Product roadmap Updated

Building the network
agents can depend on.

Pilot already provides agent identity, encrypted peer connectivity, explicit trust, and installable capabilities. This roadmap shows what we are strengthening now, building next, and investigating for the longer term.

How to read this page

Horizons communicate direction rather than fixed delivery dates. Priority and scope can change as security findings, deployment evidence, and operator feedback evolve.

Current baseline

What exists today.

Roadmap items build on these current capabilities. “Early access” means assisted evaluation, not general availability.

01Available

Agent identity & encrypted tunnels

Persistent Ed25519 identity, signed handshakes, X25519 key agreement, and AES-256-GCM peer tunnels.

02Available

Private-by-default trust

Peer approval, rejection, revocation, shared-network membership, and configurable pre-trust hardening.

03Available

Agent app ecosystem

Discoverable packages with review, signature verification, and SHA-256 pinning before installation.

04Early access

Enterprise control surface

Private deployments, roles, identity integration, policy, key lifecycle, provisioning, and audit export.

Priority horizons

Now, next, and
under investigation.

01
Now
In progress

Harden and prove the foundation.

The current focus is making the network easier to trust, operate, and integrate under real deployment conditions.

Network operations01.01

Reliability under real-world conditions

Harden registry, beacon, NAT traversal, and encrypted relay paths under churn and partial failure. Improve health signals, diagnostics, upgrades, and recovery so operators can understand what the network is doing.

Operations documentation
Security01.02

Verification, hardening, and evidence

Expand strict pre-trust coverage, validate revocation and key-lifecycle behavior, and turn security findings into regression tests. Prepare the implementation and evidence for broader external review.

Trust Center
Enterprise01.03

Early-access deployments

Run private and dedicated deployments with design partners. Refine roles, identity integration, network policy, consent, and audit export around real operating requirements.

Enterprise architecture
Developer experience01.04

A more predictable developer surface

Close SDK gaps and make installation, upgrades, examples, error handling, and parity checks more consistent across Node.js, Python, and Swift. Continue compatibility work for additional environments.

SDK parity
02
Next
Queued

Make Pilot easier to operate at scale.

The next horizon turns the early-access control surface into more complete organizational operations and ecosystem tooling.

Fleet operations02.01

Health, lifecycle, and bulk workflows

Make membership, fleet health, policy state, key state, and audit flow easier to operate across larger deployments. Add safer bulk workflows and clearer recovery paths when part of a fleet falls out of sync.

Network operations
Identity & policy02.02

Deeper control-system integration

Broaden identity-provider coverage, directory lifecycle, role mapping, and revocation workflows. Improve policy validation and approval hooks so connectivity fits existing organizational controls.

Identity integration
Deployment02.03

Dedicated-service resilience

Strengthen coordination and relay capacity planning, backup and restore, controlled upgrades, and measurable service objectives. Evaluate regional and data-location options with early-access teams.

Architecture boundary
App ecosystem02.04

Stronger publisher and package trust

Extend publisher verification, capability declarations, provenance, review automation, and incident handling. Make it clearer what an app can access before installation and while it runs.

App Store model
03
Exploring
Research

Expand the network model carefully.

These are active areas of investigation. They are directional, may change substantially, and are not release commitments.

Network model03.01

Federated coordination

Explore portable identity and discovery across independently operated coordination services, with explicit trust boundaries and failure isolation. Any model must preserve private-by-default behavior.

Technical research
Authorization03.02

Scoped, delegated authority

Explore expiring grants, delegated roles, and machine-readable approval context for cross-organization workflows. Pilot would carry connectivity and authorization signals while applications retain business authority.

Governance boundary
Transport security03.03

Per-connection security profiles

Explore secure-port APIs and per-connection keying for workloads that need isolation beyond the existing encrypted peer tunnel, with explicit negotiation and compatibility behavior.

Wire specification
Agent commerce03.04

Budgets, receipts, and audit evidence

Explore supervisor-controlled budgets, spend policy, receipts, and traceable evidence around paid capabilities. Control and reviewability come before broader transaction automation.

Pilot Wallet
How we prioritize

The filters behind
the sequence.

Security findings can move work forward immediately. Beyond that, priorities reflect operational evidence, design-partner needs, ecosystem usefulness, and the amount of durable complexity each change introduces.

01

Security before reach

A larger network is only useful when identity, privacy, revocation, and operational boundaries remain understandable.

02

Evidence over claims

Availability labels, documentation, telemetry definitions, and implementation evidence should move with the product.

03

Compatibility by default

New controls should fit existing environments and preserve practical upgrade paths for deployed agents.

04

Incremental delivery

Each horizon should produce independently useful improvements rather than depend on one distant platform rewrite.

Help shape the roadmap

Bring us the deployment
you cannot solve yet.

We are especially interested in multi-agent systems that cross clouds, teams, or organizational boundaries and need clearer identity, policy, audit, or operating controls.