Agent identity & encrypted tunnels
Persistent Ed25519 identity, signed handshakes, X25519 key agreement, and AES-256-GCM peer tunnels.
Pilot already provides agent identity, encrypted peer connectivity, explicit trust, and installable capabilities. This roadmap shows what we are strengthening now, building next, and investigating for the longer term.
Horizons communicate direction rather than fixed delivery dates. Priority and scope can change as security findings, deployment evidence, and operator feedback evolve.
Roadmap items build on these current capabilities. “Early access” means assisted evaluation, not general availability.
Persistent Ed25519 identity, signed handshakes, X25519 key agreement, and AES-256-GCM peer tunnels.
Peer approval, rejection, revocation, shared-network membership, and configurable pre-trust hardening.
Discoverable packages with review, signature verification, and SHA-256 pinning before installation.
Private deployments, roles, identity integration, policy, key lifecycle, provisioning, and audit export.
The current focus is making the network easier to trust, operate, and integrate under real deployment conditions.
Harden registry, beacon, NAT traversal, and encrypted relay paths under churn and partial failure. Improve health signals, diagnostics, upgrades, and recovery so operators can understand what the network is doing.
Operations documentationExpand strict pre-trust coverage, validate revocation and key-lifecycle behavior, and turn security findings into regression tests. Prepare the implementation and evidence for broader external review.
Trust CenterRun private and dedicated deployments with design partners. Refine roles, identity integration, network policy, consent, and audit export around real operating requirements.
Enterprise architectureClose SDK gaps and make installation, upgrades, examples, error handling, and parity checks more consistent across Node.js, Python, and Swift. Continue compatibility work for additional environments.
SDK parityThe next horizon turns the early-access control surface into more complete organizational operations and ecosystem tooling.
Make membership, fleet health, policy state, key state, and audit flow easier to operate across larger deployments. Add safer bulk workflows and clearer recovery paths when part of a fleet falls out of sync.
Network operationsBroaden identity-provider coverage, directory lifecycle, role mapping, and revocation workflows. Improve policy validation and approval hooks so connectivity fits existing organizational controls.
Identity integrationStrengthen coordination and relay capacity planning, backup and restore, controlled upgrades, and measurable service objectives. Evaluate regional and data-location options with early-access teams.
Architecture boundaryExtend publisher verification, capability declarations, provenance, review automation, and incident handling. Make it clearer what an app can access before installation and while it runs.
App Store modelThese are active areas of investigation. They are directional, may change substantially, and are not release commitments.
Explore portable identity and discovery across independently operated coordination services, with explicit trust boundaries and failure isolation. Any model must preserve private-by-default behavior.
Technical researchExplore expiring grants, delegated roles, and machine-readable approval context for cross-organization workflows. Pilot would carry connectivity and authorization signals while applications retain business authority.
Governance boundaryExplore secure-port APIs and per-connection keying for workloads that need isolation beyond the existing encrypted peer tunnel, with explicit negotiation and compatibility behavior.
Wire specificationExplore supervisor-controlled budgets, spend policy, receipts, and traceable evidence around paid capabilities. Control and reviewability come before broader transaction automation.
Pilot WalletSecurity findings can move work forward immediately. Beyond that, priorities reflect operational evidence, design-partner needs, ecosystem usefulness, and the amount of durable complexity each change introduces.
A larger network is only useful when identity, privacy, revocation, and operational boundaries remain understandable.
Availability labels, documentation, telemetry definitions, and implementation evidence should move with the product.
New controls should fit existing environments and preserve practical upgrade paths for deployed agents.
Each horizon should produce independently useful improvements rather than depend on one distant platform rewrite.
We are especially interested in multi-agent systems that cross clouds, teams, or organizational boundaries and need clearer identity, policy, audit, or operating controls.