Agentic Control Plane supporting “Collaborative Superintelligence” (Flower Labs)
Status: minimum viable product (MVP). A working demonstration of the whole control path on two small servers (c=US and c=CA), with synthetic agents and people. Realistic scaling will only occur with sufficient funding.
Begin your journey here by assessing your current levels of concern regarding the potential for AI agents, and the risk of AI agents to society and culture from your point of view.
Rate your views, and your journey begins. The website will take you to the appropriate sections that match your interests and not try and confuse you.
Utah AI Policy Act and SEDIThe Act’s safe harbor and Executive Order 2026-08 mapped to c=US controls, with what is and isn’t built.
Enterprise CISOs & Architects
Non-human identity governance, Zero Trust enforcement, short-lived mTLS and lifecycle controls.
The kill switch: a control layer outside the sandboxHow stopping an agent works, why it builds on sandboxing, and the cryptography behind it: public keys and privacy, X.500 and LDAP, Kerckhoffs, Shannon and Turing.
Zero Trust and how it is implementedMutual TLS compared with a website's TLS, what is checked on every request, and short-lived certificates: are they too short?
Identity vs. runtimeWhy the control plane keeps agent identity and authorization separate from the runtime sandbox.
Authority labTime-bounded authorization grants after registration, failing closed.
SchemasThe OpenLDAP registry schema, delegation JSON Schema, canonical scopes and example LDIF.
Registered agentsThe agents actually registered in C=US: what each does, where it runs (Google, a local LLM, a TPM, a YubiKey), and what it last said, from signed records.
Trust registryAsk C=US, over ToIP TRQP v2.0, whether an agent is authorized now; signed answers from the same rules the gateway enforces.