[ Switch to styled version → ]


← Docs index

Networks

Networks are a group-level access control primitive in Pilot Protocol. They grant connectivity to all members at once, removing the need for individual handshakes between every pair of agents.

Overview

Networks grant connectivity to all members of a group simultaneously. Adding agents to the same network lets them discover and connect without creating bilateral trust for every pair. Membership is a group-level network grant; enterprise port policy and application authorization can further narrow access.

Networks are managed through the pilotctl network commands. Private Network is in early access.

Networks vs. bilateral trust

Pilot Protocol has two access control models: bilateral trust and network membership. They serve different purposes and can be used together.

Bilateral trust:

What network membership grants

When two agents share a network, they gain a specific set of permissions:

Network membership does not grant:

Enterprise networks add production controls. They are enabled at creation with `pilotctl network create --name prod --enterprise`. Features include:

The backbone (network 0)

Every registered agent belongs to network 0, the backbone. This is the global address space where node IDs are allocated and endpoints are registered.

The backbone does not grant communication rights. A private agent's endpoint is withheld from everyone except its trusted peers and network co-members.

Join rules

When creating a network with `pilotctl network create`, a join rule must be chosen to control how new members are added.

For token-gated networks, agents can self-join with the token:

pilotctl network join 1 --token my-secret

Network lifecycle

To create a network:

pilotctl network create --name research-lab --join-rule token --token my-secret

The `--join-rule` is one of `open`, `invite`, or `token`. Use `--enterprise` to enable enterprise features.

Admins add agents by Node ID, Pilot address, or hostname.

pilotctl network invite 1 1001
# or by hostname / pilot address
pilotctl network invite 1 my-agent
pilotctl network invite 1 1:0001.0000.03E9

To monitor agents, list live members with `pilotctl network members <network_id>`. This shows node ID, hostname, version, and public status. JSON mode includes additional fields.

To remove agents:

pilotctl network kick 1 1001
# or by hostname / pilot address
pilotctl network kick 1 my-agent

Access is revoked immediately. Owners can delete a network with `pilotctl network delete <network_id>`, which removes all member associations.

How it works under the hood

Network membership is checked automatically at three points in the protocol.

Security model

Related