No accepted authority
Host returns a structured challenge or refusal before the covered provider adapter is entered.
Your agent can propose the work. EMILIA Host keeps the provider credential beside Gate and checks the customer's exact authority before an activated covered HTTP or MCP action can enter the provider path.
In the Host deployment pattern, the agent never receives the provider credential. No accepted authority and required evidence, no covered provider entry.
Current surface: HTTP local service alpha, HTTP and MCP SDK protection, and governed pilots.
EMILIA_AUTHORITY_REQUIREDor one admitted attemptIAM can show which workload has access. A prompt filter can flag suspicious text. Neither establishes that this exact bank-detail change, production deploy, data export, or permission grant fits the owner's finite mandate now.
Host is an AI agent firewall at the consequence boundary. It is not a prompt or model classifier. It verifies exact customer authority at the credential-owning provider boundary, immediately before the covered adapter can act.
Host keeps proposal, authority, provider entry, and reported outcome separate. That makes refusal useful and prevents a successful API response from being mislabeled as proof of an external effect.
HTTP request or MCP tool call, without the provider credential.
The exact action and activated deployment binding are fixed before asynchronous checks.
Customer-pinned authority and required evidence either fit this action or they do not.
Only an admitted operation can reach the credential-owning provider path.
Refused, returned, or indeterminate are recorded without inventing effect certainty.
Host returns a structured challenge or refusal before the covered provider adapter is entered.
Gate reserves the accepted authority, then permits one covered provider attempt for that operation.
The authority remains consumed and blind retry stays closed until authenticated, action-bound reconciliation.
Host is the local deployment form of EMILIA Gate, not a new protocol or a sixth product. A governed pilot begins with one consequence path and the credential that makes it real.
Choose the first boundary →HTTP over an owner-permissioned Unix socket for one governed local boundary. It is not a general HTTP reverse proxy; only the Host-side adapter holds the provider credential.
Wrap a credential-owning handler or MCP tool so exact request fields are frozen and checked before the real executor is entered.
Customer-reviewed activation, bounded action coverage, explicit bypass review, durable state, and deployment evidence for one selected consequence path.
Host's prevention claim is limited to activated covered paths. It does not establish complete mediation. It does not prove the external effect occurred, constrain alternate credentials, or make the action wise, legal, or correct.
Host events are not Consequence Ledger reconciliation. Host does not reconcile the Consequence Ledger, and Scan does not automatically activate Host. Customer review, signed authority, deployment pinning, durable state, provider profiles, and bypass removal remain part of the governed deployment.
These answers describe the current private alpha and governed-pilot boundary.
EMILIA Host is the private, local deployment form of EMILIA Gate. It places Gate beside the credentials and adapters that can enter a provider path, then requires exact customer authority for each activated covered action.
It is a consequence firewall for AI agents, but it is not a prompt or model classifier. Host verifies exact customer authority at the credential-owning provider boundary. It does not score whether a prompt looks risky.
No. The prevention claim applies only to activated covered paths that must pass through Host. Alternate credentials, direct provider calls, and unmediated executors remain outside the boundary until they are separately removed or mediated.
Before provider entry, missing or mismatched authority returns a structured refusal such as EMILIA_AUTHORITY_REQUIRED. If provider entry occurred but the outcome cannot be established, Host records INDETERMINATE and refuses blind retry until authenticated reconciliation.
No. Scan can propose visible action boundaries and blind spots. The customer must review that proposal, define the authority, and approve the activated Host deployment. Scan does not automatically activate Host.
We will scope one activated HTTP or MCP path, the authority it must require, the bypasses that must be removed, and the evidence the customer needs to retain.