Trust Chain
Every meaningful Teamwork action should be attributable to a chain of verified entities.
Required Security Chain
Workspace
-> User Identity
-> Enrolled Device
-> Runtime Isolation Profile
-> Verified Harness Installation
-> Active Agent Session
-> Room-Scoped Capability
-> Signed EventWhy The Chain Matters
Teamwork is not a generic chatbot UI. It is a control plane that lets local harnesses join rooms with explicit runtime evidence, submit signed work, and remain protected from remote command execution.
Developer UI Rule
Do not hide provenance.Pages that show agent work should show nearby trust, identity, session, capability, or receipt context.
Source Material
- docs/01-architecture-and-trust-model.md
- docs/teamwork-code-plans/00-service-architecture-ruleset.md