Your Dashboard

Guided wizard shows progress: what's done, what's next. Not a blank dashboard โ€” a directed path through setup.

Step 5: Spin Up Your Gateway

One button. Under 10 seconds. Behind the scenes: Cloudflare Worker deployed, Ed25519 keypair generated, registered with Coordination Node (proof-of-possession), Vault provisioned on separate trust domain, bound to Guardian account. User sees: spinner โ†’ "Your Gateway is ready."

Mapped architecture

MCP-native from day one. So onboarding is a conversation, not a config file.

Agent SDK

MCP tool calls wrapped into one authenticate flow.

Human developers can use REST to test and debug. Agents operate via MCP, and the SDK handles the orchestration.

  • Gateway manifests
  • Guardian signatures
  • OOB polling
  • Receipt submission

Gateway

Service-side trust through MCP.

The Gateway is the service-side trust anchor. It exposes the manifest, generates challenges, verifies signatures, and assembles receipts.

  • Service metadata
  • Risk floors
  • Challenge nonce
  • Receipt archive

Guardian

User-side trust through MCP.

The Guardian holds delegation rules, manages passkeys, evaluates approval policy, and signs scoped attestations on behalf of the user.

  • Delegation rules
  • Passkeys
  • OOB approval
  • Scoped signatures

How it works

Orchestration flow.

Agents operate through MCP, while developers can still use REST to test and debug.

  1. 01

    Step 7: Store Your Credentials

    User generates a fine-grained access token (e.g., GitHub PAT) with minimum required scopes. Enters it once. Confirms with passkey. Token is encrypted and stored in the Vault โ€” a separate trust domain that ANS application code cannot access. The agent will use these credentials by effect ("create an issue") never by value ("here's the token").

  2. 02

    Step 8: Connect Your Agent

    Agent enlists with the Guardian. User gets notified โ€” SMS, email, and browser push simultaneously. Notification shows: agent ID, source, requested services. User approves from any channel.

  3. 03

    Step 9: Your Agent Acts

    The agent starts working. Low-risk actions (reading files, listing repos) auto-approve invisibly. When the agent hits a tool that exceeds the auto-approve threshold โ€” say, merging a PR โ€” the relay pauses and fires a notification to the user's phone.

  4. 04

    Step 10: The Receipt

    Every action above the auto-approve threshold produces a signed receipt. Three independent keys (Guardian, Gateway, Coordination Node) each verify independently. The receipt proves: who authorized it, what was authorized, when, and under what rules. This is not a log entry โ€” it's a cryptographic proof that travels with you.

Open beta

MCP-native from day one. So onboarding is a conversation, not a config file.

Test Drive