Skip to content

Plan: Mirror privilege boundary + evidence broker - #5

Draft
jackye426 wants to merge 2 commits into
mainfrom
cursor/mirror-privilege-plan-703c
Draft

Plan: Mirror privilege boundary + evidence broker#5
jackye426 wants to merge 2 commits into
mainfrom
cursor/mirror-privilege-plan-703c

Conversation

@jackye426

@jackye426 jackye426 commented Jul 16, 2026

Copy link
Copy Markdown
Owner

Summary

Planning doc for the Mirror security model, with decisions locked:

  • Two MCP endpoints in one service (/mcp Mirror, /mcp/ops)
  • Mirror has no raw vault tools; sessions are broker-only
  • Calendar structure via sanitised view; descriptions/attachments via broker
  • Agent may request evidence; deterministic policy decides access
  • Sensitive = scoped short-lived capabilities; restricted = ops-issued
  • Compilers keep a separate non-interactive vault credential
  • Portraits / behavioural models get stronger protection than ordinary distillates

See docs/mirror-privilege-plan.md.

No runtime code in this PR.

Open in Web Open in Cursor 

Document distillates-by-default architecture: credential split, Mirror vs ops
tool profiles, retrieve_supporting_evidence broker, audit, and rollout order.

Co-authored-by: jackye426 <jackye426@users.noreply.github.com>
Two MCP endpoints, no raw Mirror tools, broker-only sessions, sanitised
calendar, policy-gated capabilities, ops-issued restricted access, separate
vault credential for compilers, stronger portrait protection.

Co-authored-by: jackye426 <jackye426@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant