The harness is running. This page reads its own live surfaces — nothing here is remembered.
Sign-in is not open: it awaits the owner's root key. The harness refuses rather than pretends — no deployment root key is bound and the platform offers no per-tenant custody.
| name | rig-portal |
|---|---|
| adapter | rig-portal-adapter/v1 |
| adapted classes | PlatformPortal |
| custody | unavailable |
| platform per-tenant custody | not earned — recorded as an open production gap |
| owner-only provision door | ARMED — a caller secret is bound |
| capability | binding present | version declared | route resolves |
|---|---|---|---|
| tenant.resolve | yes | yes | yes |
| session.start | yes | yes | yes |
| ledger.append | yes | yes | yes |
| vault.mint-grant | yes | yes | no |
These are observations from inside this isolate. A resolving route is not a promise that the provider will answer — the capability surface refuses honestly and names which reason.
/_substrate · /_capabilities — unchanged, and still the authority for anything automated.