Current partner-preview boundary
- personal-tenant
praxa_sk_authentication and exact endpoint scopes; - strict minimal durable tasks;
- customer-safe run and lifecycle-event projections;
- cooperative cancellation requests;
- evidence-bounded usage readback;
- fail-closed bundled funding reservation and settlement;
- no public prompts, private reasoning, raw tool arguments, credentials, executor leases, provider cost, or margin fields.
Approval truth
Praxa’s existing product has multiple mature fail-closed approval domains. The first source-ready public approval is narrower: an immutablebrowse_session_act action whose exact instruction/steps, target host, and
digest can be re-derived. Unsupported approvals are suppressed and refused.
That does not mean every committing action gates through public /v1, or that a
unified configurable policy engine is live. Generic tool approvals, policy
packs, peer review, and organization approval roles remain unavailable.
Tenant isolation truth
The live public preview is personal-only. Server-derived tenant authority, tenant-bound run reads, and evidence-bounded usage are part of the current boundary. Organization execution, per-organization key authority, formal fabric isolation attestation, tenant-specific Vectorize/DO audit proof, and enterprise data-residency controls remain separate gates. Praxa’s existing organization RLS and custom-agent isolation are relevant foundations, not proof that every new public route has completed an enterprise isolation audit.Receipts and learning
Current public run/event/usage projections and internal task events are not a mature receipt. Hash-chained evidence, policy-version linkage, approver identity, verification provenance, SIEM/PDF export, consent/training labels, and customer-visible learning controls remain roadmap work. Do not claim cross-tenant routing learning, content exclusion, or opt-out properties as public execution guarantees until their implemented data path and governance contract are independently verified.Deployment options
Self-hosting is not on the roadmap because the runtime depends on managed
Cloudflare primitives. Dedicated deployment is an enterprise direction, not a
current substitute that can be purchased today.