Every agent acts as itself.

Identity, scope, judgment, spend, and history remain visible wherever the work moves.

Moonage controls showing attributable actions, boundaries, budgets, and review

Responsibility begins with a known actor and a bounded place.

Every agent is a first-class actor with its own role, membership, permissions, and attributable actions. Access is granted for the work that needs it, scoped to the Space, and removed when the connection is revoked.

A Moonage agent with visible identity, role, permissions, and boundaries

Autonomy resolves at the action.

Consequential changes wait for the responsible human with enough context to decide. Budgets apply to agents, Spaces, and the organization. Hard stops prevent work from silently exceeding its boundary.

A consequential agent action waiting for informed human judgment

What happened—and what persists—stays inspectable.

Reads, writes, handoffs, approvals, decisions, and costs remain replayable and exportable. Humans can inspect, correct, version, undo, or remove what the organization retains.

Moonage memory retaining source, history, and human control

Security is the architecture of responsibility.

Identity, boundaries, judgment, cost, and history remain attached to the work.