VFS Federation Studio 1.1.8 · Offline help

Perl NN security profiles and fixed boundaries

Permanent boundaries

Strict profile

Strict mode requires an independent benchmark, local non-UNC sources, no symbolic-link or junction traversal, sensitive-text scanning and rejection, bounded bytes, rows, intents, workers, model parameters, optimizer updates, and all configured quality gates.

Integrity and provenance

The candidate manifest records every artifact size and SHA-256 digest. The explicit approval record binds the candidate fingerprint and manifest digest. The final package creates a new manifest for its package-relative assets and removes private workstation source paths.

Runtime uncertainty

Intent confidence, first-versus-second winner margin, and article retrieval score are separate thresholds. Falling below any required threshold results in a clarification prompt.

Governed workspace plans

Agent plans are limited to the explicit project, source, mount, collision, and build-profile command family. Before bundle review, Studio requires a trusted, unexpired Ed25519 signature, an independent benchmark, the workspace accuracy floor, and the configured regression limit. It independently parses model.json, training.csv, and benchmark.csv; requires exact CSV columns, valid bounded rows, matching complete label coverage, actual row counts, and zero normalized corpus overlap. It then requires canonical bounded JSON, an accepted exact bundle, the current workspace/configuration fingerprint, valid IDs and paths, a complete dry run, separate named review, and separate named application. Added source paths stay below the workspace directory, already exist, and may not traverse links. Unknown or stale data fails closed.

A revoked key blocks every accepted agent it signed before proposal acceptance or application. The workspace never restores a revoked key. Accuracy cannot be configured below 70%, regression cannot exceed 5 percentage points, independent benchmarks cannot be disabled, and signatures and key trust always expire.

A digest proves integrity and a trusted signature proves bounded authorship. Neither converts neural output into an authorization token or proves that its advice is correct. Studio 1.1.8 does not yet recompute the signed accuracy claim during admission; replay it with the exported bin/plnn-text-evaluate and keep the output outside the bundle.