How it works

Four parts. One of them has the last word.

VigilantDev is in development. This page describes how the first release is designed.

Vigil Agent

A small agent with a fixed vocabulary.

The agent runs as a Windows service. It does not take arbitrary commands. It knows a short list of typed capabilities, each with a parameter schema, and announces that list to the console.

It opens an outbound connection to the console, so the device needs no open inbound ports.

// what WS-ACCOUNTING-07 announces
{
  "device": "WS-ACCOUNTING-07",
  "agent": "vigil 0.1.0",
  "capabilities": [
    { "id": "screenshot" },
    { "id": "defender.scan", "params": { "type": ["quick", "full"] } },
    { "id": "restart",  "params": { "delay_s": "0..3600" } },
    { "id": "shutdown", "params": { "delay_s": "0..3600" } }
  ]
}
Policy

The device decides, in a file you can read.

The policy lives on the device. The console can display it and suggest changes, but a change only takes effect after a local administrator approves it on the machine.

ModeWhat happens to a request
allowRuns, if its parameters and time fall inside the limits in the policy.
askThe signed-in user sees the request on screen and approves or refuses it. No answer within the timeout counts as a refusal.
denyRefused and recorded. This is the mode for every capability the policy does not mention.
A request, step by step

From click to verdict.

  1. The console signs a request

    It names one capability and its parameters, for example restart {"delay_s": 300}.

  2. The agent checks the capability

    If the agent does not implement it, the request is refused. There is no fallback to a shell.

  3. The agent checks the policy

    Mode, parameter limits and time window are evaluated on the device. ask shows a prompt to the user.

  4. The agent runs it, or refuses

    Either way the verdict and result go into the ledger, then back to the console.

Ledger

The device keeps its own record.

Each entry carries the hash of the one before it, so a deleted or edited entry breaks the chain and shows. When you need to know what happened on a machine, you read the machine, not a log the console wrote about it.

#1041 14:21:55 ops@acme  screenshot               ALLOW  prev 9c1e44a0
#1042 14:22:08 ops@acme  defender.scan full       VETO   prev 4b7a2f19
        type="full" outside policy [quick]
#1043 14:22:31 claude    shell.exec               VETO   prev e03d7c58
        capability not allowed on this device
#1044 14:23:02 ops@acme  restart delay_s=300      ASK    prev 51aa90de
        approved by the signed-in user at 14:23:40