Fleet Control Tower
Why it is in the ecosystem. One policy across an organisation, and a stop button whose firing is itself provable.
What it is
One policy across an organisation, inherited org to team to agent, and a stop button. Press it and every in-flight action resolves to DENY with the reason fleet_killed. The press itself is judged by the engine and leaves a signed receipt, so a board can be shown exactly when the fleet was stopped. Even the stop button leaves a receipt.
The fleet
fleet and its activity DEMOreceipts REALreason code REALreading the fleet
When the switch fires
The second-approver rule
Above a fleet threshold, a kill, a policy change, or a payment over 2,000 USDC per day, two devices must sign. Each signs the hash of the exact action, so the two approvals are approvals of the same bytes. This demo has one passkey, so the rule is shown here and not exercised. The single-device ceremony is live in tour 3.