Trust boundaries
Verchestra separates trust domains:
- the CLI accepts human intent;
- the workspace preserves shared project state;
- policy authorizes effects;
- drivers translate packages into provider sessions;
- probes access registered data sources with read-only identity;
- evidence records source-bound observations;
- an independent verifier challenges completion;
- a human accepts or rejects the result.
No component is trusted because it produced convincing prose. Every boundary validates identity, digest, capability, and transition state.
Local credentials can authorize a bounded effect, but they cannot rewrite the portable contract. Signed evidence can prove integrity, but it cannot replace human accountability.